GRC Engineer
About the role
We're seeking a mid-level GRC Engineer to help scale our compliance program through automation and run audits across SOC 2, ISO 27001, and SOX. This role involves hands-on technical work, automation, and cross-functional collaboration.
Responsibilities
- Build and maintain automation for continuous control monitoring, evidence collection, and audit readiness through scripts, APIs, and GRC platform integrations
- Integrate compliance workflows with cloud providers, identity systems, ticketing platforms, and CI/CD pipelines to automatically collect control data and evidence
- Reduce manual compliance work by codifying control checks and pulling evidence directly from source systems
- Develop dashboards and reporting that provide stakeholders with real-time visibility into control health and audit readiness
- Run and coordinate audits for SOC 2 (Type I and Type II), ISO 27001, and SOX, including scoping, evidence collection, control walkthroughs, and auditor coordination
- Map controls across multiple compliance frameworks to reduce duplication and maintain a unified control library
- Track audit findings and control gaps through remediation and closure with business and technical stakeholders
- Maintain audit-ready documentation including policies, procedures, control narratives, and evidence repositories
- Identify, assess, and document organizational risks while maintaining the enterprise risk register
- Support risk assessments, including likelihood and impact scoring, treatment planning, and remediation tracking
- Partner with Engineering and IT to evaluate the control impact of new systems, vendors, and architectural changes
- Contribute to the third-party risk management program
- Cross-Functional Partnership: Partner with control owners to ensure controls are operating effectively and generating appropriate evidence
- Translate compliance requirements into practical, engineering-focused guidance
- Support customer security questionnaires, trust requests, and due diligence activities
Requirements
- 3–5 years of experience in GRC, IT audit, security compliance, or a related field
- Hands-on experience supporting or leading audits for SOC 2, ISO 27001, SOX, or a comparable framework
- Working knowledge of SOC 2 Trust Services Criteria, ISO 27001 Annex A, COSO/SOX ITGCs, NIST, or similar control frameworks
- Experience with scripting and automation using Python or a similar language, including working with REST APIs to automate evidence collection
- Familiarity with at least one major cloud platform (AWS, GCP, or Azure) and its security and logging services
- Strong understanding of access management, change management, logging and monitoring, vulnerability management, and SDLC controls
- Excellent written communication skills with the ability to create clear control documentation, risk assessments, and stakeholder reporting
- Able to manage multiple priorities while driving audit findings and remediation efforts to completion
Qualifications
- Bachelor’s degree in Computer Science, Information Systems, or a related field
- Experience with Infrastructure as Code (Terraform)
- Experience using SQL or data analysis for evidence collection and control sampling
- Experience with SOX ITGC testing within a public company or pre-IPO environment
- Certifications such as CISA, CISSP, CCSK, ISO 27001 Lead Implementer or Lead Auditor, or cloud security certifications
Skills
- Scripting and automation using Python or a similar language
- Cloud platform integration (AWS, GCP, Azure)
- Data analysis and evidence collection
- Access management, change management, logging and monitoring, vulnerability management, and SDLC controls
- Written communication and stakeholder reporting
- Risk assessment and mitigation
- Third-party risk management
- Collaboration with control owners and external auditors
Benefits
- Annual target bonus of 10%
- 401k with 3.5% company match
- Generous PTO
- 7 Paid Holidays Annually + 5 Conditional Holidays Annually
- Service Day
- Health, Vision, Dental Coverage
- Life and Disability Insurance
- Flexible Work Schedule
- Additional Flex Remote Days
- Company Wide Office-Optional Weeks
Pay
The salary range for this role is $130,000.00 - $145,000.00 USD. In addition, this position will also receive an annual target bonus of 10%. NinjaTrader offers a 401K plan through ADP under which the company will match up to 3.5% of employee contributions.
Schedule
This role is based in Chicago, IL. We are not open to remote candidates for this role. Hybrid: In-office Tuesday through Thursday, with remote work on Mondays and Fridays. In addition to these weekly remote days, we offer: 20 additional flex remote days annually, 5 Company Wide Office-Optional weeks tied to major holidays.