GRC Engineer

Posted 2 Days Ago
Be an Early Applicant
Hiring Remotely in USA
Remote
Senior level
Information Technology • Software
The Role
Own Clerk’s SOC 2 Type II, HIPAA, and future compliance frameworks. Design controls, manage evidence and audits, lead vendor reviews, maintain risk assessments, and oversee security questionnaires and trust center workflows. Build integrations, automations, policy-as-code checks, configuration drift detection, and control-failure pipelines across cloud, SaaS, and internal systems. Embed compliance into software development and change management while reducing manual audit work.
Summary Generated by Built In
About Clerk

Clerk is on a mission to solve the user identity layer once and for all. We are a globally distributed team dedicated to providing best-in-class developer infrastructure to build the next generation of AI software. Today, we provide developers with full-stack React components and hooks like , , , useUser, and useOrganization. These APIs allow developers to build hard-to-get-right infrastructure for user identity, organization management and billing flows. We believe that a component is worth a thousand APIs.

Clerk is looking for a Senior GRC Engineer to join our Security Team. Our customers put Clerk in the middle of their authentication flow, and every one of them runs us through their own vendor review before they do. You'll own the program that makes that review easy: the controls, the evidence, the audits, and the answers.

You'll work as a hands-on engineer. Expect to spend a lot of your time writing integrations, automations, and internal tools that enforce policies and automate the evidence gathering. The goal is a program that's always current, so an audit is just someone observing it rather than a quarterly scramble.

What you'll do
  • Own SOC 2 Type II and HIPAA end to end: scoping, control design, evidence, auditor walkthroughs, and remediation

  • Scope and lead our next framework (ISO 27001 is the likely candidate) based on what customers actually ask for

  • Build and maintain the integrations that feed our GRC platform from our cloud providers, SaaS tools, and internal systems

  • Turn controls into continuous checks: policy-as-code, config drift detection, and a control-failure pipeline from detection to closure

  • Run the vendor security review program, from intake to periodic re-review

  • Own the security questionnaire and trust center workflow

  • Maintain the risk register and run risk assessments that produce documented decisions

  • Embed compliance requirements into the SDLC and change management so they're enforced by tooling, not by reminders

  • Reduce the number of things a human has to do to pass an audit every quarter

Who you are
  • 5+ years in security, with demonstrated experience building automation for a GRC or compliance program

  • You've been the technical owner of at least one SOC 2 Type II or ISO 27001 audit and can tell us what you would do differently

  • You write code, and you use LLMs to get more done without lowering the bar

  • Hands-on with a GRC platform's API, not just its dashboard

  • Cloud IAM and configuration depth on at least one provider, GCP preferred

  • You can decide what evidence is sufficient and defend an automated test to an auditor

  • Comfortable being one of a few security engineers; you can scope, prioritize, and ship without a lot of process around you

  • Clear writer: policies, control narratives, and questionnaire answers are read by customers, so they have to be good

Nice-to-haves
  • Experience at an all-remote company

  • Shipped LLM or agentic workflows in production for compliance work

  • Experience at a developer-tools company

Benefits
  • Competitive Salary – We want you to know that we value the skills and experience you bring to the table. We go out of our way to make sure that you feel fairly compensated.

  • Equity Ownership – At Clerk, we believe in shared success. That's why we offer a stock option plan so that everyone can benefit from the growth and prosperity of the company.

  • Health Coverage – We care about your well-being. That's why we offer top-tier health insurance to ensure that your health needs are fully met.

  • Work Gear - Set up your ideal home office with the gear of your choice. At Clerk, we want to ensure that you have everything you need to perform at your best.

  • Flexible Vacation Policy – We believe in work-life balance and trust you to take the time you need. Although we recommend 25 days per year, our vacation policy is unlimited. This is in addition to observing national holidays specific to your country of residence.

  • Diverse and Inclusive Team – Join our exceptional, diverse, and globally distributed team at Clerk. We are committed to fostering an inclusive environment where everyone can contribute their best in building impactful products and tools for the modern web.

Skills Required

  • 5+ years of experience in security
  • Experience building automation for a GRC or compliance program
  • Technical ownership of at least one SOC 2 Type II or ISO 27001 audit
  • Ability to write code and use LLMs productively
  • Hands-on experience with a GRC platform API
  • Cloud IAM and configuration expertise with at least one cloud provider; GCP preferred
  • Ability to determine sufficient audit evidence and defend automated tests to auditors
  • Ability to scope, prioritize, and deliver independently on a small security engineering team
  • Strong technical writing skills for policies, control narratives, and questionnaire responses
  • Experience at an all-remote company
  • Production experience shipping LLM or agentic workflows for compliance work
  • Experience at a developer-tools company
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
147 Employees
Year Founded: 2019

What We Do

Clerk is a complete suite of embeddable UIs, flexible APIs, and admin dashboards to authenticate and manage your users.

Similar Jobs

Block Logo Block

Senior GRC Engineer

Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
In-Office or Remote
8 Locations
12000 Employees
185K-327K Annually

American Express Global Business Travel Logo American Express Global Business Travel

Senior Security GRC Engineer, AI & Automation

Fintech • Software • Travel • Business Intelligence • Consulting • App development • Big Data Analytics
Remote
United States
18000 Employees
104K-194K Annually

Bright Vision Technologies Logo Bright Vision Technologies

SAP Security & GRC Engineer

Artificial Intelligence • Information Technology • Software • Consulting
In-Office or Remote
2 Locations
53 Employees
100K-150K Annually

Peraton Logo Peraton

Cloud Engineer

Aerospace • Information Technology • Security • Cybersecurity • Defense
Remote
United States
18000 Employees
112K-179K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account