Назад
Company hidden
4 часа назад

Senior Security Engineer, GRC (Governance, Risk and Compliance)

14 123 025 - 18 013 770$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer, GRC (Governance, Risk and Compliance) (AWS/AI): Building automated security control monitoring and self-service evidence systems for AWS environments with an accent on continuous control monitoring, audit-ready evidence, and AI-native GRC workflows. Focus on engineering control-failure pipelines, applying LLMs with human guardrails, and shifting compliance controls left through policy-as-code and CI/CD.

Location: United States, Remote

Base salary: $141,230.25–$180,137.70 per year, with potential bonus or commission, stock options, and benefits.

Company

hirify.global develops technology focused on helping companies improve growth, retention, and operational efficiency.

What you will do

  • Design, build, and maintain automated security control monitoring as production-quality, version-controlled software.
  • Convert manual, sample-based control testing into continuous control monitoring with defined signals, thresholds, alerting, and escalation paths.
  • Engineer self-service AWS evidence collection using services including Config, Security Hub, CloudTrail, IAM, Lambda, EventBridge, Athena, S3, and CloudWatch.
  • Build end-to-end control-failure workflows covering detection, enrichment, ticketing, ownership, SLA tracking, remediation verification, exceptions, and risk acceptance.
  • Apply LLMs and agentic workflows to evidence review, control mapping, gap analysis, questionnaires, policy drafting, and risk triage with human review and validation.
  • Lead audits, risk assessments, control remediation, reporting, GRC integrations, and technical enablement across Security, Platform Engineering, DevOps, and IT.

Requirements

  • 5+ years of experience in GRC or a similar security function.
  • 2+ years of hands-on automation experience with a scripting or programming language, preferably Python, plus Git, code review, and CI/CD.
  • Hands-on AWS experience with control monitoring and evidence generation, including Config, Security Hub, CloudTrail, IAM, Organizations, SCPs, Lambda, EventBridge, S3/Athena, and CloudWatch.
  • Experience retrieving, normalizing, and reconciling data through APIs and SQL, with attention to data completeness and accuracy.
  • Practical experience applying LLMs or AI agents to real workflows, including prompt design, output evaluation, human review, and guardrails.
  • Knowledge of security tools and frameworks including ISO 27001, SOC 2, GDPR, PCI DSS, SOX, and NIST, with the ability to defend automated testing and evidence to auditors.

Nice to have

  • Infrastructure-as-code and policy-as-code experience with Terraform, CloudFormation, OPA/Rego, AWS Config custom rules, or cfn-guard.
  • Experience with continuous control monitoring at scale in SaaS or multi-account cloud environments.
  • Experience building API-integrated GRC platforms and self-service tools for engineers or control owners.
  • Big Four experience, a related bachelor's degree, or certifications such as CISSP, CISM, GIAC, AWS Certified Security – Specialty, CCSK, or CCSP.

Culture & Benefits

  • Full-time employment with health coverage, life and disability insurance, paid parental leave, paid holidays, PTO, and quarterly self-care days.
  • Stock options may be available, along with a 401(k) employer matching program.
  • Equipment and support are provided for working from home or from company offices.
  • Learning and development support includes access to LinkedIn Learning.
  • Wellness education, employee resource group events, and a growth-oriented work environment are provided.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →