Senior GRC Engineer @A-LIGN
Compliance
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 4wks ago

[Hiring] Senior GRC Engineer @A-LIGN

4wks ago - A-LIGN is hiring a remote Senior GRC Engineer. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

The Senior GRC Engineer owns audit evidence collection and technical control maintenance across A-LIGN's growing portfolio of compliance frameworks, including FedRAMP Moderate Equivalency, FedRAMP 20x, ISO 27001, ISO 42001, and SOC 2. This role bridges the GRC function and A-LIGN's technical teams, working hands-on in GCP, GitHub, and Microsoft 365 to collect evidence, verify controls, and keep A-LIGN continuously audit-ready. The Senior GRC Engineer works cross-functionally with every technical department in the company to reduce audit burden on engineering and IT while protecting the certifications that A-LIGN's clients and platforms depend on. The role also supports broader information security activities, including risk assessments, threat modeling, security reviews, and AI technical safeguards.

Responsibilities

  • Own end-to-end audit evidence collection, validation, and organization across A-LIGN's compliance frameworks, including FedRAMP (Moderate Equivalency and FedRAMP 20x), ISO 27001, ISO 42001, SOC 2, NIST 800-53, and NIST 800-171.
  • Maintain and continuously verify technical controls across A-LIGN's cloud and corporate environments, including Google Cloud Platform (GCP/GKE), GitHub, and Microsoft 365/Entra ID.
  • Serve as the primary liaison between the GRC function and technical departments (IT, Engineering, DevOps) to gather evidence, validate control implementation, and reduce audit burden on those teams.
  • Support FedRAMP continuous monitoring activities, including Key Security Indicator (KSI) evidence, vulnerability scan artifact collection, POA&M tracking, and assessor (3PAO) requests.
  • Build and maintain evidence automation, including integrations between GRC tooling and source systems (identity provider, cloud platforms, code repositories, ticketing, endpoint management) to reduce manual collection effort.
  • Support A-LIGN's ISO 42001 Artificial Intelligence Management System (AIMS), including AI risk register evidence, AI control monitoring, and nonconformity remediation tracking.
  • Prepare audit-ready evidence packages and coordinate directly with external assessors and certification bodies during assessment windows.
  • Monitor control health between audit cycles, identify control drift or failures, and drive remediation with control owners before findings occur.
  • Maintain compliance documentation, including control narratives, policies, and procedures.
  • Support supplier and vendor security reviews with framework-specific evidence requirements.
  • Track framework changes (FedRAMP 20x requirements, ISO standard revisions, SOC 2 criteria updates) and translate them into actionable control and evidence updates.
  • Conduct security risk assessments and contribute to A-LIGN's corporate risk management program and risk register.
  • Participate in threat modeling for A-SCEND features, internal systems, and AI use cases, and translate findings into control improvements.
  • Perform security reviews of new tools, vendors, and internal initiatives, including support for Vendor Review Board activities.
  • Implement and validate AI technical controls and safeguards, including data loss prevention, AI connector and agent governance, and acceptable use enforcement, in support of A-LIGN's AI Management System.
  • Report compliance posture, evidence status, and audit readiness metrics to the CISO and GRC leadership.

Qualifications

  • Bachelor's degree in Information Systems, Cybersecurity, Business, or equivalent combination of education and experience.
  • 5+ years of experience in information security, GRC, IT audit, or compliance engineering roles.
  • Hands-on experience with audit evidence collection and technical control validation for at least two of the following: FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171.
  • DevSecOps or cloud engineering experience sufficient to independently locate and extract evidence from GCP, GitHub, and Microsoft 365/Entra ID environments.
  • Experience with GRC platforms and evidence automation (AuditBoard, Vanta, Drata, or similar).
  • Experience supporting external audits and assessor interactions, including 3PAO assessments.
  • Working knowledge of vulnerability management, CI/CD pipelines, infrastructure-as-code, and identity and access management concepts.
  • Experience scripting or automating evidence collection (Python, PowerShell, or similar) preferred.
  • Familiarity with risk assessment methodologies, threat modeling (e.g., STRIDE), and security review processes preferred.

Requirements

  • CISA, CISSP, CCSK/CCSP, ISO Lead Auditor/Implementer, or relevant certifications preferred but not required.
  • Strong cross-functional collaboration and project management skills.
  • Ability to translate framework requirements into clear, actionable requests for technical teams.
  • Highly organized with the ability to manage evidence deadlines across multiple concurrent audit cycles.
  • Excellent written communication for control narratives, evidence descriptions, and assessor responses.
  • Self-directed with strong follow-through in a fast-paced, deadline-driven environment.
  • Proven experience utilizing AI tools to automate manual tasks, streamline workflows, and increase team efficiency.
  • Experience operating in PE-backed or high-growth environments preferred.

Benefits

  • Healthcare, Dental, and Vision Benefits.
  • Employer Paid Life Insurance and Disability Insurance.
  • EAP - Employee Assistance Program.
  • Pet Insurance.
  • 401(k) Plan with Employer Matching.
  • Competitive Bonus Structure.
  • Home Office Reimbursement.
  • Certification Reimbursement.
  • Personalized Career Coaching.
  • Generous Paid Time Off.
  • Paid Office Closure December 25-January 1.
  • Vacation Bonus.
  • Summer Hours.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior GRC Engineer @A-LIGN
Compliance
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 4wks ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,870+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later