GRC Engineer I
Posted 62ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
GRC Engineer I managing cybersecurity compliance projects for a tech startup. Focus on SOC 2, ISO 27001, and NIST frameworks with mentorship support.
Responsibilities:
- Assist in implementing and maintaining cybersecurity compliance programs aligned with SOC 2, ISO 27001, and other regulatory standards
- Develop and update cybersecurity policies, procedures, and control evidence to support audits and assessments
- Work with internal and external teams to identify, track, and help remediate cybersecurity risks and control gaps
- Support multiple compliance projects by managing documentation, timelines, and deliverables under senior guidance
- Engage with clients via email, chat, and calls to gather evidence, clarify compliance requirements, and provide timely updates
- Conduct basic control checks and assist in readiness reviews to ensure continuous compliance with internal and external standards
- Partner with IT, security, and operations teams to implement corrective actions and strengthen compliance posture
- Receive mentorship from senior team members and contribute to improving processes, templates, and playbooks for compliance delivery
Requirements:
- Strong organizational skills with the ability to manage multiple cybersecurity compliance projects concurrently
- Exceptional written and verbal English communication skills
- Proven ability to work directly with clients in the US
- Experience working in cybersecurity compliance, including SOC 2, ISO 27001, or NIST CSF frameworks
- Familiarity with creating and enforcing cybersecurity policies
- Experience working in a tech company with a focus on cybersecurity
- Thrives in a fast-paced startup environment
- Familiarity with Vanta or similar compliance automation platforms (Nice to Have)
- Additional experience with frameworks such as GDPR, HIPAA, or PCI DSS (Nice to Have)
- Certifications such as ISO 27001 Lead Implementer, CISA, or Security+ (Nice to Have)
Benefits:
- Career Development: Clear path with mentorship and training opportunities
- Technical Training: Comprehensive onboarding on security and compliance frameworks
- Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities
- Growth Opportunity: Early-stage company with significant room for career advancement.
- Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
- Work Environment Requirements: Reliable high-speed internet connection and quiet, professional home office setup.


















