Overview
Design, build, and scale automation and AI-driven solutions that modernize the security governance, risk, and compliance program. Translate manual, evidence-heavy processes into automated, data-driven workflows.
What you'll do
- Design, build, and maintain automation pipelines that continuously collect, normalize, and validate compliance and control evidence across security and business systems.
- Evaluate, prototype, and deploy AI and large language model (LLM)-based solutions for control testing, evidence review, policy mapping, and risk narrative generation.
- Integrate GRC tooling such as Onspring, Archer, MetricStream, or similar platforms with security and IT systems via APIs to enable automated data flows, dashboards, and reporting.
- Develop and maintain scripts, bots, and workflow tools that automate evidence gathering, control monitoring, and audit preparation.
- Partner with Security GRC analysts and program managers to identify manual, repetitive processes and re-engineer them into scalable, automated solutions.
- Establish guardrails, testing, and quality controls to ensure AI-assisted outputs are accurate, explainable, and compliant with regulatory and audit requirements.
- Monitor and report on the performance, reliability, and risk posture of automation and AI tools used within the GRC program.
- Stay current with emerging AI, automation, and GRC technologies and recommend new tools and techniques to improve program maturity.
- Collaborate with security, engineering, data, and business teams to align automation initiatives with broader security posture and compliance goals.
What you'll need
- Bachelor’s degree in computer science, information security, information systems, or a related field, or equivalent experience.
- 5+ years of experience in security engineering, GRC, or a related field, with demonstrated experience building automation or AI-enabled solutions.
- Strong programming and scripting skills, such as Python, JavaScript, or similar.
- Experience working with APIs, databases, and workflow automation tools.
- Hands-on experience applying AI or machine learning technologies, including LLMs and generative AI, to real-world business or security use cases.
- Solid understanding of cybersecurity frameworks including NIST, ISO 27001, and SOC 2.
- Understanding of regulatory compliance requirements including GDPR and PCI DSS.
- Experience with GRC platforms such as Onspring, Archer, MetricStream, or similar tools, including configuration or integration work.
- Familiarity with risk assessment methodologies, control frameworks, and audit evidence requirements.
- Strong analytical and problem-solving skills, with the ability to translate complex, manual processes into automated solutions.
- Excellent communication and reporting skills, with the ability to present technical solutions and their risk and compliance impact to technical and non-technical stakeholders.
Details
Read the full description and apply on the company’s own careers page.