← All jobs

GRC Engineer I – Special Programs

About the role

• Execute end-to-end client compliance initiatives aligned with SOC 2, ISO 27001, and regulatory standards
• Maintain policy and evidence repositories by authoring and updating security policies, standard operating procedures, and control evidence
• Identify, evaluate, track, and remediate cybersecurity risks and control gaps with cross-functional technical teams
• Manage compliance milestones, evidence gathering, task execution, project deliverables, and timelines across concurrent client engagements
• Communicate directly with client stakeholders via email, chat, and video calls
• Gather evidence, clarify control requirements, and share engagement updates
• Perform structured control testing and readiness reviews
• Collaborate with internal IT, security, and operations teams on corrective action plans
• Update delivery templates, playbooks, and standard operating procedures
• Manage active client accounts within the first 15 days
• Serve as the primary point of contact for a portfolio of accounts
• Guide engagements end-to-end and resolve escalations with urgency
• Manage accounts and oversee a pod of analysts across SOC 2, ISO 27001, and NIST CSF frameworks

• Proven ability to communicate directly with U.S. clients
• Strong organizational discipline to manage multiple cybersecurity compliance engagements simultaneously
• Hands-on execution experience across SOC 2, ISO 27001, or NIST CSF frameworks within tech-focused cybersecurity environments
• Practical familiarity authoring, rolling out, and enforcing enterprise cybersecurity policies and control benchmarks
• Ability to thrive in fast-paced startup settings and adapt to shifting priorities
• Outstanding written and verbal English communication skills for executive and technical interactions
• Practical exposure to automated compliance solutions such as Vanta or similar GRC platforms
• Practical familiarity with GDPR, HIPAA, or PCI DSS
• Recognized industry certification such as ISO 27001 Lead Implementer, CISA, or Security+
• Excellent written and verbal English communication skills
• Reliable, high-speed internet connection
• Professional home office environment supporting confidential conversations and uninterrupted collaboration
• Availability to work 8:00 AM–5:00 PM U.S. Eastern Time
• Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities
• Participation in live video interviews with camera on
• Identity verification and background screening, where permitted by law

• Career development with mentorship and training opportunities
• Reimbursement for approved training and certification courses relevant to the current role
• Competitive base salary with regular performance reviews linked to merit-based appraisals
• Bonus opportunities
• Significant room for career advancement
• Remote-first flexibility to work from anywhere while collaborating with a global team