About the Team OpenAI’s Governance, Risk, and Compliance team helps ensure security and privacy are grounded in how our products and systems actually operate. Assurance Operations partners with Security, Engineering, Infrastructure, Product, Privacy, and Legal to make controls provable, risk decisions explicit, and audit readiness a result of well-designed systems. About the Role We are hiring a technical, product-minded GRC builder who can own consequential audits while improving the control and evidence systems behind them. You will build a reusable common control framework, use Codex to automate assurance work, validate changing system scope, and turn repeated audit friction into measurable improvements. We are looking for someone who questions inherited assumptions, solves novel problems creatively, works closely with engineers, and makes the next audit easier by improving the underlying system. You’ll be responsible for: Lead external, internal, customer, and certification audit work from scoping through evidence review, fieldwork, remediation, and closeout. Build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks. Validate actual scope and ownership instead of assuming last year's controls, product boundaries, or evidence remain accurate. Use Codex to build and test evidence checks, control mappings, request triage, owner workflows, monitoring, and remediation reporting. Partner with engineers on cloud architecture, identity, logging, data flows, software changes, vulnerabilities, and control effectiveness. Design maintainable, permission-aware tools that preserve source provenance, human review, and evidence integrity. Reduce repeated requests and operational burden for control owners through measurable workflow improvements. Define roadmaps, decision rights, milestones, success metrics, and clear cross-functional escalations. We’re looking for someone with: Direct ownership
Jobiba hiring network
Grc Engineer Jobs
127 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current grc engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.
Drata is building the trust layer between great companies - automating compliance, managing risk, and helping organizations prove trust continuously as they scale. We're Dratanauts: a global crew of 600+ professionals united by a culture that rewards integrity, ownership, and raising the bar, no matter where in the world we're working from. Why Join the Drata Team? At Drata, you're not maintaining legacy compliance software - you're building the agentic AI platform defining what trust looks like for the next generation of companies. Here's what makes the work itself worth showing up for: Problems without a playbook: You'll work at the edge of AI and security, building agentic governance, continuous compliance, and real-time trust verification to solve problems that don't have an established answer yet. You're writing it as you go. Real ownership, not just process: Our values center on owning outcomes and raising the bar, not checking boxes. You're expected to have opinions and back them. A seat at the table: Your perspective is unique and valued. Open debate and diverse viewpoints are built into how decisions actually get made here, at every level. Growth at rocketship speed: Drata is scaling fast, which means scope grows fast too. High performers get more ownership, visibility, and experience. A crew, not just coworkers: Dratanauts consistently describe a "come as you are" culture with sharp, curious people—the kind of team that makes hard problems genuinely fun to solve. See what they say here and follow us on LinkedIn for company news, employee stories, and career updates. Job Summary: The Staff Software Engineer serves as a technical leader across multiple small teams. They design and build scalable systems, guide architectural decisions, and tackle complex challenges that span codebases and domains. They work closely with Product and Engineering leadership to shape the technical roadmap, ensure systems are reliable and secure, and drive key cross-team initiativ
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Our Senior Software Engineers lead and mentor engineers, delivering high-value products for our customers and infrastructure that enables our business to scale. Vanta’s team and technology surface are growing quickly, and it’s essential that we invest in the right abstractions and systems to enable us to scale with our business. As a Senior Software Engineer, you’ll be responsible for setting technical direction to enable our product and infrastructure to scale with our business, driving complex projects across our technical stack, and mentoring our talented engineering team. Your past experience will be leveraged to enable and accelerate Vanta’s growth. Our business has found incredible product-market fit and has monetized effectively since the day we signed our first customer. We’re growing at a blistering pace, which presents career-defining opportunities for engineers to accelerate their growth and to contribute to a rapidly-scaling company. Visit our Vanta Engineering Blog to learn more about what our team is working on! The GRC (Governance, Risk and Compliance) organization is the primary org responsible for developing and maintaining Vanta's core product offerings. These teams are at the heart of Vanta moving upmarket to support enterprise customers and build products that enable our customers’ existing security and compliance programs to integrate seamlessly with Vanta, giving them invaluable insights and recommendations to continue to operate, mature and evolve their programs. What you’ll do as a Senior Software Engineer at Vanta: Lead complex projects with multiple stakeholders and engineers to deliver significant imp
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Vanta’s team and technology surface are growing quickly, and it’s essential that we invest in the right abstractions and systems to enable us to scale with our business. As a Staff Software Engineer, you’ll be responsible for setting technical direction to enable our product and infrastructure to scale with our business, driving complex projects across our technical stack, and mentoring our talented engineering team. Your past experience will be leveraged to enable and accelerate Vanta’s growth. Our business has found incredible product-market fit and has monetized effectively since the day we signed our first customer. We’re growing at a blistering pace, which presents career-defining opportunities for engineers to accelerate their growth and to contribute to a rapidly-scaling company. The GRC (Governance, Risk and Compliance) organization is the primary org responsible for developing and maintaining Vanta's core product offerings. These teams are at the heart of Vanta moving upmarket to support enterprise customers and build products that enable our customers’ existing security and compliance programs to integrate seamlessly with Vanta, giving them invaluable insights and recommendations to continue to operate, mature and evolve their programs. As a Staff Software Engineer at Vanta, you will play a critical role in driving the long-term technical strategy, leading complex initiatives, and making high-impact decisions that affect your product area and the broader engineering organization. You will set the tone for engineering excellence and culture. This role involves a mix of hands-on development, leadership, strategic thinki
Strength in Trust OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society. The Challenge We are looking for a dynamic Senior Information Security GRC Analyst to support IT and InfoSec by performing various governance, risk, and compliance activities as part of the OneTrust InfoSec GRC team. Your Mission Customer Security Assurance & Questionnaires Own a high volume of end-to-end completion of customer security questionnaires (CAQs) , RFP security sections, and other assurance artifacts (e.g., SIG, CAIQ, custom questionnaires). Provide accurate, consistent, and defensible responses by leveraging internal evidence repositories (SOC reports, ISO certificates, policies, standards, diagrams, pen test summaries, etc.). Partner with internal stakeholders (Sales, Marketing, Customer Success, Security, Engineering, Privacy, Legal, Compliance, Product) to validate responses and resolve gaps. Customer Engagement & Security Discussions Meet with customers and prospects to explain security controls, risk posture, and compliance commitments . Present security topics with confidence and clarity—tailoring depth for technical and non-technical audiences. Support Sales and Customer Success by addressin
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team’s mission. The GRC team is at the heart of Roblox's security organization — empowering every builder to make risk-informed decisions by establishing a portfolio of governing policies and standards, a repeatable and scalable method of assessing and quantifying risk, and a formal oversight process for GRC capabilities across Roblox. Our program takes a balanced, "right-sized" approach to security governance — combining qualitative and quantitative risk management methodologies, including Factor Analysis of Information Risk (FAIR), to assess and prioritize the security risks that matter most to Roblox. GRC partners closely with Engineering, Legal, Finance, and leadership — including providing regular reporting to the Board of Directors and the Audit & Compliance Committee — to ensure that security risk is visible, well-understood, and actioned appropriately. The team is in an exciting phase of growth and innovation. We are using engineering to drive automation across risk management, policy lifecycle management, supply chain risk, AI risk, and controls pr
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Vanta for Government (V4G) is how we bring that mission to the public sector. As federal compliance undergoes its biggest shift in a decade — FedRAMP 20x, machine-readable authorization, OSCAL — we're building the platform that turns federal frameworks into automated, continuously monitored product experiences. The GRC Subject Matter Experts on this team are the people who make that possible. As Vanta's GRC Subject Matter Expert for V4G , you'll own federal compliance content used by every customer pursuing or maintaining federal authorization on our platform. This is an interpretation-and-authoring role, not a compliance program administration role: your job is to interpret underlying control requirements, identify where FedRAMP modifies or constrains the NIST framework, and translate those interpretations into precise, technically testable guidance that engineering can build and customers can act on. The content you write ships as product — a five-person startup and a Fortune 100 CSP both receive it — so calibrating depth, precision, and universality is the core craft. You'll join Vanta's Security organization, which directly influences product development, facilitates the creation of automated GRC solutions for customers, and provides expert advisory services across the company. What you’ll do as a V4G GRC SME at Vanta: Build and own federal compliance frameworks — Lead the creation, enhancement, and lifecycle management of controls, evidence requirements, and implementation guidance for FedRAMP (Low/Moderate/High), NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP. Author clear control rationales, acceptance crite
Position Overview As a Solutions Engineer at Diligent, you will partner closely with Sales to help organizations understand how our platform can transform the way they identify and mitigate risk, perform audits, strengthen controls, and operationalize broader GRC programs. You’ll independently lead the SE workstream on small to mid-sized opportunities, while partnering with more senior Solutions Engineers on complex, multi-pillar deals, acting as a trusted partner to customer stakeholders and helping translate Risk & Audit and broader GRC challenges into clear, compelling solutions that drive business value. If you enjoy combining domain expertise, storytelling, solution design, and customer interaction and are looking to build your career in a commercial, customer-facing environment, this is a strong next step. Key Responsibilities Customer & Commercial Partnership Partner with Sales to lead the full pre-sales lifecycle for small to mid-sized opportunities, helping customers understand how Diligent solves real-world risk, audit, and control management challenges. Deliver independent, well-prepared, tailored software demonstrations that clearly articulate business value, while seeking coaching and feedback from senior team members for continuous improvement. Engage confidently with stakeholders across Internal Audit, Risk, Compliance, IT, Controls, and Governance teams, owning day-to-day customer conversations and escalating to senior SEs for high-risk or complex topics as needed. Translate customer pain points into clear solution narratives, including outcomes and success criteria, to support deal progression and closure. Own the technical win for small to mid-sized opportunities, and contribute to the technical strategy on larger, multi-stakeholder deals in partnership with senior SEs. Solution Design & Thought Leadership Design and present solu
Position Overview As a Solutions Engineer at Diligent, you will partner closely with Sales to help organizations understand how our platform can transform the way they identify and mitigate risk, perform audits, strengthen controls, and operationalize broader GRC programs. You’ll independently lead the SE workstream on small to mid-sized opportunities, while partnering with more senior Solutions Engineers on complex, multi-pillar deals, acting as a trusted partner to customer stakeholders and helping translate Risk & Audit and broader GRC challenges into clear, compelling solutions that drive business value. If you enjoy combining domain expertise, storytelling, solution design, and customer interaction and are looking to build your career in a commercial, customer-facing environment, this is a strong next step. Key Responsibilities Customer & Commercial Partnership Partner with Sales to lead the full pre-sales lifecycle for small to mid-sized opportunities, helping customers understand how Diligent solves real-world risk, audit, and control management challenges. Deliver independent, well-prepared, tailored software demonstrations that clearly articulate business value, while seeking coaching and feedback from senior team members for continuous improvement. Engage confidently with stakeholders across Internal Audit, Risk, Compliance, IT, Controls, and Governance teams, owning day-to-day customer conversations and escalating to senior SEs for high-risk or complex topics as needed. Translate customer pain points into clear solution narratives, including outcomes and success criteria, to support deal progression and closure. Own the technical win for small to mid-sized opportunities, and contribute to the technical strategy on larger, multi-stakeholder deals in partnership with senior SEs. Solution Design & Thought Leadership Design and present solu
Agents have changed the game for software delivery and efficacy. Diligent is the leading GRC platform in the world, and we are racing ahead to take the agents show on the road and work with the customers where they work . The FDE function will lead the change on how we embed AI agents into some of the world’s most complex governance, risk and compliance environments. This is not a support or consultancy role. It is a builder role, for someone who is equally comfortable reading a failing agent trace, running a discovery workshop with a bank’s internal audit team, and translating what they find into a production-grade agentic solution. You will be building AI agents for GRC professionals , not assistants that surface suggestions, but agents that own complex, multi-step workflows end to end . Agents that customers can hand a task to and trust it will come back done. Closing the gap between a promising prototype and something a company Board and ELT depends on is a completely . Here’s a breakdown of what you’ll do Embed directly with major enterprise customers (global banks, regulated corporates) across EU and US ; sitting wi th internal audit teams, risk functions, compliance and governance professionals to understand their real workflows and devise agentic solutions to intelligently automate them creating tremendous efficacy and efficiencies for our customers. Run agent-focused discovery workshops, rapidly prototype agentic solutions, and test them with practitioners; distinguishing between workflows that need an agent and those that need a button. Source, integrate, and move data between enterprise systems as part of live customer implementations — understanding the real data landscape customers operate in and building reliable pipelines to support it . Take agents from prototype t
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Solutions Engineer, you'll serve as a trusted technical voice, guiding customers toward clarity, feasibility, and alignment on the end-to-end solution. Because Vanta is the platform our customers rely on to build and run their GRC programmes, this is a natural next step for GRC professionals, programme managers, auditors, and compliance practitioners who want to apply their domain expertise in a strategic, customer-facing pre-sales role. You’ll be an integral part of the Sales team, working to ensure technical fit and create innovative solutions for our customers. Your attention to detail, focused on customer needs, will ultimately improve retention and overall success. This role will be based from our London office or Dublin office with an office-centric hybrid schedule. The standard in-office days are Tuesday, Wednesday, and Thursday. GRC practitioners are especially encouraged to apply—whether you've managed GRC programmes in-house, audited them as an internal or external auditor, or helped customers meet their GRC programme needs at a GRC vendor, you'll bring exactly the customer empathy and domain fluency this role thrives on. What you’ll do as a Solutions Engineer at Vanta: Serve as a strategic sales partner, owning the technical relationship with prospects and customers. Strategic Discovery and Deal Qualification: Partner with Account Executives to uncover technical, operational, and business pain points, validating use cases and aligning solutions to measurable customer impact and urgency. Secure the Solution Win and Alignment: Validate technical feasibility, drive clarity on success criteria, and guide stakeholder
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Solutions Engineer, you'll serve as a trusted technical voice, guiding customers toward clarity, feasibility, and alignment on the end-to-end solution. Because Vanta is the platform our customers rely on to build and run their GRC programmes, this is a natural next step for GRC professionals, programme managers, auditors, and compliance practitioners who want to apply their domain expertise in a strategic, customer-facing pre-sales role. You’ll be an integral part of the Sales team, working to ensure technical fit and create innovative solutions for our customers. Your attention to detail, focused on customer needs, will ultimately improve retention and overall success. This role will be based from our London office or Dublin office with an office-centric hybrid schedule. The standard in-office days are Tuesday, Wednesday, and Thursday. GRC practitioners are especially encouraged to apply—whether you've managed GRC programmes in-house, audited them as an internal or external auditor, or helped customers meet their GRC programme needs at a GRC vendor, you'll bring exactly the customer empathy and domain fluency this role thrives on. What you’ll do as a Solutions Engineer at Vanta: Serve as a strategic sales partner, owning the technical relationship with prospects and customers. Strategic Discovery and Deal Qualification: Partner with Account Executives to uncover technical, operational, and business pain points, validating use cases and aligning solutions to measurable customer impact and urgency. Secure the Solution Win and Alignment: Validate technical feasibility, drive clarity on success criteria, and guide stakeholder
ABOUT BASETEN Baseten powers mission-critical inference for the world's most dynamic AI companies, like Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma and Writer. By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we enable companies operating at the frontier of AI to bring cutting-edge models into production. We're growing quickly and recently raised our $1.5B Series F , led by Altimeter Capital, Conviction Partners, and Spark Capital. Join us and help build the platform engineers turn to to ship AI products. THE ROLE We are seeking an experienced and detail-oriented GRC (Governance, Risk, and Compliance) Manager to build, support, and continuously enhance Baseten’s security governance, compliance, and privacy programs. As one of the early members of our security organization, you will play a key role in ensuring our platform meets and exceeds the highest standards for privacy, trust, and regulatory compliance. In this role, you’ll work cross-functionally with engineering, operations, legal, and leadership teams to develop policies, manage audits, and implement controls aligned with frameworks such as SOC 2, ISO 27001, ISO 27701, and FedRAMP. You’ll be instrumental in building scalable processes to manage risk, support customer assurance, and uphold Baseten’s commitment to security and compliance as we grow. RESPONSIBILITIES Governance & Policy Development: Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices. Risk Management: Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks. Compliance Operations: Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards and regulations. Audit & Certification Management: Coordinate external audits and certification processes, ensuring e
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As an Engineering Manager leading our Reporting team, you will lead a newly structured team focused on a critical product area within GRC Program Orchestration. This role represents an exciting opportunity to shape the future of how Vanta customers understand, visualize, and operationalize their compliance and security programs. This team is focused on evolving Vanta’s reporting platform beyond dashboards into a scalable, AI-powered reporting experience. The team owns core initiatives across enterprise reporting, historical analytics, AI-assisted insights, and certified data infrastructure powering in-product experiences. This role sits at the intersection of data products, enterprise scalability, and product innovation. As reporting becomes increasingly foundational to enterprise growth, customer retention, and Vanta’s long-term AI strategy, this role will play a key role in shaping engineering execution, cross-functional alignment, and the long-term technical direction of one of Vanta’s critical product investments. Visit our Vanta Engineering Blog to learn more about what our team is working on! What you’ll do as an Engineering Manager at Vanta: Build and scale a high-performing team: lead, coach, and grow the team while hiring strategically, identifying operational gaps, and raising the engineering bar Drive execution across strategic initiatives: Deliver against a multi-quarter roadmap spanning reporting infrastructure, enterprise reporting capabilities, AI-powered insights, and scalable data foundations Shape technical and product strategy: Partner closely with Product and cross-functional engineering teams to define the
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As an Engineering Manager leading our Reporting team, you will lead a newly structured team focused on a critical product area within GRC Program Orchestration. This role represents an exciting opportunity to shape the future of how Vanta customers understand, visualize, and operationalize their compliance and security programs. This team is focused on evolving Vanta’s reporting platform beyond dashboards into a scalable, AI-powered reporting experience. The team owns core initiatives across enterprise reporting, historical analytics, AI-assisted insights, and certified data infrastructure powering in-product experiences. This role sits at the intersection of data products, enterprise scalability, and product innovation. As reporting becomes increasingly foundational to enterprise growth, customer retention, and Vanta’s long-term AI strategy, this role will play a key role in shaping engineering execution, cross-functional alignment, and the long-term technical direction of one of Vanta’s critical product investments. Visit our Vanta Engineering Blog to learn more about what our team is working on! What you’ll do as an Engineering Manager at Vanta: Build and scale a high-performing team: lead, coach, and grow the team while hiring strategically, identifying operational gaps, and raising the engineering bar Drive execution across strategic initiatives: Deliver against a multi-quarter roadmap spanning reporting infrastructure, enterprise reporting capabilities, AI-powered insights, and scalable data foundations Shape technical and product strategy: Partner closely with Product and cross-functional engineering teams to define the
Get new grc engineer jobs by email
Daily job updates · Unsubscribe anytime