Security Engineer, GRC

Candid Health

$130K — $155K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years in a technical security role, such as Security Engineering or Technical GRC.
  • Proficiency in Python, TypeScript, SQL; hands-on API, log parsing, and database querying experience.
  • Experience with GCP and Infrastructure-as-Code tools like Terraform.
  • Strong understanding of CI/CD pipelines and Git workflows.
  • Familiarity with security frameworks like SOC 2, HiTrust, PCI, HIPAA.

Responsibilities

  • Develop automated scripts for compliance evidence collection from system sources.
  • Write and deploy infrastructure-as-code for automatic policy enforcement.
  • Maintain real-time compliance dashboards to monitor configuration and policy violations.
  • Collaborate with legal teams on compliance related to Medicare and Medicaid.
  • Create clear, testable controls from various regulatory and industry standards.
  • Integrate compliance controls directly into CI/CD pipelines to ensure seamless delivery.
  • Lead technical audits using automated evidence and manage vendor risk management workflows.

Benefits

  • Opportunity to build a GRC program from the ground up.
  • Focus on innovative compliance automation and engineering practices.
  • Collaboration with diverse teams including legal and finance.
  • Continuous professional growth through hands-on technical leadership.
  • Engagement with cutting-edge technologies like CI/CD and cloud infrastructure.
Full Job Description
Role Overview

We are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots in spreadsheets; you will treat compliance as an engineering and data problem.

You will build automated evidence pipelines, implement compliance-as-code, and establish continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines. You will turn point-in-time audits into a continuous compliance telemetry system that keeps our platform secure, resilient, and audit-ready at all times.

Key Responsibilities

1) Compliance Automation & Engineering
  • Develop automated scripts and API integrations to collect compliance evidence directly from system sources instead of collecting manual screenshots.
  • Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically.
  • Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time.
  • Partnering with Legal on Medicare and Medicaid compliance
  • Partnering closely with legal and finance teams on future due diligence and compliance projects

2) Framework Mapping & Control Architecture
  • Convert regulatory, security, and industry standards (SOC 2, HiTrust, PCI, HIPAA) into clear, testable technical controls.
  • Map single technical controls across multiple overlapping frameworks to eliminate redundant work.
  • Work alongside DevOps and Software Engineering teams to build compliance controls directly into CI/CD pipelines without slowing down delivery.

3) Risk Management & Audits
  • Lead technical audit readiness and external audit engagements using programmatic evidence pipelines.
  • Automate vendor risk management workflows and API-driven vendor evaluations.
  • Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs rather than static quarterly surveys.


Required Qualifications
  • 3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRC.
  • Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databases.
  • Hands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as Terraform
  • Deep familiarity with core frameworks such as
  • Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes).


Preferred Qualifications
  • Certifications such as CISSP, CISA, CRISC, AWS Certified Security - Specialty, or CCSP.
  • Experience with Policy-as-Code engines
  • Background in software development, DevOps, or platform engineering.
  • Experience with modern continuous compliance platforms (e.g., Vanta, Drata, Anecdotes).

Similar Jobs

More Jobs at Candid Health

More Healthcare Jobs

Find similar Security Engineer, GRC jobs: