GRC Engineer I
Workstreet · United States · 1 mo ago
RemoteRemoteEngineeringFull-time
About the role
We are seeking a highly motivated and detail-oriented GRC Engineer I to join our fast-growing team. The ideal candidate will have a solid background in cybersecurity compliance frameworks such as SOC 2, ISO 27001, and NIST CSF. This role requires strong communication skills and the ability to manage multiple cybersecurity compliance projects simultaneously.
Responsibilities
- Support Compliance Initiatives: Assist in implementing and maintaining cybersecurity compliance programs aligned with SOC 2, ISO 27001, and other regulatory standards.
- Maintain Documentation: Develop and update cybersecurity policies, procedures, and control evidence to support audits and assessments.
- Assist in Risk Mitigation: Work with internal and external teams to identify, track, and help remediate cybersecurity risks and control gaps.
- Coordinate Project Tasks: Support multiple compliance projects by managing documentation, timelines, and deliverables under senior guidance.
- Communicate with Clients: Engage with clients via email, chat, and calls to gather evidence, clarify compliance requirements, and provide timely updates.
- Perform Control Testing: Conduct basic control checks and assist in readiness reviews to ensure continuous compliance with internal and external standards.
- Collaborate Cross-Functionally: Partner with IT, security, and operations teams to implement corrective actions and strengthen compliance posture.
- Learn and Grow: Receive mentorship from senior team members and contribute to improving processes, templates, and playbooks for compliance delivery.
Requirements
- Strong organizational skills with the ability to manage multiple cybersecurity compliance projects concurrently
- Exceptional written and verbal English communication skills
- Proven ability to work directly with clients in the US
- Experience working in cybersecurity compliance, including SOC 2, ISO 27001, or NIST CSF frameworks
- Familiarity with creating and enforcing cybersecurity policies
- Experience working in a tech company with a focus on cybersecurity
- Thrives in a fast-paced startup environment
Nice to Have
- Familiarity with Vanta or similar compliance automation platforms
- Additional experience with frameworks such as GDPR, HIPAA, or PCI DSS
- Certifications such as ISO 27001 Lead Implementer, CISA, or Security+
Benefits
- Career Development: Clear path with mentorship and training opportunities
- Technical Training: Comprehensive onboarding on security and compliance frameworks
- Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities
- Growth Opportunity: Early-stage company with significant room for career advancement
- Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team
What You'll Need To Thrive
- Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams
- A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration
- Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams
- Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs
- Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed