Staff Grc Engineer

Crusoe · Data AI · San Francisco, CA - US · IT, Compliance, and Security

This role focuses on building automation and tooling for a Governance, Risk, and Compliance (GRC) program within an AI infrastructure company. The engineer will replace manual compliance workflows with code-driven systems, integrate GRC platforms, build dashboards, and embed compliance checks into engineering pipelines. A key aspect involves applying AI and LLM tools to streamline GRC processes. While not a core AI development role, it utilizes AI tools to enhance operational processes and is within an AI-focused company.

What you'd actually do

  1. Designing and maintaining automation workflows that replace manual compliance processes (evidence collection, control testing, policy monitoring, audit reporting)
  2. Writing production-grade scripts, services, and integrations (Python, JavaScript, YAML, etc.) that connect GRC platforms to internal systems and CI/CD pipelines
  3. Implementing and customizing GRC platforms (e.g., Vanta, AuditBoard, Drata) through APIs, configuration, and custom automation
  4. Building dashboards and reporting systems that provide real-time visibility into control health and risk posture
  5. Embedding compliance checks into engineering workflows so evidence collection and monitoring happen continuously

Skills

Required

  • automation
  • scripting
  • systems integration
  • Python
  • JavaScript
  • API integration
  • GRC platforms
  • cloud environments
  • compliance and risk frameworks
  • AI tools

Nice to have

  • Terraform
  • Ansible
  • Jenkins
  • GCP
  • AWS
  • Azure
  • CISSP
  • CISA
  • CRISC
  • DevSecOps practices
  • quantitative risk frameworks
  • continuous monitoring
  • continuous compliance systems

What the JD emphasized

  • production-grade scripts
  • production
  • API integration experience
  • compliance and risk frameworks (SOC 2, ISO 27001, NIST, HIPAA, GDPR)
  • AI tools to automate workflows