Grc Engineer

Verkada Verkada · Enterprise · Bayoffice · Security

Verkada is seeking a GRC Engineer to build and lead the GRCA function within their Security Team. This role involves managing risks, scaling compliance needs, and curating information about Verkada's security practices. The engineer will build scalable, automated programs to support business growth while maintaining customer trust, focusing on sophisticated security and compliance expectations for global enterprise customers. Responsibilities include providing guidance on security controls, building and maintaining tooling for testing and monitoring, managing compliance roadmaps, developing policies, creating documentation, performing risk assessments, conducting vendor assessments, managing exceptions, and collaborating with auditors. The role emphasizes leveraging AI and automation to scale GRCA functions.

What you'd actually do

  1. Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on security controls implementation including: effectiveness, implementation and automation
  2. Research, build and maintain tooling for testing and continuous monitoring of security controls across multiple platforms including: AWS, Github, etc.
  3. Maintain the roadmap for continuous security compliance across Verkada’s Corporate, IT and Product environments with a goal of increasing automation coverage
  4. Assist in the development and maintenance of company-wide security policies, procedures, and plans, and support communication to internal stakeholders regarding security and compliance best practices around applicable laws, regulations, and controls
  5. Leverage AI and automation to scale the GRCA functions

Skills

Required

  • Experience with AWS or another cloud service provider
  • Prior experience with software companies’ compliance
  • Experience with audits, risk and compliance (SOC 2, ISO27001, etc.) for cloud software products.
  • 7+ years of security/IT compliance or equivalent experience
  • Outstanding written and spoken communication skills
  • Ability to effectively and autonomously accomplish outcomes across cross-functional teams in ambiguous situations
  • Ability to multitask, prioritize work and meet deadlines in a fast paced environment

Nice to have

  • Experience with scripting languages such as: Python, JSON etc
  • Prior experience automating audit evidence collection

What the JD emphasized

  • security controls implementation
  • testing and continuous monitoring
  • continuous security compliance
  • security policies, procedures, and plans
  • security and compliance best practices
  • security compliance issues
  • security risk assessments
  • vendor security assessments
  • security Exception Process
  • customer questionnaires
  • auditors
  • continuous compliance
  • Experience with audits, risk and compliance (SOC 2, ISO27001, etc.) for cloud software products.
  • 7+ years of security/IT compliance or equivalent experience