Back to Remote jobs  >   All others
Security Engineer - GRC @Machinify
All others
Salary usd 90,000 - 12..
Remote Location
🇺🇸 USA Only
Job Type full-time
Posted 3d ago

[Hiring] Security Engineer - GRC @Machinify

3d ago - Machinify is hiring a remote Security Engineer - GRC. 💸 Salary: usd 90,000 - 120,000 per year 📍Location: USA

Role Description

At Machinify, we’re building a robust security program to protect our clients’ sensitive healthcare data and maintain the highest standards of information security. As part of the Security GRC team, you will play a critical technical role in configuring, automating, and integrating Machinify’s GRC platform (Vanta) to support compliance management, audit readiness, and risk program operations across the organization.

As a Security Engineer focused on GRC, you will bridge technical implementation and compliance requirements—helping streamline evidence collection, automate control monitoring, and connect Vanta to Machinify’s infrastructure and tooling. This role is well-suited for candidates with a mix of technical aptitude and compliance interest who want to build deep expertise in GRC platform engineering within a complex, multi-entity healthcare environment undergoing active transformation.

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, Compliance, Risk Management, or related field, or equivalent work experience
  • 3+ years of experience in information security, GRC, or a technical compliance role
  • Hands-on experience with a GRC platform such as Vanta, Drata, Tugboat Logic, ServiceNow GRC, Archer or similar
  • Working knowledge of SOC 2 Trust Service Criteria and HITRUST CSF control requirements
  • Familiarity with cloud environments (AWS or Azure) sufficient to understand integration points and relevant compliance controls
  • Experience with API integrations, webhooks, or similar mechanisms for connecting systems to compliance platforms
  • Understanding of common compliance evidence types and audit workflows for security certifications
  • Familiarity with healthcare compliance requirements, particularly HIPAA Security Rule
  • Strong organizational skills for managing multiple compliance workstreams simultaneously
  • Clear written communication for policy documentation, control narratives, and cross-functional stakeholder engagement

Requirements

  • Configure, administer, and continuously improve Machinify’s Vanta GRC platform across all organizational entities
  • Build and maintain Vanta integrations with cloud environments (AWS, Azure), identity providers, endpoint management tools, HR systems, and other compliance-relevant data sources
  • Automate evidence collection workflows to reduce manual effort for HITRUST r2, SOC 2 Type II, and other certification cycles
  • Develop and maintain custom tests, policies, and controls within Vanta to reflect Machinify’s specific compliance requirements and risk posture
  • Monitor control health dashboards and manage remediation workflows for failing or at-risk controls
  • Manage the Vanta vendor risk module, including questionnaire automation and third-party assessment workflows
  • Support access review automation through Vanta, ensuring timely completion and accurate documentation
  • Maintain and improve GRC platform documentation including integration configurations, data flows, and control mapping
  • Evaluate and implement new Vanta capabilities as the platform evolves, including AI-assisted compliance features
  • Support HITRUST r2 and SOC 2 Type II audit activities through evidence preparation, auditor portal management, and issue tracking
  • Assist with customer security questionnaire responses by leveraging Vanta’s trust center and evidence library
  • Contribute to third-party risk assessments by coordinating vendor security reviews and maintaining assessment records
  • Help develop and maintain security policies and procedures aligned with HITRUST and SOC 2 requirements
  • Support the risk register by maintaining risk records, tracking remediation actions, and producing risk reporting
  • Participate in security awareness program activities including content development and training delivery tracking
  • Assist with regulatory documentation requirements including HIPAA privacy and security program documentation
  • Collaborate with the Security Engineering team to ensure technical controls are properly reflected in the GRC platform

Benefits

  • Work from anywhere in the US! Machinify is digital-first.
  • Top Medical/Dental/Vision offerings
  • FSA/HSA
  • Tuition reimbursement
  • Competitive salary, 401(k) with company match
  • Additional health and wellness benefits and perks
  • Flexible and trusting environment where you’ll feel empowered to do your best work
Before You Apply
🇺🇸 Be aware of the location restriction for this remote position: USA Only
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Back to Remote jobs  >   All others
Security Engineer - GRC @Machinify
All others
Salary usd 90,000 - 12..
Remote Location
🇺🇸 USA Only
Job Type full-time
Posted 3d ago
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Unlock 152,720 Remote Jobs
🇺🇸 Be aware of the location restriction for this remote position: USA Only
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Unlock 152,720 Remote Jobs
×

Apply to the best remote jobs
before everyone else

Access 152,720+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews
Unlock All Jobs Now

Maybe later