Senior GRC Technical Engineer

Posted Yesterday
Be an Early Applicant
San Ramon, CA, USA
In-Office
141K-241K Annually
Senior level
Software
The Role
Leads technical Governance, Risk, and Compliance operations by automating evidence collection, implementing continuous control monitoring, integrating security data with GRC platforms, and translating regulatory requirements into technical controls. Partners with Engineering, IT, Cloud, Security, Legal, Privacy, Audit, and business teams across frameworks including SOC 2, ISO 27001, FedRAMP, CMMC, HIPAA, and AI governance standards. Supports risk assessments, audits, security reviews, control documentation, and stakeholder advisory activities.
Summary Generated by Built In

As a Senior GRC Technical Engineer, you will play a key role in implementing and operating the organization's Governance, Risk, and Compliance (GRC) program, with a strong focus on the intersection of technology, cybersecurity, compliance, and risk management.

This role is ideal for a technically strong security professional who understands how security controls are implemented in real-world technology environments and can translate technical requirements into practical compliance outcomes. The individual will work closely with Engineering, Product, IT, Corporate Security, Legal, Privacy, Internal Audit, and business stakeholders to drive compliance, manage risk, and strengthen the organization's overall security posture.

The role will also provide exposure to and collaboration with Corporate Security functions, including vulnerability management, identity and access management, third-party risk, security assessments, and security operations.

Key Responsibilities
  • Identify opportunities to automate manual GRC processes and reduce reliance on spreadsheets and email-based evidence collection.
  • Support implementation of automated control monitoring and continuous compliance capabilities.
  • Explore the use of AI and agentic technologies to improve evidence collection, control validation, risk analysis, reporting, and compliance operations.
  • Partner with technical teams to integrate security and compliance data from enterprise systems into GRC platforms.
  • Maintain accurate and reliable GRC data, documentation, control libraries, and reporting.
  • Leverage GRC, security, cloud, vulnerability management, IAM, and other technology platforms to improve compliance operations.
  • Support the design, implementation, and ongoing operation of GRC programs across security, privacy, technology, and compliance requirements.
  • Translate regulatory, contractual, and industry-standard requirements into technical and operational control requirements.
  • Partner with Engineering, Product, IT, Cloud, Infrastructure, and Security teams to understand how controls are implemented within technology environments.
  • Support compliance programs and assessments across frameworks such as SOC 2, ISO 27001, ISO 27701, ISO 42001, PCI DSS, FedRAMP, CMMC, IRAP, HIPAA, HITRUST, and other applicable standards.
  • Develop working knowledge of areas such as Vulnerability Management, IAM/PAM, Third-Party Risk Management, security awareness/phishing, security assessments, and security operations.
  • Help translate Corporate Security activities and technical security capabilities into compliance evidence and control outcomes.
  • Build and maintain strong relationships with control owners, Engineering, Product, IT, Security, Legal, Privacy, Finance, Sales, and business-unit stakeholders.
  • Act as a trusted advisor rather than simply a compliance reviewer, helping stakeholders understand the intent behind security and compliance requirements.
  • Influence stakeholders across the organization without relying on direct authority.
  • Understand competing business priorities and help balance security, compliance, operational efficiency, and business objectives.
Qualifications & Experience
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field.
  • 5+ years of experience in cybersecurity, GRC, security engineering, compliance, IT risk, audit, or a related discipline.
  • Demonstrated experience working with technical and security teams in a technology, SaaS, cloud, or enterprise environment.
  • Strong understanding of cybersecurity principles, security controls, risk management, and compliance frameworks.
  • Practical experience with one or more frameworks such as ISO 27001, SOC 2, NIST, PCI DSS, FedRAMP, CMMC, ISO 42001, ISO 27701, HIPAA, or similar standards.
  • Experience performing control assessments, risk assessments, security reviews, audit preparation, or technical compliance activities.
  • Experience working with security technologies or programs such as IAM/PAM, vulnerability management, cloud security, endpoint security, third-party risk, or security operations is highly desirable.
  • Ability to understand technical architecture, security controls, system configurations, and engineering processes sufficiently to evaluate compliance and risk.
  • Strong analytical and problem-solving skills with the ability to investigate complex issues and determine appropriate solutions.
  • Excellent written and verbal communication skills.
  • Demonstrated ability to build strong relationships and influence stakeholders across technical and business functions.
  • Comfortable working in a fast-paced environment with changing priorities and multiple concurrent initiatives.
Preferred Qualifications
  • Professional certification such as CISA, CRISC, CISSP, Security+, ISO 27001 Lead Auditor/Implementer, or equivalent.
  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, AuditBoard, Drata, Vanta, or similar platforms.
  • Experience with cloud platforms such as AWS, Azure, or GCP.
  • Experience with security technologies such as Wiz, Tenable, Qualys, BeyondTrust, IAM/PAM platforms, or equivalent.
  • Experience supporting customer security questionnaires and security assurance activities.
  • Experience working with external auditors, certification bodies, customers, or regulatory assessors.
  • Experience with compliance automation, continuous control monitoring, or security data integrations.
  • Familiarity with AI governance and emerging frameworks such as ISO 42001 and NIST AI RMF

Compensation may vary depending on your location, qualifications including job-related education, training, experience, licensure, and certification, that could result at a level outside of these ranges. Certain roles are eligible for additional rewards, including annual bonus, and sales incentives depending on the terms of the applicable plan and role as well as individual performance. CA generally ranges: $160,489-$240,734 All other locations fall under our General State range: $140,780-$211,170 Benefits may vary depending on the nature of your employment with Cloud Software Group and the country where you work. U.S. based employees are typically offered access to healthcare, life insurance and disability benefits, 401(k) plan and company match, among others. This requisition has no specific deadline for completion.

About Us:

Cloud Software Group is one of the world’s largest cloud solution providers, serving more than 100 million users around the globe. When you join Cloud Software Group, you are making a difference for real people, each of whom count on our suite of cloud-based products to get work done — from anywhere. Members of our team will tell you that we value passion for technology and the courage to take risks.  Everyone is empowered to learn, dream, and build the future of work. We are on the brink of another Cambrian leap -- a moment of immense evolution and growth. And we need your expertise and experience to do it. Now is the perfect time to move your skills to the cloud.

Cloud Software Group is firmly committed to Equal Employment Opportunity (EEO) and to compliance with all federal, state and local laws that prohibit employment discrimination. All qualified applicants will receive consideration for employment without regard to age, race, color, creed, sex or gender, sexual orientation, gender identity, gender expression, ethnicity, national origin, ancestry, citizenship, religion, genetic carrier status, disability, pregnancy, childbirth or related medical conditions (including lactation status), marital status, military service, protected veteran status, political activity or affiliation, taking or requesting statutorily protected leave and other protected classifications.

Cloud Software Group will consider qualified applicants with a criminal history and conduct the recruiting process in accordance with the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers and San Diego Fair Chance Ordinance. For access to the laws see the following links: California FCA and Los Angeles FCO.
 

If you need a reasonable accommodation due to a disability during any part of the application process, please contact us via the Bridge portal for assistance.

Skills Required

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field
  • 5+ years of experience in cybersecurity, GRC, security engineering, compliance, IT risk, audit, or a related discipline
  • Experience working with technical and security teams in a technology, SaaS, cloud, or enterprise environment
  • Strong understanding of cybersecurity principles, security controls, risk management, and compliance frameworks
  • Practical experience with ISO 27001, SOC 2, NIST, PCI DSS, FedRAMP, CMMC, ISO 42001, ISO 27701, HIPAA, or similar standards
  • Experience performing control assessments, risk assessments, security reviews, audit preparation, or technical compliance activities
  • Ability to understand technical architecture, security controls, system configurations, and engineering processes to evaluate compliance and risk
  • Strong analytical and problem-solving skills
  • Excellent written and verbal communication skills
  • Ability to build relationships and influence stakeholders across technical and business functions
  • Ability to work in a fast-paced environment with changing priorities and multiple concurrent initiatives
  • Experience with IAM/PAM, vulnerability management, cloud security, endpoint security, third-party risk, or security operations
  • CISA, CRISC, CISSP, Security+, ISO 27001 Lead Auditor/Implementer, or equivalent certification
  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, AuditBoard, Drata, Vanta, or similar
  • Experience with AWS, Azure, or GCP
  • Experience with Wiz, Tenable, Qualys, BeyondTrust, IAM/PAM platforms, or equivalent security technologies
  • Experience supporting customer security questionnaires and security assurance activities
  • Experience working with external auditors, certification bodies, customers, or regulatory assessors
  • Experience with compliance automation, continuous control monitoring, or security data integrations
  • Familiarity with AI governance and frameworks such as ISO 42001 and NIST AI RMF

Cloud Software Group Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Cloud Software Group and has not been reviewed or approved by Cloud Software Group.

  • Healthcare Strength Health coverage is described as strong, with medical, dental, and vision plans viewed positively and including HSA-compatible options.
  • Retirement Support The 401(k) offering is positioned as a standout benefit, with the company match frequently characterized as strong and plan administration viewed favorably.
  • Parental & Family Support Parental leave is presented as generous, including repeated references to 18 weeks for birthing parents in the U.S. in recent commentary.

Cloud Software Group Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fort Lauderdale, FL
13,135 Employees

What We Do

Cloud Software Group enables our customers to evolve, compete and succeed leveraging our software franchises for and across data, automation, insight, and collaboration.

Similar Jobs

Rocket Companies Logo Rocket Companies

Escrow Assistant (Temporary Contract) | San Francisco

Fintech • Real Estate • Sales • Financial Services
In-Office
San Fransisco, CA, USA
14200 Employees
22-33 Hourly

General Motors Logo General Motors

Software Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Hybrid
Sunnyvale, CA, USA
165000 Employees
142K-215K Annually

General Motors Logo General Motors

Machine Learning Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Hybrid
Sunnyvale, CA, USA
165000 Employees
189K-301K Annually

General Motors Logo General Motors

Product Manager

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Hybrid
2 Locations
165000 Employees
135K-245K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account