Loading...

Staff Security GRC Engineer

  • Company: Get A Job.ai
  • Salary: Pay not listed
  • Work type: Remote
  • Full Time
  • Remote

Website Get A Job.ai

Represented by Get A Job.ai

Responsibilities

We are representing a confidential technology organization seeking a Staff Security GRC Engineer to join their remote team. In this role, you will be responsible for maintaining and advancing the Information Security Management System (ISMS) and supporting ISO 27001 and SOC 2 Type 2 compliance programs.

Your core responsibilities will include:

  • Maintaining and maturing the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence
  • Supporting ISO 27001 and SOC 2 Type 2 audit execution—determining scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings
  • Contributing to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization's actual control environment
  • Tracking gaps and remediation efforts arising from readiness assessments and audits
  • Leading the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready
  • Supporting compliance scaling as additional products or business units pursue readiness assessments and certification
  • Supporting the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001's internal audit requirements
  • Partnering closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices
  • Advising senior leadership on audit risk, certification readiness, and compliance program strategy

What We're Looking For

The ideal candidate brings hands-on experience across the full breadth of a compliance program, is comfortable building process where none yet exists, and works well with a wide range of cross-functional stakeholders.

Required qualifications:

  • 5+ years of experience in information security, GRC, or compliance-focused roles
  • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, gained through meaningful involvement in audits from readiness through certification
  • Comfort operating across the full breadth of an ISMS—SoA maintenance, Management Review Meetings, and System Description authorship
  • Demonstrated experience writing and revising security policies, including running cross-functional review cycles to gain organization-wide buy-in and adoption
  • Experience tracking gaps and remediation plans and connecting that work to an organization's broader compliance and risk program
  • Excellent cross-functional collaboration skills—comfortable working with engineers, product managers, legal, and executive stakeholders, and able to translate compliance requirements into practical, actionable workflows
  • Ability to ramp up quickly and operate with a high degree of independence
  • Comfort building processes where none yet exist
  • Strong written and verbal communication skills; ability to represent the organization credibly and confidently in front of external auditors

Preferred qualifications:

  • Relevant industry certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer

How We Work With You

Our talent team at Get A Job.ai will guide you through the entire process. When you apply through our platform, one of our recruiters will conduct an initial screening to understand your background and ensure alignment with the role. We will then submit your profile to our client for consideration. Please note that candidates should not contact the client directly—all communication will be coordinated through Get A Job.ai to ensure a smooth and professional process.

Pay

This is a remote position based in France. Compensation details will be discussed during the screening process with our recruiting team.

Equal Employment Opportunity

Get A Job.ai is committed to creating a diverse and inclusive environment. We welcome applications from all qualified candidates regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

Apply with Get A Job.ai

A recruiter will review your profile and submit you to the client. Do not contact the client directly.

More options

Apply with Get A Job.ai

Apply through Get A Job.ai. A recruiter will review your profile and submit you. Do not contact the client directly.

Apply through Get A Job.ai. A recruiter will review your profile and submit you.

Job details above are provided by the employer/source. The sections on this page are compiled from public data sources with AI assistance.

Accommodations: if you need a workplace accommodation to apply for or perform this job, see ADA.gov or EEOC.gov for guidance on your rights and how to request one.

Add application deadline to calendar

Listing facts

  • Role Staff Security GRC Engineer
  • Employer Get A Job.ai
  • Location Remote
  • Type Full Time
  • Pay (from listing) Pay not listed
  • Posted September 20, 2026
  • Apply by October 20, 2026
  • Overview Full job description on this page (567 words)

Facts above come from this job record on Get A Job.AI — not copied from third-party review sites.

Limited public data for this employer

We only show facts we can ground in public sources (Wikidata, O*NET, news/discussion links, or this listing). We do not invent Glassdoor-style ratings, salaries, or testimonials when data is thin. Use the listing facts, occupation context, and related openings below while we continue researching.

Explore related openings

Keep exploring on Get A Job.ai

Not quite the right fit? Your next opportunity is a click away.

Hiring instead? Post a job and reach candidates searching right now.

Staff Security GRC Engineer Get A Job.ai · Remote