Sr. GRC Engineer

Posted 2 Days Ago
Be an Early Applicant
Raleigh, NC, USA
In-Office
133K-160K Annually
Senior level
Big Data • Software • Analytics
Pendo is the all-in-one product experience platform that puts product at the center of everything.
The Role
Leads Pendo’s governance, risk, and compliance initiatives, including regulatory programs, audit cycles, risk assessments, incident response, and security roadmap planning. The role designs durable controls, translates technical risks into business recommendations, partners with engineering and IT, and uses AI to accelerate evidence collection, policy development, regulatory research, and security workflows. It may also administer GRC platforms, tune SIEM or EDR detections, and operationalize threat intelligence.
Summary Generated by Built In
Sr. GRC EngineerThe Team + The Role

Pendo's Information Security team protects the data entrusted to Pendo and helps ensure our products are built with security and privacy by design. The team spans Security Operations, Product Security, and Compliance and Risk. With a small team and broad scope, the work directly supports the security, resilience, and trust of Pendo's products and operations.

The Sr. GRC Engineer is an AI-first technical leader who helps drive the evolution of Pendo's governance, risk, and compliance program. This role independently leads complex compliance, risk, and incident-response work while identifying program maturity gaps, translating security risk into business terms, and contributing to security roadmap and investment decisions. Success means building durable controls and programs that reduce risk and operational friction, not simply completing audits.

This role is based in our Raleigh office.

What this looks like day-to-day
  • AI-driven compliance and operations acceleration: Use AI to accelerate audit evidence preparation, policy documentation, control testing workflows, and regulatory research. Evaluate GRC platform automation capabilities and integrate AI tooling where it reduces manual overhead, then document and share effective approaches with the team.
  • Security program strategy and roadmap: Identify maturity gaps across compliance and security operations and translate them into prioritized roadmap recommendations grounded in business risk. Contribute to security investment discussions, clarify tradeoffs between coverage, cost, and risk, and anticipate emerging regulatory requirements before they become audit findings.
  • Compliance program ownership: Own one or more regulatory compliance programs end-to-end, including SOC 2 Type II, ISO 27001/42001, PCI-DSS, GovRAMP, or FedRAMP. Lead control design, evidence collection, auditor relationships, and remediation tracking to maintain effective and durable compliance programs.
  • Risk assessment and prioritization: Conduct organizational risk assessments and present findings to leadership with clear prioritization and investment-level recommendations. Translate technical exposure into business-risk language that enables leaders to make informed decisions without requiring additional security interpretation.
  • Incident response leadership: Lead incident response for complex, multi-system security events from investigation through resolution. Conduct root cause analysis, run post-incident reviews, and own resulting actions that turn incident findings into measurable program improvements.
  • Cross-functional partnership: Work directly with engineering, product, and IT teams to deliver compliance requirements, validate implementations, and embed security into day-to-day operations. Translate compliance obligations into actionable technical requirements and influence how partner teams approach security as well as what they deliver.
Who You Are

Beyond the qualifications, we hire through a specific lens. These aren't buzzwords; they're the things we'll actually look for in how you talk about your work.

You're a builder, not a maintainer.

You're most energized when there isn't a clear path yet, and you get to define it. You don't wait for direction; you identify gaps, shape solutions, and drive them forward. At Pendo, great Sr. GRC Engineers don't just follow instructions; they operate as strategic advisors, influencing decisions, guiding stakeholders, and elevating how we work.

You're AI-curious - genuinely.

You're not using AI tools occasionally. You're rewiring how you work around them. You're faster, sharper, and more prolific because of it, and you bring that energy to everything — how you approach your work, how you prep, how you communicate, how you think. We want someone who sees AI as a multiplier, not a shortcut.

Must-haves
  • 3 to 5 years of hands-on security experience with demonstrated ownership of compliance programs or security operations work, rather than participation alone.
  • Deep working knowledge of at least two of the following frameworks: SOC 2, ISO 27001, PCI-DSS, FedRAMP, GovRAMP, or the NIST 800-series.
  • Demonstrated ability to independently own auditor relationships and manage an audit cycle end-to-end, including responding directly to auditor questions.
  • Experience leading incident response investigations from triage through root cause analysis and producing post-incident documentation that engineering teams can act on.
  • Demonstrated ability to translate security risk into business-risk language that enables leaders to make investment and prioritization decisions.
  • Active, demonstrated use of AI tools to accelerate security workflows such as evidence collection, policy drafting, regulatory research, or detection analysis.
  • Strong written and verbal communication skills, with the ability to tailor recommendations effectively for engineering, auditor, and leadership audiences.
Nice-to-haves
  • Experience with SIEM or EDR platforms such as Splunk, Elastic, CrowdStrike, or SentinelOne, including independently writing and tuning detection rules.
  • GRC platform administration experience with tools such as Vanta, Drata, or Archer, including automation configuration and third-party integrations.
  • Experience operationalizing threat intelligence or conducting threat hunting using MITRE ATT&CK.
  • A security certification such as CISA, CISSP, CISM, Security+, or equivalent.
  • Experience working in a SaaS company with concurrent multi-framework compliance obligations.
About Pendo

Pendo was founded in 2013 by former product managers, who combined their heads and hearts to build something they wanted but never had as product managers: a simple way to understand and attack what truly drives product success. Our mission is to improve society's experience with software. Come join one of the fastest-growing startups, supported by best-in-class institutions like Battery Ventures, Salesforce Ventures, Spark Capital and Meritech.

Pendo Core Values: Bias to Act, Hone Your Craft, The Team is Pendo, and Maniacal Focus.

Location: Pendo is a hybrid culture. In-office 3 days per week unless designated remote.

Compensation: The expected base salary range for this role to be performed in Raleigh, NC is $133,400 - $160,000.

Benefits: Highly competitive, employer-heavy coverage, including $0 premium options, strong 401(k) match, equity, and flexible time off.

EEOC: We are an equal opportunity employer and believe having diverse teams where everyone brings their whole self to Pendo is key to our success. We welcome all people of different backgrounds, experiences, abilities and perspectives.

Accessibility: Pendo is committed to working with, and providing access and reasonable accommodation to, applicants with mental and/or physical disabilities. If you think you may require an accommodation for any part of the recruitment process, please send a request to: [email protected]. All requests for accommodations are treated discreetly and confidentially, as practical and permitted by law.

Skills Required

  • 3 to 5 years of hands-on security experience with ownership of compliance programs or security operations
  • Deep working knowledge of at least two of SOC 2, ISO 27001, PCI-DSS, FedRAMP, GovRAMP, or NIST 800-series frameworks
  • Ability to independently own auditor relationships and manage audit cycles end-to-end
  • Experience leading incident response investigations from triage through root cause analysis and post-incident documentation
  • Ability to translate security risk into business-risk language for investment and prioritization decisions
  • Active use of AI tools to accelerate security workflows
  • Strong written and verbal communication skills for engineering, auditor, and leadership audiences
  • Experience with SIEM or EDR platforms such as Splunk, Elastic, CrowdStrike, or SentinelOne, including detection rule writing and tuning
  • GRC platform administration experience with Vanta, Drata, or Archer
  • Experience operationalizing threat intelligence or conducting threat hunting using MITRE ATT&CK
  • Security certification such as CISA, CISSP, CISM, Security+, or equivalent
  • Experience working in a SaaS company with concurrent multi-framework compliance obligations

Pendo.io Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Pendo.io and has not been reviewed or approved by Pendo.io.

  • Healthcare Strength — Health coverage is described as generous, including medical, dental, vision, and mental health support for employees and families, with added wellness resources.
  • Parental & Family Support — Paid parental leave is positioned as a strength, with up to 16 weeks of paid leave and added fertility-related support noted.
  • Fair & Transparent Compensation — Market-anchored salary ranges for engineering and sales roles are visible across public postings and aggregated sources, providing clearer expectations on base pay and OTE.

Pendo.io Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Raleigh, NC
961 Employees
Year Founded: 2013

What We Do

Pendo's mission is to elevate the world's experience with software. Pendo’s product experience platform allows companies to make product intelligence actionable with speed and scale, giving rise to a new generation of companies that put product at the center of everything. Pendo customers include the world's leading companies, including Verizon, Morgan Stanley, LabCorp, OpenTable, Okta, Salesforce, and Zendesk. Through Mind the Product and customer communities, sponsored events and podcast, Pendo aims to support the success of product and digital leaders everywhere. Pendo is headquartered in Raleigh, North Carolina and has offices around the world. For more information, visit: www.pendo.io.

Why Work With Us

Pendo operates in a very exciting market and offers a unique product with highly passionate customers. Our objective has always been to hire incredibly talented, but equally as energetic employees who are committed to serving those customers. We embrace the agility and speed of a startup, but we also offer a flexible and inclusive work environment.

Gallery

Gallery

Similar Jobs

Wells Fargo Logo Wells Fargo

Operations Specialist

Fintech • Financial Services
Hybrid
Charlotte, NC, USA
205000 Employees
Hybrid
Charlotte, NC, USA
205000 Employees
Hybrid
Burlington, NC, USA
205000 Employees

Wells Fargo Logo Wells Fargo

Operations Specialist

Fintech • Financial Services
Hybrid
Charlotte, NC, USA
205000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account