Security Grc Specialist

Modal Modal · Data AI · New York, NY · Engineering

Modal is seeking a Security GRC Specialist to own and scale its security and compliance programs. This role will work closely with engineering and product teams to build customer trust, enable sales, and meet regulatory expectations. Responsibilities include managing compliance frameworks (SOC 2, ISO 27001, GDPR), driving audits, responding to customer security questionnaires, and collaborating with engineering to implement security controls. The ideal candidate has 3-7+ years of experience in security GRC, a technical mindset, and strong execution skills.

What you'd actually do

  1. Own and operate compliance frameworks (e.g., SOC 2, ISO 27001, GDPR, etc.)
  2. Drive audits end-to-end: readiness, evidence collection, auditor coordination
  3. Lead responses to customer security questionnaires, RFPs, and due diligence requests
  4. Work directly with engineering teams to design and implement practical security controls
  5. Run risk assessments across systems, vendors, and processes

Skills

Required

  • 3–7+ years in security GRC, compliance, or security engineering-adjacent roles
  • Hands-on experience with frameworks like SOC 2, ISO 27001, or similar
  • Experience supporting audits and customer-facing security conversations
  • Comfortable working with engineers and understanding systems (cloud, infra, APIs, etc.)
  • Ability to translate between compliance language and technical implementation
  • Proactive and hands-on—you drive changes, not just track them
  • Able to balance rigor with pragmatism in a fast-moving environment
  • Strong communication skills, especially with customers and cross-functional teams

Nice to have

  • Experience with modern cloud environments (AWS/GCP/Azure)
  • Experience building or scaling a GRC program from early stages
  • Familiarity with automation in compliance workflows
  • Background in security engineering or DevOps

What the JD emphasized

  • Hands-on experience with frameworks like SOC 2, ISO 27001, or similar
  • Comfortable working with engineers and understanding systems (cloud, infra, APIs, etc.)
  • Proactive and hands-on—you drive changes, not just track them