Glow is on a mission to transform how enterprises proactively protect the modern endpoint with an agentic-first approach. Our platform gives security teams the visibility, context, and autonomous remediation they've never had before — across every endpoint, application, and AI tool in the environment. We move fast, we build things that matter, and we believe security should be a force multiplier for the business, not a bottleneck. Let's Glow.
About the role ...At Glow - we’re looking for a pragmatic, technically curious GRC Engineer to help customers trust our company and products.
You’ll own customer-facing security assurance work, including security questionnaires, diligence requests, and customer calls. You’ll also manage and automate our compliance programs, improve the systems we use to collect evidence and monitor controls, and partner with Product and Engineering to design effective controls as the product evolves.
This role is ideal for someone who enjoys translating between customers, auditors, security teams, and product builders—and who believes compliance should enable the business rather than create unnecessary bureaucracy.
What you'll do ...Build the process to own and complete customer security questionnaires, assessments, and due-diligence requests accurately and efficiently.
Join customer and prospect calls to explain our security posture, controls, architecture, and risk-management practices.
Build and maintain reusable trust materials, including standard responses, evidence packages, security documentation, and trust-center content.
Manage compliance programs and audits, such as SOC 2 and ISO 27001, from readiness through evidence collection, testing, remediation, and ongoing monitoring.
Automate evidence collection, control monitoring, questionnaire responses, and other repetitive GRC workflows.
Automate and own the process for maintaining policies, risk registers, control mappings, vendor reviews, and remediation plans.
Partner with Product, Engineering, IT, Legal, Sales, and Customer Success to address security and compliance requirements.
Help Product and Engineering teams translate regulatory, contractual, and customer requirements into practical product and operational controls.
Participate in product design and roadmap discussions, identifying control requirements early and recommending solutions that are secure, scalable, and usable.
Track emerging customer expectations and compliance requirements, then help prioritize improvements to our security program.
Define metrics that show the effectiveness, efficiency, and business impact of the GRC and customer-trust program.
Experience in GRC, security assurance, customer trust, compliance, security engineering, or a related field.
A love of building from the ground up.
Hands-on experience completing customer security questionnaires and supporting customer security reviews.
Strong written and verbal communication skills, including the ability to explain technical and compliance topics clearly to both technical and non-technical audiences.
Experience managing or supporting frameworks such as SOC 2, ISO 27001, NIST CSF, NIST 800-53, or similar standards.
Working knowledge of common SaaS and cloud security controls, including identity and access management, encryption, logging, vulnerability management, secure development, incident response, business continuity, and vendor risk.
Ability to evaluate evidence critically rather than treating compliance as a checklist.
Strong project-management skills and comfort coordinating work across multiple teams.
An automation mindset, with an interest in using APIs, scripts, integrations, AI, or GRC platforms to reduce manual work.
Curiosity about how products are designed and a desire to help teams build controls into systems from the beginning.
Sound judgment when balancing security, customer commitments, usability, and business needs.
Experience at startups, B2B SaaS, cloud, infrastructure, fintech, healthcare, or other security-conscious technology company.
Familiarity with privacy and regulatory requirements such as GDPR, CCPA/CPRA, HIPAA, PCI DSS, or FedRAMP.
Experience with GRC automation, trust-center, or questionnaire-management platforms.
Ability to read technical architecture diagrams, audit logs, configurations, and code well enough to validate control design and evidence.
Experience designing product-level controls, such as audit logging, role-based access, data retention, tenant isolation, or administrative safeguards.
Relevant certifications such as CISSP, CISA, CISM, CRISC, CCSK, or ISO 27001 Lead Implementer/Auditor. Certifications are helpful but not required.
At Glow, we believe our greatest strength is our people. We're committed to building an inclusive workplace where every team member feels welcomed, respected, and empowered to do their best work. We know that diverse backgrounds, experiences, and perspectives make us stronger as a company and better partners to our customers.
Glow is proud to be an equal opportunity employer. We celebrate diversity and are committed to creating an environment free from discrimination and harassment. We make all employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, genetic information, or any other characteristic protected by applicable law.
Skills Required
- Experience in GRC, security assurance, customer trust, compliance, security engineering, or a related field
- Hands-on experience completing customer security questionnaires and supporting customer security reviews
- Strong written and verbal communication skills for technical and non-technical audiences
- Experience managing or supporting SOC 2, ISO 27001, NIST CSF, NIST 800-53, or similar frameworks
- Working knowledge of SaaS and cloud security controls, including identity and access management, encryption, logging, vulnerability management, secure development, incident response, business continuity, and vendor risk
- Ability to evaluate evidence critically and assess control effectiveness
- Strong project-management skills and ability to coordinate work across multiple teams
- Interest in using APIs, scripts, integrations, AI, or GRC platforms to automate workflows
- Curiosity about product design and ability to help build controls into systems early
- Sound judgment balancing security, customer commitments, usability, and business needs
- Experience at startups, B2B SaaS, cloud, infrastructure, fintech, healthcare, or another security-conscious technology company
- Familiarity with GDPR, CCPA/CPRA, HIPAA, PCI DSS, or FedRAMP
- Experience with GRC automation, trust-center, or questionnaire-management platforms
- Ability to read technical architecture diagrams, audit logs, configurations, and code to validate controls and evidence
- Experience designing product-level controls such as audit logging, role-based access, data retention, tenant isolation, or administrative safeguards
- Certifications such as CISSP, CISA, CISM, CRISC, CCSK, or ISO 27001 Lead Implementer/Auditor
What We Do
Glow is a San Francisco-based digital insurance agency and software company focused on small businesses. Its technology platform automates the insurance process, helping businesses purchase coverage more efficiently while providing an intelligent insurance platform. Founded in 2018, Glow combines insurance expertise with software and automation to modernize how commercial insurance is distributed and managed for small-business customers. The company aims to transform insurance by making protection more accessible and streamlined.









