Clerk.com Logo

Clerk.com

GRC Engineer

Posted An Hour Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
Own Clerk’s SOC 2 Type II, HIPAA, and future compliance frameworks. Design controls, manage evidence and audits, lead vendor reviews, maintain risk assessments, and oversee security questionnaires and trust center workflows. Build integrations, automations, policy-as-code checks, configuration drift detection, and control-failure pipelines across cloud, SaaS, and internal systems. Embed compliance into software development and change management while reducing manual audit work.
The summary above was generated by AI
About Clerk

Clerk is on a mission to solve the user identity layer once and for all. We are a globally distributed team dedicated to providing best-in-class developer infrastructure to build the next generation of AI software. Today, we provide developers with full-stack React components and hooks like , , , useUser, and useOrganization. These APIs allow developers to build hard-to-get-right infrastructure for user identity, organization management and billing flows. We believe that a component is worth a thousand APIs.

Clerk is looking for a Senior GRC Engineer to join our Security Team. Our customers put Clerk in the middle of their authentication flow, and every one of them runs us through their own vendor review before they do. You'll own the program that makes that review easy: the controls, the evidence, the audits, and the answers.

You'll work as a hands-on engineer. Expect to spend a lot of your time writing integrations, automations, and internal tools that enforce policies and automate the evidence gathering. The goal is a program that's always current, so an audit is just someone observing it rather than a quarterly scramble.

What you'll do
  • Own SOC 2 Type II and HIPAA end to end: scoping, control design, evidence, auditor walkthroughs, and remediation

  • Scope and lead our next framework (ISO 27001 is the likely candidate) based on what customers actually ask for

  • Build and maintain the integrations that feed our GRC platform from our cloud providers, SaaS tools, and internal systems

  • Turn controls into continuous checks: policy-as-code, config drift detection, and a control-failure pipeline from detection to closure

  • Run the vendor security review program, from intake to periodic re-review

  • Own the security questionnaire and trust center workflow

  • Maintain the risk register and run risk assessments that produce documented decisions

  • Embed compliance requirements into the SDLC and change management so they're enforced by tooling, not by reminders

  • Reduce the number of things a human has to do to pass an audit every quarter

Who you are
  • 5+ years in security, with demonstrated experience building automation for a GRC or compliance program

  • You've been the technical owner of at least one SOC 2 Type II or ISO 27001 audit and can tell us what you would do differently

  • You write code, and you use LLMs to get more done without lowering the bar

  • Hands-on with a GRC platform's API, not just its dashboard

  • Cloud IAM and configuration depth on at least one provider, GCP preferred

  • You can decide what evidence is sufficient and defend an automated test to an auditor

  • Comfortable being one of a few security engineers; you can scope, prioritize, and ship without a lot of process around you

  • Clear writer: policies, control narratives, and questionnaire answers are read by customers, so they have to be good

Nice-to-haves
  • Experience at an all-remote company

  • Shipped LLM or agentic workflows in production for compliance work

  • Experience at a developer-tools company

Benefits
  • Competitive Salary – We want you to know that we value the skills and experience you bring to the table. We go out of our way to make sure that you feel fairly compensated.

  • Equity Ownership – At Clerk, we believe in shared success. That's why we offer a stock option plan so that everyone can benefit from the growth and prosperity of the company.

  • Health Coverage – We care about your well-being. That's why we offer top-tier health insurance to ensure that your health needs are fully met.

  • Work Gear - Set up your ideal home office with the gear of your choice. At Clerk, we want to ensure that you have everything you need to perform at your best.

  • Flexible Vacation Policy – We believe in work-life balance and trust you to take the time you need. Although we recommend 25 days per year, our vacation policy is unlimited. This is in addition to observing national holidays specific to your country of residence.

  • Diverse and Inclusive Team – Join our exceptional, diverse, and globally distributed team at Clerk. We are committed to fostering an inclusive environment where everyone can contribute their best in building impactful products and tools for the modern web.

Similar Jobs

23 Days Ago
In-Office or Remote
CA, USA
185K-327K Annually
Senior level
185K-327K Annually
Senior level
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
Build and operate GRC data pipelines, integrations, policy-as-code, continuous control monitoring, evidence automation, and agentic AI workflows. Normalize security data from diverse systems, create auditable evaluation harnesses, govern AI systems, and define technical direction across teams. Partner with security governance, compliance, and engineering groups to transform manual governance processes into scalable products.
Top Skills: AWSBuildkiteCi/CdClaudeGCPGoGrpcHTTPJavaJSONKotlinKubernetesLlm ApisModel Context ProtocolProtocol BuffersPythonSnowflakeSQLTerraform
4 Days Ago
In-Office or Remote
100K-150K Annually
Senior level
100K-150K Annually
Senior level
Artificial Intelligence • Information Technology • Software • Consulting
Designs and operates SAP security and GRC frameworks across enterprise landscapes, including authorization roles, access provisioning, segregation-of-duties analysis, audit support, Fiori and BTP security, logging, and security remediation. The role configures SAP GRC Access and Process Control, supports SOX, GxP, and PCI audits, documents technical processes, and mentors junior engineers.
Top Skills: IamIasIgaIpsSap AraSap ArmSap BrmSap BtpSap Bw/4HanaSap EamSap EccSap FioriSap Grc Access ControlSap Grc Process ControlSap IdmSap S/4HanaSap SuccessfactorsXsuaa
8 Days Ago
Remote
United States
112K-179K Annually
Senior level
112K-179K Annually
Senior level
Aerospace • Information Technology • Security • Cybersecurity • Defense
Owns cloud GRC transformation across audits, assessments, security documentation, continuity planning, privacy reviews, compliance reporting, and remediation. Builds automated evidence-collection and continuous-monitoring pipelines using AWS services, scripting, and infrastructure as code. Serves as the primary liaison with auditors, assessors, system owners, and risk stakeholders while maintaining SSPs and NIST 800-53 controls. The role requires hands-on cloud engineering, security tooling, GRC platform administration, automation, and extensive compliance experience.
Top Skills: AWSAws Audit ManagerAws CloudtrailAws ConfigAws Security HubBashCentralized LoggingCloudFormationEdrFirewallsInfrastructure As CodePowershellPrisma CloudPythonSIEMTerraformVdiWiz

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account