A-LIGN Logo

A-LIGN

Senior GRC Engineer

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Owns audit evidence collection, technical control validation, continuous monitoring, and compliance documentation across FedRAMP, ISO 27001, ISO 42001, SOC 2, and NIST frameworks. Partners with IT, Engineering, and DevOps teams, supports external assessors, automates evidence collection, tracks remediation, and contributes to risk assessments, threat modeling, vendor reviews, and AI security safeguards.
The summary above was generated by AI
About the Role 

The Senior GRC Engineer owns audit evidence collection and technical control maintenance across A-LIGN's growing portfolio of compliance frameworks, including FedRAMP Moderate Equivalency, FedRAMP 20x, ISO 27001, ISO 42001, and SOC 2. This role bridges the GRC function and A-LIGN's technical teams, working hands-on in GCP, GitHub, and Microsoft 365 to collect evidence, verify controls, and keep A-LIGN continuously audit-ready. The Senior GRC Engineer works cross-functionally with every technical department in the company to reduce audit burden on engineering and IT while protecting the certifications that A-LIGN's clients and platforms depend on. The role also supports broader information security activities, including risk assessments, threat modeling, security reviews, and AI technical safeguards.

Reports to

Chief Information Security Officer

Pay Classification

Full-Time, Exempt  

Responsibilities 
  • Own end-to-end audit evidence collection, validation, and organization across A-LIGN's compliance frameworks, including FedRAMP (Moderate Equivalency and FedRAMP 20x), ISO 27001, ISO 42001, SOC 2, NIST 800-53, and NIST 800-171
  • Maintain and continuously verify technical controls across A-LIGN's cloud and corporate environments, including Google Cloud Platform (GCP/GKE), GitHub, and Microsoft 365/Entra ID
  • Serve as the primary liaison between the GRC function and technical departments (IT, Engineering, DevOps) to gather evidence, validate control implementation, and reduce audit burden on those teams
  • Support FedRAMP continuous monitoring activities, including Key Security Indicator (KSI) evidence, vulnerability scan artifact collection, POA&M tracking, and assessor (3PAO) requests
  • Build and maintain evidence automation, including integrations between GRC tooling and source systems (identity provider, cloud platforms, code repositories, ticketing, endpoint management) to reduce manual collection effort
  • Support A-LIGN's ISO 42001 Artificial Intelligence Management System (AIMS), including AI risk register evidence, AI control monitoring, and nonconformity remediation tracking
  • Prepare audit-ready evidence packages and coordinate directly with external assessors and certification bodies during assessment windows
  • Monitor control health between audit cycles, identify control drift or failures, and drive remediation with control owners before findings occur
  • Maintain compliance documentation, including control narratives, policies, and procedures
  • Support supplier and vendor security reviews with framework-specific evidence requirements
  • Track framework changes (FedRAMP 20x requirements, ISO standard revisions, SOC 2 criteria updates) and translate them into actionable control and evidence updates
  • Conduct security risk assessments and contribute to A-LIGN's corporate risk management program and risk register
  • Participate in threat modeling for A-SCEND features, internal systems, and AI use cases, and translate findings into control improvements
  • Perform security reviews of new tools, vendors, and internal initiatives, including support for Vendor Review Board activities
  • Implement and validate AI technical controls and safeguards, including data loss prevention, AI connector and agent governance, and acceptable use enforcement, in support of A-LIGN's AI Management System
  • Report compliance posture, evidence status, and audit readiness metrics to the CISO and GRC leadership
Minimum Qualifications 

EDUCATION 

  • Bachelor's degree in information systems, cybersecurity, business, or equivalent combination of education and experience

EXPERIENCE 

  • 5+ years of experience in information security, GRC, IT audit, or compliance engineering roles
  • Hands-on experience with audit evidence collection and technical control validation for at least two of the following: FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171
  • DevSecOps or cloud engineering experience sufficient to independently locate and extract evidence from GCP, GitHub, and Microsoft 365/Entra ID environments
  • Experience with GRC platforms and evidence automation (AuditBoard, Vanta, Drata, or similar)
  • Experience supporting external audits and assessor interactions, including 3PAO assessments
  • Working knowledge of vulnerability management, CI/CD pipelines, infrastructure-as-code, and identity and access management concepts
  • Experience scripting or automating evidence collection (Python, PowerShell, or similar) preferred
  • Familiarity with risk assessment methodologies, threat modeling (e.g., STRIDE), and security review processes preferred

CERTIFICATIONS  

  • CISA, CISSP, CCSK/CCSP, ISO Lead Auditor/Implementer, or relevant certifications preferred but not required

SKILLS 

  • Strong cross-functional collaboration and project management skills
  • Ability to translate framework requirements into clear, actionable requests for technical teams
  • Highly organized with the ability to manage evidence deadlines across multiple concurrent audit cycles
  • Excellent written communication for control narratives, evidence descriptions, and assessor responses
  • Self-directed with strong follow-through in a fast-paced, deadline-driven environment
  • Proven experience utilizing AI tools to automate manual tasks, streamline workflows, and increase team efficiency
  • Experience operating in PE-backed or high-growth environments preferred
Benefits 
  • Healthcare, Dental, and Vision Benefits
  • Employer Paid Life Insurance and Disability Insurance
  • EAP - Employee Assistance Program
  • Pet Insurance
  • 401(k) Plan with Employer Matching
  • Competitive Bonus Structure
  • Home Office Reimbursement
  • Certification Reimbursement
  • Personalized Career Coaching
  • Generous Paid Time Off
  • Paid Office Closure December 25-January 1
  • Vacation Bonus
  • Summer Hours
About A-LIGN 

A-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor. To learn more, visit a-lign.com. 

Come Work for A-LIGN! 

Apply online today at A-LIGN.com and learn about life at A-LIGN by following us on LinkedIn.  

A-LIGN is an Equal Opportunity Employer. Minorities, women, disabled, and veterans encouraged to apply! 

Similar Jobs

7 Days Ago
In-Office or Remote
CA, USA
185K-327K Annually
Senior level
185K-327K Annually
Senior level
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
Build and operate GRC data pipelines, integrations, policy-as-code, continuous control monitoring, evidence automation, and agentic AI workflows. Normalize security data from diverse systems, create auditable evaluation harnesses, govern AI systems, and define technical direction across teams. Partner with security governance, compliance, and engineering groups to transform manual governance processes into scalable products.
Top Skills: AWSBuildkiteCi/CdClaudeGCPGoGrpcHTTPJavaJSONKotlinKubernetesLlm ApisModel Context ProtocolProtocol BuffersPythonSnowflakeSQLTerraform
2 Hours Ago
Remote
United States
150K-170K Annually
Senior level
150K-170K Annually
Senior level
Artificial Intelligence • Beauty • Fitness • Software
Own Playlist's technical GRC architecture across multiple compliance frameworks. Build and maintain a unified Master Control List, framework crosswalks, evidence workflows, and control lifecycle processes. Automate compliance evidence collection and develop AI-powered GRC tools for risk quantification, vendor assessments, and monitoring. Partner with engineering, legal, finance, auditors, and product teams to translate requirements into actionable controls and harmonize compliance across multiple brands and acquisitions.
Top Skills: Amazon AuroraAmazon EventbridgeAmazon RdsAmazon S3AnecdotesAPIsAws LambdaAws Step FunctionsDrataHitrustHyperproofIso 27001LlmsMulti-Agent SystemsNist 800-53Nist CsfOptroOscalPci DssRag ArchitecturesSoc 1 Type IiVanta
27 Days Ago
Remote
United States
Senior level
Senior level
Artificial Intelligence • Information Technology • Software
Lead federal compliance engagements for clients pursuing FedRAMP and NIST certifications. Own strategic advisory, gap assessments, FedRAMP 20x readiness, OSCAL/JSON/YAML machine-readable artifacts, CCM continuous monitoring integrations, and third-party assessment orchestration while mentoring a small compliance team and maintaining executive client relationships.
Top Skills: AWSAws GovcloudAzureAzure GovernmentCmmcCspmFedramp 20XGCPGdprGrc PlatformsInfrastructure As Code (Iac)Iso 27001JSONNist Sp 800-171Nist Sp 800-53Opa/RegoOscalPythonRmfSoc 2Yaml

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account