Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role Replit is the agentic software creation platform that enables anyone to build applications using natural language. As we scale to support millions of developers and enterprise organizations, maintaining a robust, transparent, and technically sound Governance, Risk, and Compliance (GRC) program is critical. We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust, partnering deeply across the organization. We need a pragmatic operator who understands that GRC exists to enable the business—balancing rigorous standards with the velocity of a high-growth startup. What You'll Do Technical Excellence & Architecture Technical Depth: Act as a technical subject matter expert for the GRC team. You will drive quality, technical depth, and operational efficiency in our security controls. Program Architecture: Own the technical vision for Replit’s GRC program, moving the team from manual workflows toward "Compliance-as-Code" and automated evidence collection. Thought Leadership: Champion a culture of security and privacy across the company, educating teams on why controls exist rather than just enforcing them. Cross-Functional Collaboration Engineering & Architecture: Partner with Architects and Engineering Leads to "bake in" compliance requirements early in the design phase. You will translate complex technical implementations into narratives that satisfy frameworks without slowing down development. Legal & Privacy: Work closely with Legal Counsel to interpret and implement requirements for Privacy (GDPR, CCPA) and emerging AI-specific regulations (e.g., EU AI Act). Sales &a
Jobiba hiring network
Grc Engineer Jobs
127 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current grc engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.
About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in. Available Locations: Austin, TX About the role Security is at the heart of Cloudflare’s mission to help build a better Internet. Anytime we push code, it automatically affects the millions of Internet properties (powering websites, remote teams, APIs, mobile apps, etc.) running on our global network. Cloudflare's network is one of the largest in the world, spanning over 330 cities in more than 125 countries, and operating within 50 milliseco
Who Are We? Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster. The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman. P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman. The Opportunity The Security GRC team is responsible for the overall security posture of Postman by ensuring compliance with applicable regulations and contractual obligations and maintaining effective and efficient governance, risk, and compliance programs. In addition, the Security GRC team is directly involved with supporting and enabling Sales and driving security and compliance initiatives to further the growth of Postman. We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills to build and scale automation across governance, risk, and compliance. This is a hands-on technical role focused on designing and operating GRC tooling, integrations, and AI-assisted workflows that reduce manual effort while improving security assurance. The ideal candidate has experience implementing and maturing compliance programs, including SOC 2, ISO 27001, HIPAA, GDPR, CCPA, and FedRAMP, and can translate security and risk requirements into practical engineering solutions. As a senior member of the Security GRC team, you will partner with Security, Engineering, IT, Legal, Sales, and other stakeholders to
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We own Plaid’s security compliance frameworks, run our audits and risk programs, and partner across the company to keep Plaid’s platform secure, resilient, and aligned with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance into code, evidence into telemetry, and audits into a continuous, automated capability. The Role: You will own GRC Engineering at Plaid — a foundational, high-ownership role defining an emerging discipline from the ground up. Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable, and set the technical direction for the field. You will: Define the discipline and the architecture — how GRC Engineering works at Plaid, not just execute with
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. Smartsheet's customers in Europe, the Middle East, and Africa expect our Customer Trust team to understand their compliance challenges, speak their language, and respond quickly to security assessments. We're looking for a Sr. Security Engineer I to lead Customer Trust operations across EMEA—responding to security questionnaires, managing vendor risk assessments, and building trusted relationships with enterprise customers in these regions. You will be responsible for questionnaire triage, completion, and queue management for EMEA customers. You'll work closely with EMEA sales teams, understand regional compliance requirements (GDPR, EU data protection, sector-specific frameworks), and ensure Smartsheet maintains a strong reputation for responsiveness and technical credibility in these high-value markets. You will work remotely from the UK and report to our Sr. Director, GRC Engineering, based in the US You Have 5+ years of experience in customer trust, vendor risk management, security assessment, or customer-facing security roles at SaaS or cloud platform companies. Proven experience completing and responding to customer security questionnaires, vendor assessments, and RFIs. Strong understanding of GDPR, EU data protection, and regional compliance requirements: Familiarity with data residency, data processing agreements, DPIAs, and how cloud services operate within EU regulatory frameworks. Knowledge of GRC frameworks: Working knowledge of SOC 2, ISO 27001, and compliance standards commonly referenced in EMEA asse
As the Engineering Manager for Commercial Audit, you will lead a high-performing team responsible for scaling Datadog’s security and compliance posture through automation, tooling, and engineering excellence. Our GRC (Governance, Risk, and Compliance) function is a critical partner to the broader Security and Engineering organizations, ensuring that Datadog not only meets rigorous global regulatory standards but does so in a way that is efficient, scalable, and integrated into our cloud-native infrastructure. You will manage a team of engineers and analysts who are transitioning to a GRC engineering direction to treat compliance as a software problem, leveraging AI, custom tooling, CI/CD pipelines, and cloud-native services to turn complex regulatory requirements into actionable, automated controls. You will lead the strategy, roadmap, and execution of Datadog’s Commercial Audit initiatives. This is a high-impact leadership role where you will grow a team of engineers and analysts responsible for directly maintaining our compliance programs and related audits (e.g., SOC2, PCI, HIPAA, ISO) while looking to improve efficiency and effectiveness through platforms and tooling. You will act as a bridge between technical engineering, legal, and compliance, enabling the organization to move fast while maintaining a secure and compliant environment. You will champion a culture of "compliance-as-code," identifying opportunities to automate evidence collection, streamline control testing, and reduce manual toil for both your team and our partner engineering teams. At Datadog, we place value in our office culture - the relationships and collaboration it builds, and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Lead the strategy, roadmap, and execution of Datadog’s commercial security compliance efforts, shifting from manual audit processes to automated, scalable
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the role: Replit is building the security GRC function that will scale with an AI-native product. As the Risk & Compliance lead, you'll own our certification and audit program end to end: SOC 2, ISO 27001, and eventually ISO 42001 (AI management systems), while also owning the company's master security risk register and continuous compliance monitoring. You'll report to the Head of Security GRC, who retains overall accountability for the risk program, and work closely with Engineering to make sure controls hold up in practice, not just on paper. What You'll Do Own the end-to-end certification roadmap (SOC 2 Type II, ISO 27001, and future frameworks like ISO 42001) including scoping, gap assessments, remediation, and audit execution Manage relationships with external auditors and drive the annual audit calendar so certifications renew without last-minute scrambles Own and maintain the company's master security risk register including risk identification, scoring methodology, treatment plans, and residual risk reporting Build and maintain continuous compliance monitoring so control status reflects real-time state rather than point-in-time snapshots Own the core audit artifacts that back every certification including ISMS documentation, Statements of Applicability, risk assessments, and potentially FedRAMP System Security Plans (SSPs) Run regular audits and readiness assessments, and track remediation of findings and control gaps to closure Support GDPR and broader privacy compliance alongside the Legal/Privacy team, without owning the legal interpretation of requirements Partner with the GRC Engineer to define what evidence collection and control monitoring should be automated versus manually reviewed Track and
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. FedRAMP and GovRAMP (formerly StateRAMP) are transforming how Smartsheet serves government and regulated customers. We need a FedRAMP and GovRAMP subject matter expert to lead these programs—someone with real hands-on experience obtaining and maintaining ATO authorizations, navigating 3PAO assessments, and managing continuous monitoring requirements. In this role, you'll own Smartsheet's FedRAMP and GovRAMP certifications, manage relationships with our 3PAOs, drive annual assessment preparation, manage POA&M processes, and ensure we maintain authorizations at the highest level. You'll understand the nuances of federal compliance, speak fluently with government agencies and authorized assessors, and translate complex regulatory requirements into clear roadmaps for engineering and operations teams. You'll be the voice of federal compliance at Smartsheet and the trusted advisor to government customers on our security posture. You Will: Own FedRAMP and GovRAMP (formerly StateRAMP) certifications and roadmaps: Lead the overall strategy for obtaining and maintaining federal authorizations, including package management, compliance timelines, and authority coordination. Manage 3PAO relationships and assessments: Work with accredited third-party assessment organizations to conduct initial assessments and annual re-assessments. Coordinate scoping, evidence preparation, testing coordination, and results validation. Lead continuous monitoring (ConMon) execution: Oversee the delivery of monthly, annual, and event-driven Fed
Overview We are seeking a hands-on Director of AI Software Engineering to lead and scale AI engineering efforts supporting multiple business units across Governance, Risk, and Compliance (GRC). This role sits at the intersection of product delivery, platform evolution, and applied AI—driving real-world impact across core workflows. This is not a pure management role. We are looking for a builder who leads from the front, someone who has recently written production code, shipped systems end-to-end, and can operate comfortably in ambiguity while aligning teams and stakeholders. What You’ll Do Lead AI Engineering Across GRC Own delivery of AI-powered capabilities embedded directly into business unit workflows (e.g., risk analysis, compliance automation, reporting, due diligence) Partner with product, data, and platform teams to translate business problems into scalable AI systems Stay Hands-On Contribute to architecture, code reviews, and critical path implementation Prototype and validate new approaches (LLMs, agents, retrieval systems, classification pipelines, etc.) Set engineering standards for performance, reliability, and cost efficiency Build and Scale Teams Lead and mentor a high-performing team of AI/ML and software engineers Drive hiring, coaching, and career development Establish a culture of ownership, speed, and technical excellence Drive Execution Deliver production-grade systems—not experiments Balance speed with rigor (security, privacy, compliance) Operate across multiple concurrent initiatives with clear prioritization Communicate and Influence Act as a bridge between engineering and business stakeholders Clearly articulate trade-offs, risks, and outcomes to senior leadership Align cross-functional teams around shared goals and timelines What We’re Looking For Proven Builder 10+ years in software engineering, with recent hands-on coding experience Demonstrated track record of shipping production systems at scale Experience with modern
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Solutions Engineer, you'll serve as a trusted technical voice, guiding customers toward clarity, feasibility, and alignment on the end-to-end solution. Because Vanta is the platform our customers rely on to build and run their GRC programmes, this is a natural next step for GRC professionals, programme managers, auditors, and compliance practitioners who want to apply their domain expertise in a strategic, customer-facing pre-sales role. You’ll be an integral part of the Sales team, working to ensure technical fit and create innovative solutions for our customers. Your attention to detail, focused on customer needs, will ultimately improve retention and overall success. This role will be based from our London office or Dublin office with an office-centric hybrid schedule. The standard in-office days are Tuesday, Wednesday, and Thursday. GRC practitioners are especially encouraged to apply—whether you've managed GRC programmes in-house, audited them as an internal or external auditor, or helped customers meet their GRC programme needs at a GRC vendor, you'll bring exactly the customer empathy and domain fluency this role thrives on. What you’ll do as a Solutions Engineer at Vanta: Serve as a strategic sales partner, owning the technical relationship with prospects and customers. Strategic Discovery and Deal Qualification: Partner with Account Executives to uncover technical, operational, and business pain points, validating use cases and aligning solutions to measurable customer impact and urgency. Secure the Solution Win and Alignment: Validate technical feasibility, drive clarity on success criteria, and guide stakeholder
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Solutions Engineer, you'll serve as a trusted technical voice, guiding customers toward clarity, feasibility, and alignment on the end-to-end solution. Because Vanta is the platform our customers rely on to build and run their GRC programmes, this is a natural next step for GRC professionals, programme managers, auditors, and compliance practitioners who want to apply their domain expertise in a strategic, customer-facing pre-sales role. You’ll be an integral part of the Sales team, working to ensure technical fit and create innovative solutions for our customers. Your attention to detail, focused on customer needs, will ultimately improve retention and overall success. This role will be based from our London office or Dublin office with an office-centric hybrid schedule. The standard in-office days are Tuesday, Wednesday, and Thursday. GRC practitioners are especially encouraged to apply—whether you've managed GRC programmes in-house, audited them as an internal or external auditor, or helped customers meet their GRC programme needs at a GRC vendor, you'll bring exactly the customer empathy and domain fluency this role thrives on. What you’ll do as a Solutions Engineer at Vanta: Serve as a strategic sales partner, owning the technical relationship with prospects and customers. Strategic Discovery and Deal Qualification: Partner with Account Executives to uncover technical, operational, and business pain points, validating use cases and aligning solutions to measurable customer impact and urgency. Secure the Solution Win and Alignment: Validate technical feasibility, drive clarity on success criteria, and guide stakeholder
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Solutions Engineer, you'll serve as a trusted technical voice, guiding customers toward clarity, feasibility, and alignment on the end-to-end solution. Because Vanta is the platform our customers rely on to build and run their GRC programmes, this is a natural next step for GRC professionals, programme managers, auditors, and compliance practitioners who want to apply their domain expertise in a strategic, customer-facing pre-sales role. You’ll be an integral part of the Sales team, working to ensure technical fit and create innovative solutions for our customers. Your attention to detail, focused on customer needs, will ultimately improve retention and overall success. With this role being specific to support our DACH Market account teams and customers, having full German Language proficiency is a must for this successful candidate. This role will be based from our Dublin office with an office-centric hybrid schedule. The standard in-office days are Tuesday, Wednesday, and Thursday. GRC practitioners are especially encouraged to apply—whether you've managed GRC programmes in-house, audited them as an internal or external auditor, or helped customers meet their GRC programme needs at a GRC vendor, you'll bring exactly the customer empathy and domain fluency this role thrives on. What you’ll do as a Solutions Engineer at Vanta: Own the technical relationship with our commercial prospects/customers Develop a deep understanding of our product capabilities, integrations, configurations messaging, partner ecosystem, and competitive landscape. Listen carefully to prospects and clients to provide market feedback to the product te
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Solutions Engineer, you'll serve as a trusted technical voice, guiding customers toward clarity, feasibility, and alignment on the end-to-end solution. Because Vanta is the platform our customers rely on to build and run their GRC programmes, this is a natural next step for GRC professionals, programme managers, auditors, and compliance practitioners who want to apply their domain expertise in a strategic, customer-facing pre-sales role. You’ll be an integral part of the Sales team, working to ensure technical fit and create innovative solutions for our customers. Your attention to detail, focused on customer needs, will ultimately improve retention and overall success. With this role being specific to support our DACH Market account teams and customers, having full German Language proficiency is a must for this successful candidate. This role will be based from our London office with an office-centric hybrid schedule. The standard in-office days are Tuesday, Wednesday, and Thursday. GRC practitioners are especially encouraged to apply—whether you've managed GRC programmes in-house, audited them as an internal or external auditor, or helped customers meet their GRC programme needs at a GRC vendor, you'll bring exactly the customer empathy and domain fluency this role thrives on. What you’ll do as a Solutions Engineer at Vanta: Own the technical relationship with our commercial prospects/customers Develop a deep understanding of our product capabilities, integrations, configurations messaging, partner ecosystem, and competitive landscape. Listen carefully to prospects and clients to provide market feedback to the product te
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Our Senior Software Engineers lead and mentor engineers, delivering high-value products for our customers and infrastructure that enables our business to scale. Vanta’s team and technology surface are growing quickly, and it’s essential that we invest in the right abstractions and systems to enable us to scale with our business. As a Senior Software Engineer, you’ll be responsible for setting technical direction to enable our product and infrastructure to scale with our business, driving complex projects across our technical stack, and mentoring our talented engineering team. Your past experience will be leveraged to enable and accelerate Vanta’s growth. Our business has found incredible product-market fit and has monetized effectively since the day we signed our first customer. We’re growing at a blistering pace, which presents career-defining opportunities for engineers to accelerate their growth and to contribute to a rapidly-scaling company. Visit our Vanta Engineering Blog to learn more about what our team is working on! The GRC (Governance, Risk and Compliance) organization is the primary org responsible for developing and maintaining Vanta's core product offerings. These teams are at the heart of Vanta moving upmarket to support enterprise customers and build products that enable our customers’ existing security and compliance programs to integrate seamlessly with Vanta, giving them invaluable insights and recommendations to continue to operate, mature and evolve their programs. What you’ll do as a Senior Software Engineer at Vanta: Lead complex projects with multiple stakeholders and engineers to deliver significant imp
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Our Senior Software Engineers lead and mentor engineers, delivering high-value products for our customers and infrastructure that enables our business to scale. Vanta’s team and technology surface are growing quickly, and it’s essential that we invest in the right abstractions and systems to enable us to scale with our business. As a Senior Software Engineer, you’ll be responsible for setting technical direction to enable our product and infrastructure to scale with our business, driving complex projects across our technical stack, and mentoring our talented engineering team. Your past experience will be leveraged to enable and accelerate Vanta’s growth. Our business has found incredible product-market fit and has monetized effectively since the day we signed our first customer. We’re growing at a blistering pace, which presents career-defining opportunities for engineers to accelerate their growth and to contribute to a rapidly-scaling company. Visit our Vanta Engineering Blog to learn more about what our team is working on! Please note we are only able to hire in Alberta, Ontario, and British Columbia. The GRC (Governance, Risk and Compliance) organization is the primary org responsible for developing and maintaining Vanta's core product offerings. These teams are at the heart of Vanta moving upmarket to support enterprise customers and build products that enable our customers’ existing security and compliance programs to integrate seamlessly with Vanta, giving them invaluable insights and recommendations to continue to operate, mature and evolve their programs. What you’ll do as a Senior Software Engineer at Vanta: Lead comp
Get new grc engineer jobs by email
Daily job updates · Unsubscribe anytime