Назад
Company hidden
1 день назад

GRC Engineer (Cybersecurity)

200 000 - 250 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Engineer (Cybersecurity): Building scalable, automated security governance, risk, compliance, and assurance programs for a cloud software and physical AI platform with an accent on security controls, risk management, and continuous compliance. Focus on automating control testing and audit evidence collection, conducting risk and vendor assessments, and supporting SOC 2 and ISO 27001 requirements across corporate, IT, and product environments.

Location: San Mateo, California, United States; onsite five days per week

Annual OTE: $200,000–$250,000 USD

Company

hirify.global develops an integrated, privacy-sensitive, AI-powered physical security platform covering video security, access control, sensors, alarms, intercoms, and visitor management.

What you will do

  • Build and lead the governance, risk, compliance, and assurance function within the Security Team.
  • Design, maintain, and automate security control testing and continuous monitoring across AWS, GitHub, and other platforms.
  • Maintain the security compliance roadmap across corporate, IT, and product environments, increasing automation coverage.
  • Manage security policies, corrective action plans, exceptions, risk treatment plans, vendor assessments, and customer security questionnaires.
  • Conduct annual security risk assessments and collaborate on Business Impact Assessments and business continuity/disaster recovery activities.
  • Partner with internal and external auditors to maintain continuous compliance across the technology control environment.

Requirements

  • Ability to work onsite in San Mateo five days per week.
  • 7+ years of security, IT compliance, or equivalent experience.
  • Experience with compliance for software companies and cloud software products.
  • Experience with audits, risk, and compliance frameworks such as SOC 2 and ISO 27001.
  • Experience with AWS or another cloud service provider.
  • Strong written and spoken communication skills, with the ability to work autonomously across cross-functional teams.

Nice to have

  • Experience with scripting languages such as Python and JSON.
  • Experience automating audit evidence collection.

Culture & Benefits

  • Healthcare, vision, and dental coverage, including employee premium coverage under at least one medical plan.
  • HSA employer contributions, FSA options, expanded mental health support, and fertility benefits.
  • Paid parental leave, paid holidays, extended firmwide holidays, flexible PTO, and personal sick time.
  • Professional development stipend, wellness and fitness benefits, daily lunches, and commuter benefits.
  • Employment visa sponsorship and sponsorship transfer support are available for this role.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →