GRC Engineer

Posted 9 Hours Ago
Be an Early Applicant
5 Locations
In-Office or Remote
Entry level
Insurance • Software • Financial Services
The Role
Own customer-facing security assurance, including questionnaires, diligence requests, security reviews, and trust materials. Manage SOC 2 and ISO 27001 compliance programs, audits, evidence collection, control monitoring, risk registers, vendor reviews, and remediation plans. Automate GRC workflows and partner with Product, Engineering, Legal, Sales, and Customer Success to translate security and regulatory requirements into practical controls. Define program metrics and support secure product design and roadmap decisions.
Summary Generated by Built In
About Glow

Glow is on a mission to transform how enterprises proactively protect the modern endpoint with an agentic-first approach. Our platform gives security teams the visibility, context, and autonomous remediation they've never had before — across every endpoint, application, and AI tool in the environment. We move fast, we build things that matter, and we believe security should be a force multiplier for the business, not a bottleneck. Let's Glow.

About the role ...

At Glow - we’re looking for a pragmatic, technically curious GRC Engineer to help customers trust our company and products.

You’ll own customer-facing security assurance work, including security questionnaires, diligence requests, and customer calls. You’ll also manage and automate our compliance programs, improve the systems we use to collect evidence and monitor controls, and partner with Product and Engineering to design effective controls as the product evolves.

This role is ideal for someone who enjoys translating between customers, auditors, security teams, and product builders—and who believes compliance should enable the business rather than create unnecessary bureaucracy.

What you'll do ...
  • Build the process to own and complete customer security questionnaires, assessments, and due-diligence requests accurately and efficiently.

  • Join customer and prospect calls to explain our security posture, controls, architecture, and risk-management practices.

  • Build and maintain reusable trust materials, including standard responses, evidence packages, security documentation, and trust-center content.

  • Manage compliance programs and audits, such as SOC 2 and ISO 27001, from readiness through evidence collection, testing, remediation, and ongoing monitoring.

  • Automate evidence collection, control monitoring, questionnaire responses, and other repetitive GRC workflows.

  • Automate and own the process for maintaining policies, risk registers, control mappings, vendor reviews, and remediation plans.

  • Partner with Product, Engineering, IT, Legal, Sales, and Customer Success to address security and compliance requirements.

  • Help Product and Engineering teams translate regulatory, contractual, and customer requirements into practical product and operational controls.

  • Participate in product design and roadmap discussions, identifying control requirements early and recommending solutions that are secure, scalable, and usable.

  • Track emerging customer expectations and compliance requirements, then help prioritize improvements to our security program.

  • Define metrics that show the effectiveness, efficiency, and business impact of the GRC and customer-trust program.

What you'll bring ...
  • Experience in GRC, security assurance, customer trust, compliance, security engineering, or a related field.

  • A love of building from the ground up.

  • Hands-on experience completing customer security questionnaires and supporting customer security reviews.

  • Strong written and verbal communication skills, including the ability to explain technical and compliance topics clearly to both technical and non-technical audiences.

  • Experience managing or supporting frameworks such as SOC 2, ISO 27001, NIST CSF, NIST 800-53, or similar standards.

  • Working knowledge of common SaaS and cloud security controls, including identity and access management, encryption, logging, vulnerability management, secure development, incident response, business continuity, and vendor risk.

  • Ability to evaluate evidence critically rather than treating compliance as a checklist.

  • Strong project-management skills and comfort coordinating work across multiple teams.

  • An automation mindset, with an interest in using APIs, scripts, integrations, AI, or GRC platforms to reduce manual work.

  • Curiosity about how products are designed and a desire to help teams build controls into systems from the beginning.

  • Sound judgment when balancing security, customer commitments, usability, and business needs.

You might also bring ...
  • Experience at startups, B2B SaaS, cloud, infrastructure, fintech, healthcare, or other security-conscious technology company.

  • Familiarity with privacy and regulatory requirements such as GDPR, CCPA/CPRA, HIPAA, PCI DSS, or FedRAMP.

  • Experience with GRC automation, trust-center, or questionnaire-management platforms.

  • Ability to read technical architecture diagrams, audit logs, configurations, and code well enough to validate control design and evidence.

  • Experience designing product-level controls, such as audit logging, role-based access, data retention, tenant isolation, or administrative safeguards.

  • Relevant certifications such as CISSP, CISA, CISM, CRISC, CCSK, or ISO 27001 Lead Implementer/Auditor. Certifications are helpful but not required.

At Glow, we believe our greatest strength is our people. We're committed to building an inclusive workplace where every team member feels welcomed, respected, and empowered to do their best work. We know that diverse backgrounds, experiences, and perspectives make us stronger as a company and better partners to our customers.

Glow is proud to be an equal opportunity employer. We celebrate diversity and are committed to creating an environment free from discrimination and harassment. We make all employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, genetic information, or any other characteristic protected by applicable law.

Skills Required

  • Experience in GRC, security assurance, customer trust, compliance, security engineering, or a related field
  • Hands-on experience completing customer security questionnaires and supporting customer security reviews
  • Strong written and verbal communication skills for technical and non-technical audiences
  • Experience managing or supporting SOC 2, ISO 27001, NIST CSF, NIST 800-53, or similar frameworks
  • Working knowledge of SaaS and cloud security controls, including identity and access management, encryption, logging, vulnerability management, secure development, incident response, business continuity, and vendor risk
  • Ability to evaluate evidence critically and assess control effectiveness
  • Strong project-management skills and ability to coordinate work across multiple teams
  • Interest in using APIs, scripts, integrations, AI, or GRC platforms to automate workflows
  • Curiosity about product design and ability to help build controls into systems early
  • Sound judgment balancing security, customer commitments, usability, and business needs
  • Experience at startups, B2B SaaS, cloud, infrastructure, fintech, healthcare, or another security-conscious technology company
  • Familiarity with GDPR, CCPA/CPRA, HIPAA, PCI DSS, or FedRAMP
  • Experience with GRC automation, trust-center, or questionnaire-management platforms
  • Ability to read technical architecture diagrams, audit logs, configurations, and code to validate controls and evidence
  • Experience designing product-level controls such as audit logging, role-based access, data retention, tenant isolation, or administrative safeguards
  • Certifications such as CISSP, CISA, CISM, CRISC, CCSK, or ISO 27001 Lead Implementer/Auditor
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
100 Employees
Year Founded: 2018

What We Do

Glow is a San Francisco-based digital insurance agency and software company focused on small businesses. Its technology platform automates the insurance process, helping businesses purchase coverage more efficiently while providing an intelligent insurance platform. Founded in 2018, Glow combines insurance expertise with software and automation to modernize how commercial insurance is distributed and managed for small-business customers. The company aims to transform insurance by making protection more accessible and streamlined.

Similar Jobs

Block Logo Block

Senior GRC Engineer

Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
In-Office or Remote
8 Locations
12000 Employees
185K-327K Annually

ShorePoint Inc Logo ShorePoint Inc

Archer GRC Developer

Artificial Intelligence • Information Technology • Software • Cybersecurity
In-Office or Remote
Herndon, VA, USA
102 Employees

Granicus LLC Logo Granicus LLC

Automation Engineer

Cloud • Marketing Tech • Professional Services • Social Impact • Software
Remote
US
1500 Employees
104K-123K Annually

Playlist Logo Playlist

Senior GRC Engineer

Artificial Intelligence • Beauty • Fitness • Software
Remote
United States
2954 Employees
150K-170K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account