Grc Controls Automation Engineer

Box Box · Enterprise · Redwood City, CA · Compliance & Risk

This role focuses on automating GRC (Governance, Risk, and Compliance) controls within the software development lifecycle (SDLC) at an AI-first SaaS company. The engineer will design, implement, and scale frameworks that embed compliance into development processes, working with various regulatory standards and cloud security. While the company is AI-first and mentions AI architectures and model validations, the core function of this role is compliance automation, not direct AI/ML model development.

What you'd actually do

  1. Drive improvements in existing processes, process standardization and develop new innovative and efficient solutions
  2. Design, develop, and implement controls with a focus on compliance and automation
  3. Provide compliance guidance on new product features, deviations, and changes in the infrastructure
  4. Participate in cloud and application security strategic planning and execution
  5. Implement improvements by assessing the current environment, evaluate trends, and anticipating future enhancements/requirements

Skills

Required

  • 5+ years of professional experience working in a SaaS company in GRC, Information Security or similar function
  • Familiar with GCP cloud computing, AI architectures, Data governance and model validations
  • Deep understanding of global frameworks, such as NIST 800-53, PCI, ISO 27x, and SOC 2
  • BS degree in Business or Management Information Systems or related field OR equivalent work experience
  • Excellent written, verbal communication and presentation skills
  • Organizational skills
  • Ability to hustle, get stuff done, and has strong integrity

Nice to have

  • CISSP, CCSK, CISM or other related certifications

What the JD emphasized

  • regulatory standards
  • compliance requirements
  • technical infrastructure
  • engineering workflows
  • compliance
  • automation
  • software development (SDLC)
  • scalable, efficient program and process
  • automation
  • compliance guidance
  • cloud and application security
  • security and compliance posture
  • production environment
  • frameworks and regulatory standards
  • ISO
  • PCI
  • NIST
  • AICPA SOC
  • process documentation
  • compliance issues