Jobs · Engineering · New York

Senior GRC Engineer

Aircall · New York, NY · 1 mo ago
HybridEngineering$163k–$220k/yrFull-time

About the role

Aircall is hiring a Senior GRC Engineer to build and operate the engineering backbone of our Governance, Risk & Compliance program. You'll join the Security Engineering team, reporting to the Security Engineering Manager, and partner closely with IT, Privacy, Legal, Product, and Engineering to make compliance a continuously-verified property of how we build and run Aircall — not a once-a-year audit scramble.

This is a hands-on engineering role. You'll automate controls, integrate our GRC platform with the systems that produce evidence, and turn policies into code where possible. You'll be the technical owner of SOC 2 and ISO 27001 readiness from an engineering perspective, and a key contributor to how we mature risk management, vendor security, and audit operations as Aircall scales. This role will sit within the CTO organization, alongside Security & Infrastructure Engineering building the security foundation of a future Governance, Risk & Compliance (GRC) function.

Responsibilities

  • Design, implement, and operate technical controls that satisfy SOC 2, ISO 27001, NIST, and GDPR requirements across our cloud (AWS), SaaS, and corporate environments.
  • Build and maintain integrations between our GRC platform (Drata) and source systems — IdP, cloud providers, ticketing, code repositories, HRIS, endpoint management — to automate evidence collection and continuous control monitoring.
  • Engineer "compliance-as-code" workflows: codify policies and controls, automate drift detection, and surface failing controls back to owning teams via Jira, Slack, or dashboards.
  • Support and progressively automate audit readiness: SOC 2 Type II, ISO 27001 (and any future certifications such as HIPAA, FedRAMP, PCI as the strategy evolves), preparing evidence, walking auditors through controls, and remediating findings.
  • Operate the enterprise risk register day-to-day: run risk assessments, track mitigations, and produce reporting that helps leadership make decisions.
  • Build and run the technical side of the vendor security program — questionnaire automation, tiering, evidence review, and ongoing monitoring of critical vendors.
  • Partner with IT, Product, and Engineering to embed security and compliance requirements into the SDLC, change management, access reviews, and infrastructure provisioning.
  • Contribute to incident response from the GRC side: maintain runbooks and policies, ensure regulatory and contractual notification timelines are met, and capture evidence and lessons learned.
  • Partner with Legal/Privacy on GDPR obligations, data residency, DPAs, and customer security commitments.
  • Help mature security awareness and training — measuring effectiveness, not just running it.
  • Author and maintain security policies and standards in clear, accurate language that engineers will actually read.
  • Promote a security-first culture across all functions, ensuring employees understand their role in protecting company and customer data.

Qualifications

  • 5+ years in security, with at least 2–3 years in a GRC engineering, security engineering, or compliance automation role at a SaaS or cloud-native company.
  • Strong working knowledge of SOC 2, ISO 27001, NIST CSF / 800-53, and GDPR, and what it takes to actually operate (not just pass) them.
  • Hands-on experience with a modern GRC platform (Ideally Drata) — including building or extending its integrations, not just clicking through the UI.
  • Comfortable using AI tools to accelerate delivery and scale impact.
  • Comfortable writing code (Python, Go, or similar) and working with cloud APIs (AWS), Terraform/IaC, and CI/CD pipelines.
  • Solid understanding of cloud security, identity and access management, and how engineering teams ship software.
  • Experience supporting external audits as a technical lead and remediating findings.
  • Working knowledge of risk management frameworks and vendor security assessment.
  • Strong written communication — you can turn a control requirement into a clear ticket, runbook, or policy that gets adopted.
  • Bonus: relevant certifications (CISA, CISSP, ISO 27001 LI/LA, AWS/GCP security), experience with privacy engineering, or prior work building a GRC function from early stage to audit-ready.

Pay

Base Salary Range $163,000 - $220,000 USD

Benefits

  • Key moment to join Aircall in terms of growth and opportunities
  • Work-life balance prioritized
  • Fast-learning environment with an entrepreneurial and strong team spirit
  • 45+ nationalities represented, fostering a cosmopolitan and multicultural mindset
  • Competitive salary package and benefits

Similar jobs

Senior GRC Engineer

WorkstreetUnited States· 1 mo ago
RemoteEngineeringapply on ats.rippling.com

Senior GRC Engineer

Nexus Venture PartnersSan Francisco, CA· 1 mo ago
Engineering$180k–$200k/yrapply on job-boards.greenhouse.io

Senior GRC Engineer

PostmanSan Francisco, CA· 1 mo ago
Engineering$180k–$200k/yrapply on job-boards.greenhouse.io

Senior GRC Engineer

FlockUnited States· 1 mo ago
RemoteEngineering$130k–$145k/yrapply on jobs.ashbyhq.com

Senior GRC Engineer

BiographNew York, NY· 3 mo ago
Engineering$150k–$200k/yrapply on jobs.ashbyhq.com

Senior GRC Engineer

Life360United States· 2 mo ago
RemoteEngineering$116k–$213k/yrapply on job-boards.greenhouse.io