GRC Engineer
- Salary
- $140K–$160K
- Hiring from
- United States
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
About our client:
Our client is a Security & Compliance Service Growth firm that specializes in transforming security and compliance from a perceived obstacle into a strategic growth enabler. Whether you're pursuing SOC 2, ISO 27001, CMMC, NIST CSF, or another framework, they don't just advise. They execute with precision.
Our values
The GRC Engineer is a strategic, high-impact position for someone who can serve as a dependable leader.
This role is built for a proactive professional who independently drives complex compliance initiatives and stays ahead of emerging regulatory trends. You will work across a diverse client base, building rapport with stakeholders to ensure consistent progress on control implementation and audit readiness.
The ideal candidate brings a high degree of technical autonomy and a specialized GRC background with both implementer and auditor experience.
Core Requirements
Hands-on implementer and auditor experience: Professional auditing experience, plus experience building a security program on the implementation side.
Framework expertise: Expert, hands-on experience leading Cybersecurity Maturity Model Certification (CMMC) Level 2 projects and standing up ISO 27001 Information Security Management Systems (ISMS) from scratch.
Microsoft GCC High: Direct experience managing and operating within Microsoft GCC High environments to maintain strict compliance standards.
Security engineering aptitude: Technically proficient and comfortable navigating cloud environments, with the agility to serve as a technical backup for broader operational tasks.
Security leadership mindset: A big-picture, risk-based approach to building defensible security programs, with the ability to design and implement programs that are not just compliant, but practical too.
Proactive ownership: A self-starter committed to tracking emerging regulatory trends, executive orders, and framework updates to proactively evolve internal and client policies.
Preferred Qualifications
Incident response and security operations: Ability to facilitate and support incident response tabletop exercises, and to create and leverage playbooks for security events.
Frameworks, Platforms, and Environments
Compliance Frameworks & Standards
Platforms & Environments
SOC 2
Amazon Web Services (AWS)
ISO 27001
Microsoft Azure
CMMC
Microsoft GCC High
NIST 800-171
GRC automation platforms
What They Offer
Health and dental insurance
401(k) plan and Match
Paid time off