GRC Engineer I

Posted 6ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

GRC Engineer I supporting cybersecurity compliance programs and client engagement within a fast-growing startup. Managing documentation and projects aligned with industry frameworks such as SOC 2 and ISO 27001.

Responsibilities:

  • Assist in implementing and maintaining cybersecurity compliance programs aligned with SOC 2, ISO 27001, and other regulatory standards.
  • Develop and update cybersecurity policies, procedures, and control evidence to support audits and assessments.
  • Work with internal and external teams to identify, track, and help remediate cybersecurity risks and control gaps.
  • Support multiple compliance projects by managing documentation, timelines, and deliverables under senior guidance.
  • Engage with clients via email, chat, and calls to gather evidence, clarify compliance requirements, and provide timely updates.
  • Conduct basic control checks and assist in readiness reviews to ensure continuous compliance with internal and external standards.
  • Partner with IT, security, and operations teams to implement corrective actions and strengthen compliance posture.
  • Receive mentorship from senior team members and contribute to improving processes, templates, and playbooks for compliance delivery.

Requirements:

  • Strong organizational skills with the ability to manage multiple cybersecurity compliance projects concurrently
  • Exceptional written and verbal English communication skills
  • Proven ability to work directly with clients in the US
  • Experience working in cybersecurity compliance, including SOC 2, ISO 27001, or NIST CSF frameworks
  • Familiarity with creating and enforcing cybersecurity policies
  • Experience working in a tech company with a focus on cybersecurity
  • Thrives in a fast-paced startup environment
  • Familiarity with Vanta or similar compliance automation platforms
  • Additional experience with frameworks such as GDPR, HIPAA, or PCI DSS
  • Certifications such as ISO 27001 Lead Implementer, CISA, or Security+.

Benefits:

  • Career Development : Clear path with mentorship and training opportunities
  • Technical Training : Comprehensive onboarding on security and compliance frameworks
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity : Early-stage company with significant room for career advancement.
  • Remote-First Culture : Flexibility to work from anywhere while collaborating with a global team.