Senior GRC Engineer

Flock Safety

$130K — $145K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in GRC, cybersecurity, or IT audit, specifically in SaaS or cloud environments.
  • Hands-on experience with SOC 2 and ISO 27001 audits and managing customer security due diligence.
  • Strong ability to interpret regulatory requirements and translate them into operational workflows.
  • Practical knowledge of cloud security concepts and automation platforms.
  • Industry certifications such as Security+, CISA, CRISC, or ISO 27001 Internal Auditor are advantageous.

Responsibilities

  • Lead audit readiness and evidence management for SOC 2 and ISO frameworks with an automation-first approach.
  • Architect and implement automated workflows for continuous compliance monitoring.
  • Manage customer assurance requests and security questionnaires to uphold customer trust.
  • Collaborate with Engineering, Security, Legal, Privacy, and Product teams to embed compliance controls into workflows.
  • Maintain and update security policies and compliance documentation in response to regulatory changes.

Benefits

  • Flock offers stock options as part of the compensation package.
  • Encouragement of in-person collaboration through hub-based roles in Atlanta and Boston, with some remote roles available.
Full Job Description
The Problem

As Flock scales its public safety platforms across cloud infrastructure and business operations, transforming compliance from a periodic audit exercise into a continuous, automated capability is essential. Maintaining customer trust and regulatory alignment across SOC 2, ISO, and privacy frameworks requires an engineering-driven approach to assurance. You will build scalable compliance processes, automate audit evidence collection, and embed continuous compliance frameworks directly into engineering and business workflows.

What You'll Own
  • Lead audit readiness and evidence management for SOC 2, ISO 27001, ISO 27701, and privacy frameworks using an automation-first approach.
  • Architect and deploy automated workflows to transform point-in-time audits into continuous compliance monitoring capabilities across cloud and SaaS systems.
  • Manage customer assurance requests, security questionnaires, and due diligence activities to maintain customer trust and accelerate business operations.
  • Partner with Engineering, Security, Legal, Privacy, and Product teams to integrate compliance controls directly into software development and operational processes.
  • Maintain and update security policies, controls, and compliance documentation to align with evolving regulatory requirements.


What This Role is Not
  • This isn't a traditional manual audit or checklist management role, you will focus on engineering-driven automation, workflow platform tools, and process optimization.
  • This is not an isolated policy-writing function, you will collaborate daily with technical and non-technical stakeholders to embed compliance directly into operational workflows.
  • This isn't a passive advisory position, you will own audit readiness deliverables, manage customer security reviews, and build hands-on compliance tools.


What You Bring
  • Demonstrated experience in GRC, cybersecurity, or IT audit within SaaS or cloud environments, preferably AWS.
  • Hands-on experience supporting multi-framework audits such as SOC 2 or ISO 27001, alongside managing customer security due diligence activities.
  • Capability to interpret regulatory requirements and translate compliance controls into actionable engineering and operational workflows.
  • Practical understanding of cloud security concepts, automation platforms, and workflow tools used to scale compliance operations.
  • Relevant industry certifications such as Security+, CISA, CRISC, or ISO 27001 Internal Auditor are a plus.

Compensation

In this role, you'll receive a starting salary between $130,000 and $145,000 as well as Flock Stock Options. Base salary is determined by job-related experience, education/training, as well as market indicators. Your recruiter will discuss this in depth with you during our first chat.

Some problems get solved faster in the same room, so we prioritize candidates in Atlanta and Boston. Hub-based roles mean real in-person time with your coworkers. Remote roles exist, and when a posting is open to remote work, it says so.

Similar Jobs

More Jobs at Flock Safety

More Information Technology Jobs

Find similar Senior GRC Engineer jobs: