Box Inc

GRC Controls Automation Engineer

Box Inc$111K — $145K *
Enterprise Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in GRC, Information Security, or similar roles within a SaaS company
  • Familiarity with GCP, AI architectures, and data governance
  • Deep knowledge of regulatory frameworks (NIST, PCI, ISO, SOC)
  • BS in Business/Management Information Systems or equivalent experience
  • Certifications such as CISSP, CCSK, or CISM are a plus
  • Strong communication and presentation skills
  • Exceptional organizational skills, adaptable in a fast-paced environment

Responsibilities

  • Drive improvements and standardization of existing processes
  • Design and implement compliance controls with a focus on automation
  • Provide compliance insights on product features and infrastructure changes
  • Participate in cloud and application security strategy
  • Assess current security posture and suggest enhancements
  • Work across multiple regulatory frameworks and standards
  • Support audits with accurate process documentation

Benefits

  • Collaborative company culture with an emphasis on community
  • In-person collaboration with a requirement of at least 3 days in the office
  • Encouragement for diverse experiences and perspectives
  • Opportunities for growth and leveraging AI for impactful decision-making
Full Job Description
WHY BOX NEEDS YOU
  • We are looking for an experienced and driven GRC Controls Automation Engineer who is looking to put their demonstrated awareness of regulatory standards to help bridge compliance requirements, technical infrastructure and engineering workflows. You will be focused on modernizing, designing, building and scaling frameworks that embed compliance directly into the software development (SDLC) process. As our GRC Controls Automation Engineer, you will play a key role building a scalable, efficient program and process using your technical leadership focusing on automation within Box.
  • You will work with all functions of this fast-paced, rapidly changing business, and directly with key stakeholders to drive continuous improvement, communication and education with Box's internal customers. The right person will be excellent at communicating vertically and horizontally across the company and will be comfortable explaining Box's compliance posture internally and externally, working cross-functionally and providing technical and creative guidance to technical teams.


WHAT YOU'LL DO
  • Drive improvements in existing processes, process standardization and develop new innovative and efficient solutions
  • Design, develop, and implement controls with a focus on compliance and automation
  • Provide compliance guidance on new product features, deviations, and changes in the infrastructure
  • Participate in cloud and application security strategic planning and execution
  • Implement improvements by assessing the current environment, evaluate trends, and anticipating future enhancements/requirements
  • Assess the existing security and compliance posture, and provide guidance on implementing products into Box's production environment
  • Work across multiple frameworks and regulatory standards, including but not limited to ISO, PCI, NIST, AICPA SOC
  • Support audits by maintaining accurate process documentation
  • Drive improvements in existing processes and develop new innovative and efficient solutions
  • Communicate gaps to management and coordinate cross functional team meetings to remediate and close the control gaps
  • Monitor and identify compliance issues and follow-up
  • Build relationships with internal and external stakeholders


WHO YOU ARE

We are an AI-first company. This means you approach your work with a growth mindset and find ways to leverage AI to help make faster, smarter decisions that will 10X your impact at Box.
  • 5+ years of professional experience working in a SaaS company in GRC, Information Security or similar function
  • Familiar with GCP cloud computing, AI architectures, Data governance and model validations
  • Deep understanding of global frameworks, such as NIST 800-53, PCI, ISO 27x, and SOC 2
  • BS degree in Business or Management Information Systems or related field OR equivalent work experience
  • CISSP, CCSK, CISM or other related certifications a plus
  • Excellent written, verbal communication and presentation skills with a willingness to wear different hats and work in areas where needed
  • Amazing organizational skills with a drive to succeed in a fast-paced environment
  • Ability to hustle, get stuff done, and has strong integrity - make mom proud!

Box lives its values, with community and in-person collaboration being a core part of our culture. Boxers are expected to work from their assigned office a minimum of 3 days per week.Your Recruiter will share more about how we work and company culture during the hiring process.

At Box, we believe unique and diverse experiences benefit our culture, our products, our customers, our company, and our world. We aim to recruit a passionate, high-performing workforce that reflects the world we live in.If you are head-over-heels about this role but unsure if you meet all the requirements, we encourage you to apply!

About Box Inc

Box, Inc. is a cloud content management and file sharing service for businesses. The company provides a platform for managing and collaborating on content across multiple devices and applications. Box serves a wide range of industries, including healthcare, finance, and media. The company was founded in 2005 and is headquartered in Redwood City, California.
Learn more about Box Inc
Size
2,172 employees
Market Cap
$4.4 billion
Industry
Net Income
-$43.4 million
Founded
2005
5 Year Trend
+17%
Revenue
$770.7 million
NASDAQ

Similar Jobs

More Jobs at Box Inc

More Enterprise Technology Jobs

Find similar GRC Controls Automation Engineer jobs: