GRC Engineer

Job not on LinkedIn

🔥 21 hours ago

🏈 North America – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

🚔 Compliance

👻 Ghost score 12%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Clerk.dev

Clerk.dev

1 - 10 employees

☁️ SaaS

🔐 Security

🏢 Enterprise

SaaS • Security • Enterprise

Clerk. com is a comprehensive user management platform offering a suite of embeddable UIs, flexible APIs, and admin dashboards for user authentication and management. The platform provides features such as multifactor authentication, fraud prevention, SOC 2 type 2 certification, session management, social sign-on, bot detection, and more. Clerk integrates seamlessly with popular frameworks and tools, ensuring a smooth developer experience. It caters to multi-tenant SaaS applications with its suite of features designed for onboarding and management of users and organizations. Clerk is trusted by both startups and large enterprises, offering robust solutions for security and user authentication.

📋 Description

• Own SOC 2 Type II and HIPAA end to end, including scoping, control design, evidence, auditor walkthroughs, and remediation • Scope and lead the next compliance framework, likely ISO 27001, based on customer requirements • Build and maintain integrations feeding the GRC platform from cloud providers, SaaS tools, and internal systems • Convert controls into continuous checks using policy-as-code, configuration drift detection, and a control-failure pipeline • Run the vendor security review program from intake through periodic re-review • Own the security questionnaire and trust center workflow • Maintain the risk register and conduct risk assessments producing documented decisions • Embed compliance requirements into the SDLC and change management through tooling • Reduce manual work required to pass quarterly audits

🎯 Requirements

• 5+ years in security, with demonstrated experience building automation for a GRC or compliance program • Technical ownership of at least one SOC 2 Type II or ISO 27001 audit • Ability to write code and use LLMs productively without lowering quality • Hands-on experience with a GRC platform's API • Cloud IAM and configuration expertise on at least one provider; GCP preferred • Ability to determine sufficient evidence and defend an automated test to an auditor • Ability to scope, prioritize, and ship independently in a small security engineering team • Strong writing skills for policies, control narratives, and questionnaire answers • Experience at an all-remote company is a nice-to-have • Production experience shipping LLM or agentic workflows for compliance work is a nice-to-have • Experience at a developer-tools company is a nice-to-have

🏖️ Benefits

• Competitive salary • Stock option plan / equity ownership • Top-tier health insurance • Home office equipment of choice • Unlimited vacation policy; recommendation of 25 days per year • National holidays specific to country of residence • Diverse and inclusive globally distributed team

Apply Now