← Back to list

Job
Senior Security Engineer, GRC
Security Engineer
• On-site
• Full-time
• 📍 United States
The Senior Security Engineer, GRC owns the customer-facing compliance program end to end, managing security questionnaires, due diligence requests, and compliance reviews, and builds customer trust in the company's security posture in partnership with Sales, Legal, and Product.
Stack
Responsibilities
- ▹Own the intake, prioritization, and completion of all inbound customer security questionnaires, RFPs, and due diligence requests (SIG, CAIQ, custom enterprise questionnaires), with accuracy, thoroughness, and turnaround time
- ▹Serve as the primary customer-facing representative for security and compliance, leading calls and meetings with enterprise customers, prospects, and their security or procurement teams
- ▹Build and maintain a comprehensive, evergreen response library for common security and compliance questions, reducing duplication of effort
- ▹Build and maintain automations to continuously validate the organization's compliance posture (SOC2 Type II, ISO 27001, HIPAA), coordinating evidence collection, managing auditor relationships, and driving audit readiness
- ▹Build dashboards and reporting pipelines that give leadership real-time visibility into compliance posture, open risks, and program health
- ▹Design and automate the third-party risk assessment process, including vendor tiering logic, questionnaire workflows, and continuous monitoring for critical vendors
- ▹Perform ongoing risk assessments and maintain a risk register, escalating material findings to leadership with clear remediation recommendations
- ▹Conduct third-party vendor risk assessments, including use case-specific analysis, tiering, monitoring, and implementation recommendations
- ▹Author, maintain, and operationalize security policies and procedures; track employee acknowledgments and manage exceptions through to resolution
- ▹Coordinate and participate in customer security review meetings, onsite or virtual, with enterprise security, legal, and procurement stakeholders
- ▹Collaborate cross-functionally with Engineering, Legal, and Product to gather documentation, validate control descriptions, and resolve compliance gaps
Requirements
- ▹8+ years of experience in GRC, information security compliance, or a closely related field
- ▹Deep, hands-on experience with at least two major compliance frameworks (SOC2, ISO 27001, HIPAA, PCI-DSS, or FedRAMP), including direct involvement in audits and assessments
- ▹Proven track record managing high volumes of security questionnaires and enterprise due diligence requests, including SIG and CAIQ formats
- ▹Strong understanding of the security program's influence on company revenue and a partnership mindset with the Go To Market function
- ▹Scripting and automation fluency (Python, Bash, or similar) and a track record of building tools, not just spreadsheets
- ▹Strong customer-facing communication skills, comfortable presenting to a CISO, walking a procurement team through a control matrix, or discussing technical security controls with customer engineering leaders
- ▹Solid understanding of risk management principles, with hands-on experience performing risk assessments and maintaining a risk register
- ▹Ability to translate technical security controls into clear, business-appropriate language for non-technical audiences
- ▹Strong organizational skills and the ability to manage multiple concurrent questionnaire engagements with distinct deadlines and stakeholders
- ▹Bachelor's degree in Information Security, Computer Science, Business, or a related field (or equivalent experience)
Nice to have
- ▹Security certifications: CISSP, CISM, CRISC, CISA, or CCSP
- ▹Experience with GRC platforms such as Vanta, Drata, Sprinto, or similar
- ▹Familiarity with NIST CSF or NIST 800-53 control frameworks
- ▹Background in SaaS, fintech, or healthcare environments with regulated data handling requirements
- ▹Experience drafting or reviewing Data Processing Agreements (DPAs), Business Associate Agreements (BAAs), or security-related contract language
- ▹Experience supporting FedRAMP authorization or state-level public sector compliance programs
Soft skills
Strong customer-facing communication across all levels, from CISO to procurementAbility to translate technical controls into business languageStrong organizational skills managing concurrent engagementsPartnership mindset with go-to-market teams
What we offer
- ▹Eligible to participate in Temporal's equity plan
Languages: Angol: Felsőfok
Education: Információbiztonság, számítástechnika, üzleti vagy kapcsolódó terület, BSc (vagy azzal egyenértékű tapasztalat)
Similar jobs

Job
Sr. Security Engineer, Corporate Information Security
betterment
$165,000–$185,000/yr
gross
🏢 On-site
🇺🇸 Betterment HQ - New York City
🗣️ EN

Job
Sr. Product Security Engineer
betterment
+7
$175,000–$205,000/yr
gross
🏢 On-site
🇺🇸 Betterment HQ - New York City
🗣️ EN

Job
Sr. Staff Embedded Software Engineer - Security
Ambiq Micro, Inc.
💰 Salary: not specified
🏢 On-site
🇺🇸 Austin
🗣️ EN

Job
Embedded Software Engineer - Security
Ambiq Micro, Inc.
💰 Salary: not specified
🏢 On-site
🇺🇸 Austin
🗣️ EN

Job
Senior Security Engineer, Bug Bounty
Mozilla
+1
💰 Salary: not specified
🌍 Remote
🇺🇸 Remote US
🗣️ EN

Job
Staff Security Engineer, Secure Digital Asset Operations
Ripple
$200,000–$250,000/yr
gross
🏢 On-site
🇺🇸 New York
🗣️ EN