Staff GRC Engineer
Staff GRC Engineer
About the role
We're looking for a Staff GRC Engineer to bring an engineering mindset to governance, risk, and compliance. This is a senior, hands-on role for someone who believes compliance shouldn't be a spreadsheet-and-screenshot exercise — it should be automated, continuous, and backed by real evidence pulled straight from systems. You'll build the tooling and pipelines that turn our control framework into code, collect evidence automatically, and give us continuous visibility into our compliance posture.
As a Staff engineer, you'll set the technical direction for how we do GRC at scale, partner with the compliance and risk teams to translate requirements into automation, and free up the organization from manual audit toil so it can focus on actual risk reduction.
What you'll do
Build and operate compliance automation: continuous controls monitoring, automated evidence collection, and control testing across cloud and corporate systems.
Implement compliance-as-code and policy-as-code so controls are defined, versioned, tested, and enforced programmatically.
Integrate GRC tooling with the systems that hold the evidence (cloud providers, IdP, ticketing, CI/CD, HRIS) via APIs.
Build dashboards and reporting that give real-time visibility into control health, drift, and audit readiness.
Reduce audit burden by automating the collection and packaging of evidence for SOC 2, ISO 27001, and other frameworks.
Partner with GRC analysts and risk owners to translate control requirements into technical checks and remediation workflows.
Automate access reviews, risk assessments, and vendor risk workflows.
Set engineering standards for the GRC function and mentor analysts and engineers on automation.
What we're looking for
Significant experience (typically 8+ years) spanning security/GRC and software engineering, with a strong hands-on engineering background.
Strong programming skills (Python, Go, or similar) and comfort building integrations against APIs.
Working knowledge of compliance frameworks (SOC 2, ISO 27001, and similar) and what evidence and control testing actually require.
Experience with cloud environments (AWS, GCP, or Azure) and infrastructure-as-code.
Familiarity with GRC/compliance automation platforms and continuous controls monitoring concepts.
Ability to lead cross-team initiatives and translate between compliance and engineering.
Nice to have
Experience implementing compliance-as-code or building custom GRC tooling.
Familiarity with policy-as-code (e.g., OPA) and drift detection.
Prior experience surviving audits and knowing where the manual pain lives.
Relevant certifications (CISA, CISSP, or similar).
How we define Staff level
At the Staff level, your impact reaches beyond the automation you personally write. You'll set the technical strategy for continuous compliance, identify where automation removes the most toil and risk, elevate the analysts and engineers around you, and make audit readiness a byproduct of how our systems already run.
Salary: $220k
Values