GRC Engineer

🔥 11 hours ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Charlie Health

Charlie Health

501 - 1000 employees

⚕️ Healthcare Insurance

🧘 Wellness

💰 Seed Round on 2020-06

Healthcare Insurance • Wellness

Charlie Health is a provider of personalized intensive therapy and virtual Intensive Outpatient Programs (IOP) targeting mental health challenges. They cater to both teens and adults, offering a comprehensive treatment approach that includes therapies such as Cognitive Behavioral Therapy (CBT), Dialectical Behavior Therapy (DBT), and art and music therapy, among others. The company aims to provide immediate access and flexible scheduling to accommodate patients' needs, focusing on various conditions like anxiety, depression, self-harm, and substance use disorders. Charlie Health emphasizes measurable outcomes and connection with peers to foster long-term healing, with services available in as little as 24 hours.

📋 Description

• Design, build and operate automated controls that support HIPAA, SOC 2, NIST, ISO 27001 and other applicable frameworks • Translate compliance requirements into technical control logic, workflows, integrations, dashboards and evidence pipelines • Build scalable systems that reduce manual compliance work and improve confidence in control effectiveness • Partner with Security, IT, Compliance and Engineering teams to embed control requirements into systems and operating processes • Build and maintain continuous control monitoring capabilities across identity, endpoints, cloud, SaaS platforms, security tools and business systems • Define control health metrics, thresholds, alerts and reporting mechanisms • Identify control gaps, exceptions and drift, then partner with control owners to drive remediation • Improve visibility into the design, operation and effectiveness of key controls • Automate audit evidence collection across systems such as Okta, Google Workspace, Jamf, Intune, SentinelOne, Wiz, AWS, Jira, Confluence, Slack and GRC platforms • Build repeatable evidence workflows that support HIPAA, SOC 2, customer due diligence, vendor assessments and internal risk reviews • Improve the quality, consistency and traceability of audit evidence • Partner with Compliance, Legal and external auditors to reduce audit burden and improve readiness • Configure and improve GRC platforms, compliance tools, ticketing systems, documentation repositories and reporting workflows • Build integrations between GRC systems and source systems of record using APIs, webhooks, scripts and workflow automation tools • Develop dashboards and reports that show control health, remediation status, audit readiness and risk trends • Maintain documentation for control logic, data sources, automations and operational procedures • Support risk and control assessments by providing technical analysis, control evidence and remediation tracking • Build workflows for risk acceptance, exception management, corrective action plans and control remediation • Partner with control owners to ensure findings are tracked, prioritized and resolved • Help define metrics that measure risk reduction, compliance maturity and control reliability • Help evaluate how AI tools, LLM platforms and AI-enabled workflows affect compliance, privacy and security requirements • Support governance controls for enterprise AI adoption, including access, logging, data protection, review workflows and evidence collection • Identify opportunities to use automation and AI responsibly to improve GRC operations • Stay current on emerging approaches to compliance automation, continuous assurance and AI-enabled GRC.

🎯 Requirements

• 5+ years of experience in GRC engineering, security engineering, compliance automation, IT risk, security operations, cloud security, infrastructure engineering or a related technical discipline • Hands-on experience translating compliance, risk or security requirements into technical controls, workflows or automations • Experience with frameworks such as HIPAA, SOC 2, NIST, ISO 27001, HITRUST, PCI or FedRAMP • Experience working with enterprise systems such as Okta, Google Workspace, AWS, Jamf, Intune, SentinelOne, Wiz, Jira, Confluence, Slack or similar platforms • Experience using APIs, scripting or workflow automation tools such as Python, Bash, PowerShell, Workato, Terraform, REST APIs, webhooks or JSON • Experience with audit evidence collection, control testing, remediation tracking or compliance reporting • Familiarity with GRC platforms, compliance automation tools, ticketing systems or control monitoring systems • Strong understanding of access control, endpoint security, cloud security, logging, vulnerability management and data protection concepts • Ability to work cross-functionally with Security, IT Engineering, Compliance, Legal and business stakeholders • Strong analytical thinking, ownership and ability to operate independently in ambiguous environments.

🏖️ Benefits

• Charlie Health offers comprehensive benefits to all full-time employees. Read more about our benefits here.

Apply Now

Similar Jobs

🔥 12 hours ago

HealthEdge

1001 - 5000

⚕️ Healthcare Insurance

☁️ SaaS

💳 Fintech

Manager of Regulatory Compliance leading a team at HealthEdge for healthcare regulatory operations. Ensuring alignment with federal and state regulatory requirements for healthcare products.

🔥 13 hours ago

Sezzle

201 - 500

💳 Fintech

👥 B2C

🛍️ eCommerce

Manager, Regulatory Reporting leading bank-specific regulatory reporting at Sezzle. Responsible for building the regulatory reporting function for banking operations and ensuring compliance.

🔥 13 hours ago

Sezzle

201 - 500

💳 Fintech

👥 B2C

🛍️ eCommerce

Bank Regulatory Reporting Manager overseeing regulatory reporting and compliance for banking operations at Sezzle. Building regulatory frameworks and collaborating with cross-functional teams.

🔥 13 hours ago

Mission Lane

501 - 1000

💳 Fintech

🏦 Banking

👥 B2C

Compliance Manager establishing fraud, collections, and back-office compliance for Mission Lane's credit card business. Leading compliance initiatives and ensuring adherence to regulations and best practices.

🔥 23 hours ago

SummitStone Health Partners

201 - 500

🧘 Wellness

Compliance Generalist supporting regulatory compliance activities at SummitStone Health Partners. Professionally communicate compliance topics and respond to queries from the organization.