Senior GRC Engineer

Posted 23 Days Ago
Hiring Remotely in USA
Remote
5-7 Years Experience
Big Data • Software • Analytics
The Role
Seeking a highly skilled Senior GRC Engineer to strengthen security infrastructure, ensure compliance with industry standards, and implement advanced security practices like Policy as Code and Shift Left Security.
Summary Generated by Built In

What will you do?

  • We seek a highly skilled, experienced, and self-motivated Senior GRC Engineer.

  • As a Senior GRC Engineer you will play a critical role in fortifying our security infrastructure, ensuring compliance with industry standards such as SOC 2, HIPAA, GDPR, and ISO27001, and implementing cutting-edge security practices like Policy as Code and Shift Left Security.


    Compliance and Standards:

  • Lead efforts to maintain and enhance compliance with industry standards, including SOC2 Type2, HIPAA, GDPR, ISO27001, and USDPI.
  • Stay updated with current regulatory changes and ensure our security practices align with evolving requirements.
  • Build a unified compliance framework (UCF) that captures cybersecurity, data protection, and business continuity risks.
  • Create policies and processes in collaboration with security engineers such that they comply with the UCF, covering cloud security, application security, endpoint security, and data privacy.
  • Set up a review of all policies in practice to ensure all policies are adhered to at all times. Review and validate if the approach/solution taken to address the security and privacy risks/policies is appropriate.
  • Data Privacy: To be able to guide various teams on data protection practices. Review legal documents related to security/privacy as and when required.
  • Be the subject matter expert (SME) for security and privacy compliance and address queries/scenarios that might arise from different departments.
  • Stay up to date with security compliance frameworks and best practices to contribute towards the overall security posture of Atlan.
  • Policy as a Code

  • Identify the opportunities for implementing Policy as a Code, to minimise manual intervention.
  • Partner with security engineers to drive the implementation of Policy as Code methodologies to automate and enforce security policies throughout the organization.
  • Shift Left Security

  • Advocate and identify Shift Left Security practices to embed security into the early stages of the development lifecycle.
  • Partner with security engineers across Cloud Infra and IT team in driving implementation of shift left security practices, such as :Embedding security practices in SDLC & Cloud infrastructure.
  • Embedding the GRC team approvals/reviews in day-to-day processes to enable better governance.
  • GRC Tools

  • Utilise GRC tools such as Vanta, to streamline security processes and enhance efficiency.
  • Maintain a good security score on VANTA by coordinating with different stakeholders.
  • Evaluate and implement additional tools to support the automation of security tasks and assessments.
  • Training / Awareness

  • Create security and privacy training and awareness content and deliver training through creative and innovative means to create maximum impact.
  • Vendor and Client Security Assessment - Carry out assessments as and when required.

    ARR Improvement

  • Collaborate with stakeholders to enhance Annual Recurring Revenue (ARR) through improved security measures.
  • Implement security strategies that align with organizational goals and customer expectations.

What makes you a great match for us? 😍

  • Proven experience demonstrating a deep understanding of security frameworks (SOC 2, HIPAA, GDPR, ISO27001, USDPI) and Policy as Code
  • Experience identifying and driving the "Shift Left Security" culture
  • Proficiency with GRC automation tools (Vanta) and a strong understanding of ISO Security Standards
  • Excellent communication and collaboration skills – you'll be working closely with various teams across the organization
  • Adaptability to a flexible work environment with global stakeholders across different geos
  • Prior experience creating and implementing a Unified Compliance Framework (UCF) with a heavy focus on improving cyber security posture for SaaS organizations
  • High Ownership and ability to run multiple security projects simultaneously
  • Ability to go the extra mile being flexible to drive measurable improvements to Atlan's security posture keeping business objectives in mind.
The Company
HQ: New York, NY
192 Employees
On-site Workplace
Year Founded: 2018

What We Do

Built by a data team for data teams, Atlan is the active metadata platform for the modern data stack. It stitches together metadata from various sources (Snowflake, dbt, Databricks, Looker, Tableau, Postgres, etc.) to create a unified data discovery, cataloging, lineage, and governance experience across all your data assets, from columns and queries to metrics and dashboards. Atlan facilitates a two-way movement of metadata, bringing context back into the tools and workflows that your data team uses every day — for example, in your BI tool when you wonder what a metric on the dashboard means.

A pioneer in the space, Atlan was named a Leader in Forrester Wave™️: Enterprise Data Catalogs for DataOps in 2022 and was recognized by Gartner seven times in 2021, including as a Cool Vendor in DataOps and in the inaugural Market Guide for Active Metadata Management. Today, we power pioneering data teams like WeWork, Plaid, Postman, Unilever, and Ralph Lauren. We recently raised a Series B, backed by top investors (including Insight Partners, Sequoia, and Salesforce Ventures) and founders & CEOs from the modern data stack (including Snowflake, Looker, and Stitch).

For more information, visit http://www.atlan.com/ or follow us on Twitter at AtlanHQ.

Jobs at Similar Companies

Cencora Logo Cencora

Engineer II - Quality & Testing (IN)

Healthtech • Logistics • Software • Pharmaceutical
Pune, Maharashtra, IND
46000 Employees

MassMutual India Logo MassMutual India

Data Engineer

Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana, IND
Louisville, CO, USA
69 Employees
80K-134K Annually

Similar Companies Hiring

TrainingPeaks (A Peaksware Company) Thumbnail
Software • Fitness
Louisville, CO
69 Employees
MassMutual India Thumbnail
Insurance • Information Technology • Fintech • Financial Services • Big Data
Hyderabad, Telangana
Cencora Thumbnail
Software • Pharmaceutical • Logistics • Healthtech
Conshohocken, PA
46000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account