The Opportunity
We are seeking a GRC Engineer to lead the transformation of our Technology Compliance program. In this role, you will replace manual audit testing with Compliance-as-Code (CaC), Policy-as-Code (PaC), and Continuous Control Monitoring (CCM) by embedding controls into the CI/CD pipelines to ensure systems remain continuously secure and compliant in our Azure cloud ecosystem. Leveraging your expertise, you will focus heavily on automating technical controls for data persistence layers, ensuring our infrastructure remains continuously compliant with SOC 1/2, NIST and PCI-DSS throughout a complex ecosystem.
A Day in the Life
- Compliance-as-Code: Embed security checks directly into development workflows and Infrastructure-as-Code (IaC) to block non-compliant deployments before they reach production.
- Policy-as-Code (PaC) Engineering: Design, write, and maintain executable policies using Azure Policy, Open Policy Agent (OPA), or Rego to prevent non-compliant infrastructure deployments.
- Continuous Control Monitoring (CCM): Build and maintain automated pipelines that continuously audit cloud environments, specialized database clusters, and storage systems against compliance baselines.
- Database & Data Compliance: Design automated controls for database security, focusing on data-at-rest encryption, automated key rotation, data masking, database activity monitoring (DAM), and secure access controls (IAM/PIM).
- CI/CD Security Integration: Inject automated compliance and configuration checks directly into our DevOps deployment pipelines to catch configuration drifts before code reaches production.
- Audit Evidence Automation: Develop Python, PowerShell, or Go scripts to automatically gather, aggregate, and store point-in-time evidence for SOC, NIST, and PCI audits.
- Remediation Automation: Solution to automatically remediate any potential control failures including Attestations
- Risk Assessments: Identify, document, and quantify technical security risks, threats, and vulnerabilities, translating them into business-impact metrics for leadership.
- Perform all other duties as assigned.
Qualifications
- Bachelors Degree in Computer Science, Cybersecurity, Management Information Systems (MIS), or equivalent experience
- Exceptional background in database administration with deep knowledge of technical database compliance rules (PCI-DSS) requirements and knowledgable in Security GRC practices.
- 10 + years as subject matter expert formerly in DBA roles and/or GRC Engineer
- Strong program management skills in large complex organizations.
- Propose solutions and implement effectively with minimal oversight.
- Capable of building strong relationships with Security, Engineering, Product and other key stakeholders.
- Ability to demonstrate GRC Engineering practices and use of AI solutions.
- Previous GRC tooling for control automation experience highly desired.
Pay Equity
$110,100.00 - $143,100.00
Actual Pay will be adjusted based on experience and other job-related factors permitted by law.
Great Work/Life Benefits!
Competitive wages
Medical with telemedicine
Dental and Vision
Basic and Optional Life Insurance
Paid Time Off (PTO)
Maternity, Parental, Family Care
Community Volunteer Time Off
12 Paid Holidays
Company Paid Disability Insurance
401k (with employer match)
Health Savings Accounts (HSA) with company provided contributions
Flexible Spending Accounts (FSA)
Supplemental Insurance
Mental Health and Well-being: Employee Assistance Program (EAP)
Tuition Reimbursement
Wellness program
Benefits are subject to generally applicable eligibility, waiting period, contribution, and other requirements and conditions