GRC Engineer
Posted 2hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
GRC Engineer at WorkOS managing compliance, risk, and customer trust programs. Leading initiatives for certifications and automating GRC processes in a remote environment.
Responsibilities:
- Own our compliance function. Frameworks, policies, controls, and audits are yours.
- Lead our next certifications. Drive initiatives for FedRAMP and other frameworks; scoping the controls, documentation, and collaborating with others across the organization to make it happen.
- Partner directly with customers. Be the voice of our compliance program to our customers. Support audits, enable sales on compliance-gated deals, and build on the trust we've established with the companies that depend on us.
- Own risk across WorkOS. Run our risk and third-party risk programs. Identify risks as they emerge, drive remediation, and surface signal to leadership.
- Build GRC-as-code. Write code and tooling to automate the parts of GRC that don't need a human, and leverage AI where it fits.
Requirements:
- 5+ years in a GRC, or compliance role, with demonstrated program ownership at a cloud-native company.
- Hands-on experience implementing or auditing SOC 2 plus one other major framework (ISO 27001, PCI DSS, NIST 800-53).
- Proficiency in at least one programming or scripting language (Python, TypeScript, Go, or similar). You can read code, write automation, and leverage AI effectively. CS or engineering background preferred.
- Experience with GRC automation platforms (Vanta, Drata, or similar); migrating into, configuring, and building in them.
- Strong written communication, particularly in customer-facing and cross-functional contexts.
Benefits:
- Healthcare insurance (Medical, Dental and Vision) for you and your family
- 401k matching
- Wellness and fitness monthly allowances
- PTO + paid holidays + unlimited sick leave
- Autonomy and flexibility with remote work
- Substantial equity grants


















