Overview
Senior Security Engineer for GRC (Governance, Risk and Compliance), building automated systems that continuously test security controls and produce audit-ready evidence.
What you'll do
- Design and own automated security control monitoring systems.
- Build production-quality code (e.g., Python) under version control with peer review and CI/CD.
- Convert periodic manual testing into continuous control monitoring (CCM) with defined signals, frequency, thresholds, and alert paths.
- Implement AWS-native automated technical evidence collection so control owners and auditors can retrieve evidence on demand.
- Redesign GRC processes to be AI-native for evidence review, control mapping, and related workflows with human-in-the-loop review and validation.
- Build an end-to-end control-failure pipeline including detection, enrichment, ticket creation, routing, SLA tracking, remediation verification, and closure.
What you'll need
- 5+ years of experience on a GRC or similar team.
- 2+ years hands-on automation building with at least one scripting/programming language (Python preferred) and comfort with Git, code review, and CI/CD.
- Hands-on AWS experience for control monitoring and evidence generation (Config, Security Hub, CloudTrail, IAM, Organizations/SCPs, Lambda, EventBridge, S3/Athena, CloudWatch).
- Experience retrieving, normalizing, and reconciling data across systems via APIs/SQL and reasoning about completeness/accuracy.
- Practical experience applying LLMs/AI agents to real workflows with prompt/workflow design, output evaluation, and human review/guardrails.
- Ability to determine sufficient audit evidence and defend automated control testing/evidence to auditors.
Details
- Location: United States, Remote.
Read the full description and apply on the company’s own careers page.