Forward Networks

GRC Engineer

Forward Networks • $140K — $170K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years in GRC, security engineering, or IT audit with control design experience.
  • Experience with GRC/compliance automation tools (e.g. Vanta, Drata, etc.).
  • Solid working knowledge of SOC 2; familiarity with ISO 27001 is a plus.
  • Basic scripting skills in Python, Bash, or SQL for data manipulation.
  • Exposure to SIEM/SOAR tools and incident response knowledge.
  • Ability to communicate across both GRC and engineering spectrums.
  • Experience in a Mac-centric compliance environment.

Responsibilities

  • Write and maintain security policies and procedures, ensuring review cycles are active.
  • Build automated control tests for real-time verification of system configurations.
  • Manage and extend GRC platforms through scripting and API work.
  • Continuously monitor control drift and drive remediation efforts.
  • Lead day-to-day SOC 2 audits and prepare for ISO 27001 certification.
  • Maintain a prioritized risk register and execute actionable risk assessments.
  • Conduct vendor security reviews using automated evidence gathering.

Benefits

  • Work in an innovative field of GRC Engineering, focusing on compliance automation.
  • Opportunity to expand into Security Operations (SIEM/SOAR).
  • Be part of evolving role with potential for continuous professional growth.
  • Collaborative environment integrating compliance into engineering workflows.
  • Use of AI tools to assist with engineering tasks.
Full Job Description
Forward is looking for a GRC Engineer. GRC Engineering is a new discipline: instead of chasing down screenshots every quarter and hoping the auditor doesnt ask too many follow-up questions, youre building scripts and API integrations that pull evidence straight from the source systems and keep it current on their own. If youve spent any time reading about the field, youve probably run into grc.engineering, the GRC Engineering Club, or grcengineer.com. Wed rather hire someone who already thinks this way than someone who needs to be convinced of it; if your engineering skills enable doing more than a traditional GRC Analyst role, youre the right fit. Your initial focus, likely for the next 6 months, is **GRC Engineering**: compliance automation, audit management (SOC 2, ISO 27001/42001), control design and testing, and risk management. Once the most critical automations are in place, this job broadens to include a **Security Operations** piece: mostly SIEM and SOAR work plus whatever incident response comes up. This is your chance to go beyond mere exposure to SecOps work, to directly participate in alert triage, SIEM/SOAR administration and tuning, enforcement work, and incident response. This is a real split, and were looking for someone who can grow to handle both types of work. **What Youll Do** **GRC Engineering (main focus of role)** - Policy & Documentation: Write, maintain, and actively drive review cycles for security policies and procedures. - Automated Control Testing: Build control tests that verify real system configurations directly at the source, rather than manual spreadsheets. If a control says MFA is enforced, you should be able to verify that in the identity provider yourself. - Manage and extend our GRC platform (Vanta, Drata, etc.) using scripts and API integrations. - Control Monitoring: Continuously manage control drift between audits and drive remediation to completion. - Audit Management: Lead day-to-day SOC 2 Type II audits and lay groundwork for ISO 27001 and ISO 42001. - Risk Management: Maintain a prioritized risk register and run actionable risk assessments. - Handle vendor security reviews and due diligence: pull evidence from a vendors API or trust page, rather than mailing them a 40-question spreadsheet. - Engineering Collaboration: Integrate compliance requirements directly into engineering workflows, such as CI/CD, access provisioning, and change management. **Security Operations (additional piece after critical automations in place)** - SIEM & SOAR Admin: Tune detection rules, correlation logic, and response playbooks. - Endpoint Support: assist with EDR, DLP, and endpoint break/fix and incident response cases. - Alert Triage: Participate in security alert triage and documentation. - Jump into incident response when something happens: investigation, helping contain it, and post-mortem write-ups. - Feed what you see in the SOC back into the GRC side of your job. If operations tell a different story than what the compliance platform says, that gap is worth knowing about. **What Were Looking For** **Required** - 3+ years in GRC, compliance, security engineering, IT audit, or equivalent, with on-the-job exposure to control design, risk assessment, AND compliance frameworks. - Experience writing policies and procedures, with a focus on testable and verifiable outcomes. - Time spent doing real work in a GRC/compliance automation platform (Vanta, Drata, Thoropass, Anecdotes, or similar). - Solid working knowledge of SOC 2. ISO 27001 experience is a plus. ISO 42001 is a possible future endeavor, but curiosity about AI governance is important. - Basic scripting knowledge: Python or Bash, SQL, and comfortable pulling data from an API, parsing a log file, or automating something you used to do by hand. This is not a software engineer role and you will be able to take advantage of AI to assist, but the ability to read, troubleshoot, and deliver working scripts is a requirement. - Some exposure to SIEM/SOAR tooling (Splunk, Chronicle, Panther, XSOAR, Tines, whatever youve used) and a basic feel for how incident response actually runs. - The ability to speak to an auditor and an engineer in languages they understand, as both the GRC and engineering skill sets will be utilized. - A tolerance for ambiguity. "GRC Engineer" is an evolving field/role. We will be figuring out parts of this role as time goes on together. - Experience with endpoint compliance in a Mac-centric environment. **Nice to Have** - We run in the cloud but also still operate our own data center, so comfort with straight Linux administration and scripting matters just as much as anything cloud-native. If youve worked with Terraform or policy-as-code, that helps too. - Certs like Security+, CISA, CISSP, or ISO 27001 Lead Implementer/Auditor are fine to have. We just care more about whether you can trace a control back to the system its actually describing. - Time spent tuning or migrating a SIEM/SOAR setup, or running incident response for real, not just in a tabletop exercise. - Understanding tabletop exercises, how to run them, how to conduct a post-mortem and how to drive the findings to completion with stakeholders. The base pay range for this role is between $140,000 and $170,000. This range represents the low and high end of the salary for this position. Actual compensation will vary based on factors including location, candidate experience, skills, and level.

About Forward Networks

Forward Networks is a software company that provides network assurance and verification solutions for enterprise networks. The company was founded in 2013 by David Erickson and Peyman Kazemian and is headquartered in Palo Alto, California. Forward Networks' platform uses mathematical models to analyze network behavior and identify potential issues before they occur. The company has received funding from investors such as Andreessen Horowitz and A.Capital Ventures.
Learn more about Forward Networks
Size
100 employees
Industry
Founded
2013

Similar Jobs

More Jobs at Forward Networks

More Information Technology Jobs

Find similar GRC Engineer jobs: