GRC Engineer

Posted 2 Days Ago
Be an Early Applicant
Santa Clara, CA, USA
In-Office
140K-170K Annually
Mid level
Software • Analytics
The Role
Build and maintain automated GRC workflows, including control testing, policy management, audit readiness, risk assessments, vendor reviews, and compliance integrations. Manage GRC platforms through scripts and APIs, support SOC 2 audits, and help establish ISO 27001/42001 readiness. After initial automation work, contribute to security operations through SIEM/SOAR administration, alert triage, endpoint support, incident response, and post-mortems.
Summary Generated by Built In

Forward was founded in 2013 by four Stanford Ph.D.s, building the industry's first network digital twin: a mathematically accurate model of the production network. It's the foundation for autonomous networking, giving engineers and AI agents the ability to know the impact of every change before it touches production. That founding instinct still defines how we work. We're accurate and evidence-driven, relentless about clarity, and we'd rather be certain than comfortable, building a groundbreaking platform that transforms how teams run and secure networks across every major cloud and vendor environment.

Global leaders like Goldman Sachs, PayPal, S&P Global, IBM, and Dell trust Forward, alongside fast-growing enterprises and government agencies, realizing an average of $14.2 million in annual benefits, according to IDC. Backed by top-tier investors, including A. Capital, Andreessen Horowitz, Goldman Sachs, MSD Partners, Omega Venture Partners, Section 32, and Threshold Ventures, and headquartered in Santa Clara, we're most proud of our team: curious people who'd rather build what doesn't exist than accept how things have always been done.
Forward is looking for a GRC Engineer. GRC Engineering is a new discipline: instead of chasing down screenshots every quarter and hoping the auditor doesn't ask too many follow-up questions, you're building scripts and API integrations that pull evidence straight from the source systems and keep it current on their own. If you've spent any time reading about the field, you've probably run into grc.engineering, the GRC Engineering Club, or grcengineer.com. We'd rather hire someone who already thinks this way than someone who needs to be convinced of it; if your engineering skills enable doing more than a traditional GRC Analyst role, you're the right fit.

Your initial focus, likely for the next 6 months, is GRC Engineering: compliance automation, audit management (SOC 2, ISO 27001/42001), control design and testing, and risk management. 

Once the most critical automations are in place, this job broadens to include a  Security Operations piece: mostly SIEM and SOAR work plus whatever incident response comes up.  This is your chance to go beyond mere exposure to SecOps work, to directly participate in alert triage, SIEM/SOAR administration and tuning, enforcement work, and incident response. This is a real split, and we're looking for someone who can grow to handle both types of work.

What You'll Do

GRC Engineering (main focus of role)

  • Policy & Documentation: Write, maintain, and actively drive review cycles for security policies and procedures.
  • Automated Control Testing: Build control tests that verify real system configurations directly at the source, rather than manual spreadsheets. If a control says MFA is enforced, you should be able to verify that in the identity provider yourself.
  • Manage and extend our GRC platform (Vanta, Drata, etc.) using scripts and API integrations.
  • Control Monitoring: Continuously manage control drift between audits and drive remediation to completion.
  • Audit Management: Lead day-to-day SOC 2 Type II audits and lay groundwork for ISO 27001 and ISO 42001.
  • Risk Management: Maintain a prioritized risk register and run actionable risk assessments.
  • Handle vendor security reviews and due diligence: pull evidence from a vendor's API or trust page, rather than mailing them a 40-question spreadsheet.
  • Engineering Collaboration: Integrate compliance requirements directly into engineering workflows, such as CI/CD, access provisioning, and change management.  

Security Operations (additional piece after critical automations in place)

  • SIEM & SOAR Admin: Tune detection rules, correlation logic, and response playbooks. 
  • Endpoint Support: assist with EDR, DLP, and endpoint break/fix and incident response cases.
  • Alert Triage: Participate in security alert triage and documentation.
  • Jump into incident response when something happens: investigation, helping contain it, and post-mortem write-ups.
  • Feed what you see in the SOC back into the GRC side of your job. If operations tell a different story than what the compliance platform says, that gap is worth knowing about.

What We're Looking For

Required

  • 3+ years in GRC, compliance, security engineering, IT audit, or equivalent, with on-the-job exposure to control design, risk assessment, AND compliance frameworks. 
  • Experience writing policies and procedures, with a focus on testable and verifiable outcomes. 
  • Time spent doing real work in a GRC/compliance automation platform (Vanta, Drata, Thoropass, Anecdotes, or similar).
  • Solid working knowledge of SOC 2. ISO 27001 experience is a plus. ISO 42001 is a possible future endeavor, but curiosity about AI governance is important.
  • Basic scripting knowledge: Python or Bash, SQL, and comfortable pulling data from an API, parsing a log file, or automating something you used to do by hand. This is not a software engineer role and you will be able to take advantage of AI to assist, but the ability to read, troubleshoot, and deliver working scripts is a requirement. 
  • Some exposure to SIEM/SOAR tooling (Splunk, Chronicle, Panther, XSOAR, Tines, whatever you've used) and a basic feel for how incident response actually runs.
  • The ability to speak to an auditor and an engineer in languages they understand, as both the GRC and engineering skill sets will be utilized.
  • A tolerance for ambiguity. "GRC Engineer" is an evolving field/role. We will be figuring out parts of this role as time goes on together. 
  • Experience with endpoint compliance in a Mac-centric environment. 

Nice to Have

  • We run in the cloud but also still operate our own data center, so comfort with straight Linux administration and scripting matters just as much as anything cloud-native. If you've worked with Terraform or policy-as-code, that helps too.
  • Certs like Security+, CISA, CISSP, or ISO 27001 Lead Implementer/Auditor are fine to have. We just care more about whether you can trace a control back to the system it's actually describing.
  • Time spent tuning or migrating a SIEM/SOAR setup, or running incident response for real, not just in a tabletop exercise.
  • Understanding tabletop exercises, how to run them, how to conduct a post-mortem and how to drive the findings to completion with stakeholders. 

The base pay range for this role is between $140,000 and $170,000. This range represents the low and high end of the salary for this position. Actual compensation will vary based on factors including location, candidate experience, skills, and level.

Skills Required

  • 3+ years of experience in GRC, compliance, security engineering, IT audit, or equivalent
  • Experience with control design, risk assessment, and compliance frameworks
  • Experience writing security policies and procedures with testable, verifiable outcomes
  • Hands-on experience with a GRC or compliance automation platform such as Vanta, Drata, Thoropass, or Anecdotes
  • Solid working knowledge of SOC 2
  • Basic scripting with Python or Bash, SQL, and API data extraction
  • Exposure to SIEM/SOAR tools and incident response processes
  • Ability to communicate effectively with auditors and engineers
  • Experience with endpoint compliance in a Mac-centric environment
  • ISO 27001 experience
  • Curiosity about AI governance and ISO 42001
  • Linux administration and scripting experience
  • Terraform or policy-as-code experience
  • Security+, CISA, CISSP, or ISO 27001 Lead Implementer/Auditor certification
  • Experience tuning or migrating SIEM/SOAR systems
  • Hands-on incident response experience beyond tabletop exercises
  • Experience running tabletop exercises, post-mortems, and remediation follow-through

Forward Networks Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Forward Networks and has not been reviewed or approved by Forward Networks.

  • Fair & Transparent Compensation — Pay is considered competitive for a mid-stage infrastructure/software company across several roles and locations. Signals point to strong totals in technical and select go-to-market positions.
  • Equity Value & Accessibility — Equity is broadly offered to all employees, creating ownership potential alongside salary and bonus. As a private company, perceived value can rise with company performance and future liquidity.
  • Healthcare Strength — Medical, dental, and vision coverage is described as top-grade for employees and dependents. Company materials consistently highlight strong core health benefits across hiring channels.

Forward Networks Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Palo Alto, CA
70 Employees
Year Founded: 2013

What We Do

The future of network operations is network modeling. Forward Networks' flagship platform Forward Enterprise gives users a mathematically accurate network digital twin. Forward enables perfect network visibility, full path analysis, security policy verification, and change prediction, freeing up time and saving you money.

Similar Jobs

Block Logo Block

Senior GRC Engineer

Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
In-Office or Remote
8 Locations
12000 Employees
185K-327K Annually

Cursor Logo Cursor

Security GRC Engineer

Artificial Intelligence • Generative AI
In-Office
2 Locations
300 Employees
In-Office
Sandoz, CA, USA
17135 Employees

Higgsfield AI Logo Higgsfield AI

Lead GRC Engineer

Artificial Intelligence • Marketing Tech • Software • Generative AI
Remote or Hybrid
8 Locations
70 Employees
220K-280K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account