Senior Security Engineer – GRC Controls, Audit

🕒 May 28

🇺🇸 United States – Remote

💵 $153k - $214k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

info
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of 1Password

1Password

501 - 1000 employees

Founded 2009

🔒 Cybersecurity

☁️ SaaS

⚡ Productivity

💰 $620M Series C on 2022-01

Cybersecurity • SaaS • Productivity

1Password is a leading password management and cybersecurity company that offers solutions for both individual and business customers to securely store and manage passwords, secrets, and sensitive information. With features like extended access management (XAM), 1Password empowers users to manage access to every application and web account, ensuring security across all devices with alerts for possible breaches. Trusted by over 150,000 businesses, 1Password provides comprehensive security solutions that enhance productivity by enabling easy and secure sharing of credentials and managing permissions, while maintaining high visibility and control. Their services cater to enterprises and families, providing protection from bad actors in today's SaaS-centric hybrid work environment.

📋 Description

• lead our commercial audit programs • partner directly with the Senior Manager of GRC • own the question of what "good evidence" looks like across SOC 2 Type II, ISO 27001/27017/27018, and ISO 27701 • help build the AI-assisted workflows and automation for our audit programs • partner cross-functionally with Engineering, IT, Security, and People teams

🎯 Requirements

• 5+ years of experience in GRC, compliance, or audit • Deep hands-on experience with SOC 2 Type II • strong working knowledge of ISO 27001 and related standards (27017, 27018, 27701) • demonstrated experience leading technical audit walkthroughs with external auditors • ability to define what "good evidence" looks like for each control domain • proven ability to design and execute control testing • ability to work cross-functionally with Engineering, IT, Security, and People teams • strong written and verbal communication skills • experience with compliance automation platforms (Drata, Vanta, Secureframe, or equivalent)

🏖️ Benefits

• health, dental, 401k and many others • generous paid time off • equity grant • participation in our incentive programs

Apply Now

Similar Jobs

🕒 May 28

L3Harris Technologies

10,000+ employees

🚀 Aerospace

🔒 Cybersecurity

Security Research Engineer developing cybersecurity solutions for L3Harris Technologies. Collaborating on challenging security research problems and transforming them into commercial products within a global engineering team.

🕒 May 28

Turner & Townsend

10,000+ employees

Security Project Manager for EV-charging projects at Turner & Townsend. Overseeing project delivery and ensuring adherence to security standards.

🇺🇸 United States – Remote

💵 $130k - $160k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🕒 May 28

Cyclotron, Inc.

51 - 200

🏢 Enterprise

☁️ SaaS

⚡ Productivity

Security Architect at Cyclotron designing Microsoft 365 Identity and Device Management tools. Collaborate with clients to improve security posture across Microsoft ecosystems.

🇺🇸 United States – Remote

💵 $130k - $180k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🕒 May 28

Soteria - Security Solutions & Advisory

11 - 50

🔒 Cybersecurity

📋 Compliance

Security Advisor performing control gap assessments and advising on compliance in cybersecurity. Collaborating with clients to improve security measures and deliver tailored solutions.

🇺🇸 United States – Remote

💰 $2.5M Venture Round on 2018-04

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🕒 May 28

Celestica

10,000+ employees

🤝 B2B

Cybersecurity Lead overseeing product security for network hardware and OS. Leading integration of security in product development lifecycle and vulnerability management strategies.