5+ years of experience in GRC, Information Security or related fields, preferably within a SaaS environment
Knowledge of cloud solutions, particularly GCP; familiarity with AI architectures is a plus
In-depth understanding of regulatory frameworks like NIST 800-53, PCI, ISO 27x, and SOC 2
Bachelor’s degree in Business, Management Information Systems, or equivalent work experience
Professional certifications such as CISSP, CCSK, or CISM are advantageous
Outstanding communication skills, both verbal and written, with the ability to adapt to different roles as necessary
Strong organizational skills demonstrated in fast-paced settings.
Responsibilities
Drive improvements in existing processes and develop innovative solutions
Design, develop, and implement compliance-focused controls with automation
Provide compliance guidance for new product features and infrastructure changes
Engage in strategic planning and execution for cloud and application security
Monitor security and compliance posture and recommend enhancements
Support audits with thorough and accurate process documentation
Foster relationships with internal and external stakeholders.
Benefits
Collaborative and community-focused company culture
Opportunity to work in an AI-first environment, leveraging tech for better decision-making
Flexibility with in-office work; require a minimum of 3 days in the office per week
Supportive of diverse experiences and perspectives.
Full Job Description
We are looking for an experienced and driven GRC Controls Automation Engineer who is looking to put their demonstrated awareness of regulatory standards to help bridge compliance requirements, technical infrastructure and engineering workflows. You will be focused on modernizing, designing, building and scaling frameworks that embed compliance directly into the software development (SDLC) process. As our GRC Controls Automation Engineer, you will play a key role building a scalable, efficient program and process using your technical leadership focusing on automation within Box.
You will work with all functions of this fast-paced, rapidly changing business, and directly with key stakeholders to drive continuous improvement, communication and education with Box's internal customers. The right person will be excellent at communicating vertically and horizontally across the company and will be comfortable explaining Box's compliance posture internally and externally, working cross-functionally and providing technical and creative guidance to technical teams.
WHAT YOU'LL DO
Drive improvements in existing processes, process standardization and develop new innovative and efficient solutions
Design, develop, and implement controls with a focus on compliance and automation
Provide compliance guidance on new product features, deviations, and changes in the infrastructure
Participate in cloud and application security strategic planning and execution
Implement improvements by assessing the current environment, evaluate trends, and anticipating future enhancements/requirements
Assess the existing security and compliance posture, and provide guidance on implementing products into Box's production environment
Work across multiple frameworks and regulatory standards, including but not limited to ISO, PCI, NIST, AICPA SOC
Support audits by maintaining accurate process documentation
Drive improvements in existing processes and develop new innovative and efficient solutions
Communicate gaps to management and coordinate cross functional team meetings to remediate and close the control gaps
Monitor and identify compliance issues and follow-up
Build relationships with internal and external stakeholders
WHO YOU ARE
We are an AI-first company. This means you approach your work with a growth mindset and find ways to leverage AI to help make faster, smarter decisions that will 10X your impact at Box.
5+ years of professional experience working in a SaaS company in GRC, Information Security or similar function
Familiar with GCP cloud computing, AI architectures, Data governance and model validations
Deep understanding of global frameworks, such as NIST 800-53, PCI, ISO 27x, and SOC 2
BS degree in Business or Management Information Systems or related field OR equivalent work experience
CISSP, CCSK, CISM or other related certifications a plus
Excellent written, verbal communication and presentation skills with a willingness to wear different hats and work in areas where needed
Amazing organizational skills with a drive to succeed in a fast-paced environment
Ability to hustle, get stuff done, and has strong integrity - make mom proud!
Box lives its values, with community and in-person collaboration being a core part of our culture. Boxers are expected to work from their assigned office a minimum of 3 days per week.Your Recruiter will share more about how we work and company culture during the hiring process.
At Box, we believe unique and diverse experiences benefit our culture, our products, our customers, our company, and our world. We aim to recruit a passionate, high-performing workforce that reflects the world we live in.If you are head-over-heels about this role but unsure if you meet all the requirements, we encourage you to apply!
About Box Inc
Box, Inc. is a cloud content management and file sharing service for businesses. The company provides a platform for managing and collaborating on content across multiple devices and applications. Box serves a wide range of industries, including healthcare, finance, and media. The company was founded in 2005 and is headquartered in Redwood City, California.