Senior Risk & Compliance Engineer - Data
Instacart · United States · 4 wk ago
RemoteRemoteManufacturing$188k–$230k/yrFull-time
About the job
Instacart's Governance, Risk and Compliance (GRC) team builds an automated, engineering-grade risk program that produces real-time risk scoring, quantified exposure models, and ROI-linked investment decisions that reach the CISO, executive leadership, and the board. We're looking for a Senior Risk & Compliance Engineer to help us get there.
Responsibilities
- Build automated signal ingestion pipelines that pull real-time data from security tooling — normalizing, enriching, and scoring raw findings into actionable, ranked risk intelligence that drives remediation decisions across the organization
- Develop probabilistic risk models that express security exposure as probability distributions, giving leadership a quantified, confidence-backed view of breach likelihood and expected losses — connecting model outputs directly to investment decisions and board-level reporting
- Identify systemic choke points across the attack surface — high-leverage remediation paths where a single fix eliminates risk at scale — and prioritize them by expected impact to maximize the efficiency of our security program
- Create dashboards and data-driven insights that cascade risk visibility across security, engineering, and executive stakeholders, translating complex model outputs into language that resonates at every level of the organization
- Support risk quantification efforts that express security exposure in financial terms, connecting model outputs to investment decisions and board-level reporting
Requirements
- 5+ years of experience in data engineering, with demonstrated ability to write production-level code in Python and SQL (PostgreSQL, Presto, or SparkSQL)
- 3+ years of experience building and deploying machine learning or probabilistic models (e.g., Bayesian models) in a production environment
- Experience building data pipelines that ingest real-time or near-real-time data across multiple formats, handling both stream and batch processing at scale
- Experience with data modeling for classification, normalization, and risk or anomaly detection signal development
- Experience developing metrics that inform security and business decisions
Qualifications
- Familiarity with security risk concepts including threat intelligence enrichment pipelines, EPSS, or CISA KEV
- Experience with quantitative risk frameworks such as FAIR
- Experience with security frameworks such as NIST CSF, SOC 2 as context for what controls the data is measuring
- Demonstrated ability to translate risk model outputs into executive or board-level narratives
- A genuine passion for building systems that protect customers and products, and a track record of operating effectively in fast-paced, ambiguous environments where the program is still being shaped