Job Summary
The Cybersecurity GRC AI & Process Automation Engineer will design and implement automation solutions across Cybersecurity Governance, Risk, and Compliance (GRC) processes, with a focus on improving the efficiency, traceability, and governance of Risk and Control Self-Assessment (RCSA) activities. The role will leverage Artificial Intelligence, Generative AI, intelligent workflows, and process automation technologies to reduce manual effort, streamline evidence collection and validation, improve tracking of risk and control activities, and provide greater visibility into cybersecurity controls. The position will work closely with Cybersecurity, Risk Management, Compliance, Technology, and control owners to transform manual and fragmented processes into standardized, automated, and auditable workflows. This is a hybrid onsite position in Quincy, Massachusetts.
Key Responsibilities
• Drive automation initiatives across Cybersecurity GRC, with an initial focus on RCSA and control management processes.
• Design and implement automated workflows for the collection, organization, validation, and tracking of control evidence across multiple teams and systems.
• Reduce manual effort associated with RCSA activities, including evidence requests, follow-ups, status tracking, control assessments, documentation, and reporting.
• Establish centralized tracking and workflow capabilities providing visibility into evidence status, outstanding actions, ownership, due dates, exceptions, and remediation activities.
• Leverage AI and Generative AI to support evidence analysis, identify gaps or inconsistencies, summarize control information, and assist control owners and risk teams throughout the assessment lifecycle.
• Improve traceability and audit readiness by maintaining structured records of evidence, approvals, assessments, decisions, and supporting documentation.
• Develop dashboards and management reporting to provide visibility into RCSA progress, control status, evidence completeness, overdue activities, and key risk indicators.
• Support regulatory, audit, and risk management activities through automated evidence collection, workflow tracking, and reporting.
• Identify additional opportunities to automate Cybersecurity GRC processes and establish reusable capabilities that can be scaled across other risk and control activities.
Required Qualifications
• Experience in Cybersecurity Governance, Risk, and Compliance (GRC).
• Experience designing and implementing automated workflows to streamline risk, compliance, and control processes.
• Experience with Risk and Control Self-Assessment (RCSA) and control management processes.
• Experience leveraging AI, Generative AI, intelligent workflows, or process automation technologies within risk, compliance, or cybersecurity processes.
• Experience with evidence collection, validation, tracking, documentation, and reporting for risk and control activities.
• Strong ability to identify manual or fragmented processes and transform them into standardized, automated, and auditable workflows.
• Strong communication and collaboration skills when working with Cybersecurity, Risk Management, Compliance, Technology, and control owners.
• English proficiency.
Preferred Qualifications
• Spanish language proficiency.
• Experience developing dashboards and management reporting for risk and control activities.
• Experience supporting regulatory, audit, and risk management activities through automation.
• Experience developing reusable automation capabilities that can be scaled across multiple risk and control processes.