Back to Remote jobs   >   All Others   >   grc analyst
GRC Engineer @Aegis AI
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 3d ago

[Hiring] GRC Engineer @Aegis AI

3d ago - Aegis AI is hiring a remote GRC Engineer. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

We're looking for a GRC Engineer to advance AegisAI's security program. We sell to security teams, which means our buyers grade us the way we grade our own vendors: audits, frameworks, questionnaires, policies, proof. Your job is to own that proof: keep it current, airtight, and fast to produce.

The title says engineer on purpose. We run compliance the way we run infrastructure:

  • Controls mapped once across frameworks.
  • Evidence collected automatically through APIs instead of screenshots.
  • An audit that falls out of how we operate every day rather than a yearly scramble.

You'll own our SOC 2 end to end, keep our policies current as we scale, advance the business continuity and incident response muscle behind our customer commitments, and answer the security reviews that gate our biggest deals.

You'll work directly with the head of security, our engineers, and the customers who ask the hard questions. What you build here becomes the reason deals close faster.

What You'll Do

  • Own Compliance end to end: Keep the program audit-ready year round and run the auditor relationship.
  • Pave the road to what's next: Keep us ahead of what our customers ask for, so when the business needs its next certification or framework, we're already on track.
  • Run our risk management program: Maintain the risk register, keep treatments moving, and ensure we have an accurate picture of risk at all times.
  • Own the policy suite: Keep our policies, standards and procedures current as we grow, aligned with how we operate, and clear to the customers who read them.
  • Own BC/DR and incident response: Maintain and exercise our plans and playbooks, own the customer notification commitments behind them, and make sure everyone knows their part before it's needed.
  • Answer the questions that gate deals: Own customer security questionnaires and TPRM reviews end to end, grow the answer library so answers stay accurate and consistent, and keep turnaround fast.
  • Run vendor and subprocessor risk: Review the vendors we depend on, keep DPAs and the subprocessor list current, scale third-party risk management as our vendor footprint grows, and handle customer data requests end to end.
  • Map controls across frameworks: Maintain our control set against the industry frameworks we build on, audit against it, and make one piece of evidence count everywhere it can.
  • Expand evidence automation: Pull more proof straight from systems through APIs and scripts, so audits and questionnaires draw from live data.

Qualifications

  • 4+ years in GRC, security compliance or audit at a SaaS company.
  • Experience running a SOC 2 Type II end to end at least once.
  • Ability to answer enterprise security questionnaires clearly.
  • Technical enough to read an architecture diagram and question an engineer's answer.
  • Ability to differentiate between a control that exists and one that's written down.
  • Proficient in scripting (Python or similar) and comfortable with APIs.
  • Working knowledge of major privacy regimes and their implications for a data processor.
  • Organized, self-directed, and honest about what you don't know yet.

Bonus Points

  • Experience implementing ISO 27001 or carrying a company through certification.
  • Compliance automation platform experience, especially custom tests and the API side.
  • AI governance exposure: ISO 42001, NIST AI RMF, or building an AI policy from scratch.
  • Experience building or testing BC/DR for a production SaaS.
  • Privacy certifications (CIPP or similar).
  • Experience working at a security vendor and familiarity with the standards your answers get held to.

Our Culture

  • Flat, flexible, and fast.
  • You'll own your decisions.
  • Clear KPIs for success β€” but how you get there is up to you.
  • If you want compliance work that protects our customers and wins deals instead of filling binders, and want to work with a team that moves at the speed of the real world, join us.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Back to Remote jobs   >   All Others   >   grc analyst
GRC Engineer @Aegis AI
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 3d ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 120,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 122,806+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later