Security Engineer, GRC

Treasure AI

• $110K — $130K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years in Security Engineering, DevSecOps, or Technical GRC with a strong focus on automation and tooling.
  • Proficient in Python and/or TypeScript; capable of building integrations without guidance.
  • Hands-on experience creating automation in enterprise settings, extending functionalities rather than just using default features.
  • Experience with modern GRC platforms like Vanta, Drata, or Secureframe, including API use and custom workflows.
  • Familiarity with compliance standards such as SOC 2 and ISO 27001, and ability to test controls programmatically.
  • Demonstrated experience with AI-assisted automation and coding tools like Claude Code.
  • Knowledge of AWS security controls and CI/CD workflows, with an understanding of embedding compliance checks.

Responsibilities

  • Automate GRC tasks by building AI workflows using tools like Claude or MCP integrations.
  • Maintain and extend the GRC platform's technical configuration through APIs and custom rules.
  • Streamline executive reporting with automated workflows to minimize build time.
  • Design continuous monitoring systems to pull real-time compliance signals from source systems.
  • Translate compliance controls into codified checks and contribute logic where gaps exist.
  • Embed compliance checkpoints in design workflows to catch issues before deployment.
  • Support quantitative risk modeling using data pipelines to demonstrate risk scenarios clearly.

Benefits

  • Comprehensive medical, dental, and vision plans, including Employee Assistance Program (EAP).
  • Company-paid life insurance at 3x salary and disability coverage.
  • Retirement planning with a 4% company match on 401K.
  • Flexible Time Off (FTO) policy and up to 26 weeks of paid parental leave.
  • Access to global reproductive health and family-building benefits through Carrot.
  • Restricted Stock Units (RSUs) which offer a stake in the company.
Full Job Description
Your Role:

Treasure AI is hiring a Security Engineer, GRC to architect, build, and automate the systems that power our Trust & Assurance (T&A) program. The right person for this role gets frustrated by manual compliance work - not because it's beneath them, but because they know it doesn't have to exist.

This role sits at the intersection of security engineering and GRC. You will design, operate, and maintain the systems that make compliance continuous, visible in real-time, and GRC insights actionable. You will treat the GRC platform as a programmable surface, extend it via APIs and agent workflows, and integrate it with the rest of Treasure AI's tech stack.

You will work closely with GRC Specialists, taking program requirements and translating them into technical implementations - automations, integrations, dashboards, guardrails, and tooling. You will also work directly with Security, IT, Engineering, and Product teams to embed compliance into the systems and pipelines they already use.

AI fluency is a baseline expectation. You will use agentic tools to accelerate your own work and will build AI-powered automations into GRC workflows - from evidence ingestion to questionnaire response to executive reporting.

Responsibilities & Duties:
  • Build AI agent workflows (using Claude, MCP integrations, or similar) to automate repeatable GRC tasks.
  • Configure and maintain the technical configuration and extension of our GRC platform - architect data relationships, configure control workflows, build custom rules, and extend the platform via APIs and webhooks rather than relying on the default UI.
  • Build automated executive readout workflows so monthly and quarterly GRC reporting is a 30-minute review, not a multi-day build.
  • Design and operate automated evidence collection pipelines and continuous control monitoring - pulling signals directly from source systems in real time so drift is surfaced before audit time, not during it.
  • Translate controls into testable, codified checks. Identify gaps in compliance coverage across CI/CD pipelines and IaC (Terraform) and contribute compliance logic where gaps exist.
  • Embed lightweight compliance checkpoints into design review workflows, ensuring control-relevant changes are flagged before deployment.
  • Support FAIR-informed quantitative risk modeling with data pipelines and tooling that make risk scenarios computable rather than narrative-only.
  • Build and maintain automation for the TPRM lifecycle - vendor intake, risk scoring, questionnaire distribution, evidence analysis, and remediation tracking - using AI-assisted tooling to reduce per-vendor manual effort.
  • Build tooling and dashboards that give the GRC Specialist and business stakeholders a continuous view of privileged access, access exceptions, and open remediation items - replacing point-intime UAR reports with an always-on IGA posture.
  • Build and maintain automation across the customer trust surface - AI-assisted questionnaire response pipelines, RFP contribution workflows, and trust center content management - so customer assurance accelerates deals rather than bottlenecking them.
  • Build automation across the security awareness and training lifecycle - detecting end-user risk signals or policy violations to improve the culture of security.


Required Qualifications:
  • At least 3+ years in Security Engineering, DevSecOps, Technical GRC, or a closely adjacent function - with a demonstrably strong engineering track record in automation and tooling, not just program ownership.
  • Strong coding foundation: proficient in Python and/or TypeScript, comfortable calling REST APIs, handling JSON/YAML payloads, building webhooks, and shipping integrations from scratch without hand-holding or assistance. You treat Jira, Confluence, Slack, and similar enterprise tools as systems to integrate with, not just UIs to click through.
  • Hands-on experience building automation and integrations in enterprise environments - not just configuring OOTB features, but writing code to extend or connect systems.
  • Practical hands-on experience with a modern GRC platform (Vanta, anecdotes, Drata, Secureframe, or similar) - you've configured custom workflows, written rules, and used the APIs; not just the UI.
  • Working knowledge of SOC 2, ISO 27001/17/18, ISO 42001 and HIPAA - enough to read a control and determine how to test it programmatically.
  • Demonstrated experience shipping AI-assisted automation: agent workflows, prompt pipelines, LLM-integrated integrations, or similar. Comfort with agentic coding tools (Claude Code, Cursor, or equivalent).
  • Familiarity with the AWS security control surface (IAM, CloudTrail, Config, GuardDuty) and how to consume compliance signals via API; working knowledge of CI/CD workflows (GitHub Actions or similar) and IaC (Terraform or equivalent) - you understand where compliance checks can be embedded in a deployment pipeline.
  • Strong collaboration and written communication skills - able to work across multiple Security domains, IT, Engineering, Legal/Privacy, and GTM, and able to write clear technical documentation.

Travel Requirements:

Annual team on-site in the US/CAN (total travel:
Perks and Benefits (US):

Our benefit package showcases our culture of care and empathy with
  • Comprehensive medical, dental, vision plans and Employee Assistance Program (EAP)
  • Competitive compensation packages
  • Company paid life insurance 3x salary
  • Company paid short- and long-term disability coverage
  • Retirement planning (401K) with 4% company match
  • Restricted Stock Units (RSU)
  • Flexible Time Off (FTO)
  • Up to 26 weeks paid parental leave including a post-partum night nurse
  • Comprehensive support and access to care for everyone, everywhere through Carrot - our global reproductive health and family-building benefit.

This description captures the core of the role today. As we adopt AI and new ways of working, responsibilities may evolve, and we encourage team members to take initiative, lean into change, and help expand the impact of their role beyond what's listed here.

Similar Jobs

More Jobs at Treasure AI

More Information Technology Jobs

Find similar Security Engineer, GRC jobs: