GRC Engineer
Glow · United States
About this role
## About Glow Glow is transforming how enterprises proactively protect the modern endpoint with an agentic-first approach. Our platform gives security teams the visibility, context, and autonomous remediation they need across every endpoint, application, and AI tool in the environment. ## About the Role (GRC Engineer) We’re looking for a pragmatic, technically curious **GRC Engineer** to help customers trust Glow and our products. You’ll own customer-facing security assurance work (questionnaires, diligence requests, and customer calls) and manage/automate our compliance programs—improving how we collect evidence, monitor controls, and partner with Product and Engineering to design effective controls as the product evolves. ## What You’ll Do - Own and complete **customer security questionnaires, assessments, and due-diligence requests** accurately and efficiently. - Join customer/prospect calls to explain our **security posture, controls, architecture, and risk-management practices**. - Build and maintain reusable **trust materials** (standard responses, evidence packages, security documentation, trust-center content). - Manage compliance programs and audits such as **SOC 2** and **ISO 27001** (readiness → evidence collection/testing → remediation → ongoing monitoring). - **Automate evidence collection**, control monitoring, questionnaire responses, and other repetitive GRC workflows. - Automate and own processes for **policies, risk registers, control mappings, vendor reviews, and remediation plans**. - Partner with **Product, Engineering, IT, Legal, Sales, and Customer Success** to address security and compliance requirements. - Help translate **regulatory, contractual, and customer requirements** into practical product and operational controls. - Participate in product design/roadmap discussions to identify control requirements early and recommend secure, scalable, usable solutions. - Track emerging customer expectations and compliance requirements, then help prioritize improvements to the security program. - Define **metrics** for the effectiveness, efficiency, and business impact of the GRC and customer-trust program. ## What You’ll Bring - Experience in **GRC, security assurance, customer trust, compliance, security engineering**, or a related field. - Enjoy building from the ground up. - Hands-on experience completing customer security questionnaires and supporting security reviews. - Strong written and verbal communication skills—able to explain technical and compliance topics to technical and non-technical audiences. - Experience with frameworks such as **SOC 2, ISO 27001, NIST CSF, NIST 800-53**, or similar standards. - Working knowledge of common SaaS/cloud security controls (IAM, encryption, logging, vulnerability management, secure development, incident response, business continuity, vendor risk). - Ability to evaluate evidence critically (not just treat compliance as a checklist). - Strong project management skills and comfort coordinating across teams. - Automation mindset—interest in using **APIs, scripts, integrations, AI, or GRC platforms** to reduce manual work. - Curiosity about product design and desire to help teams build controls into systems from the beginning. - Sound judgment balancing security, customer commitments, usability, and business needs. ## You Might Also Bring (Nice to Have) - Experience at startups / B2B SaaS / cloud / fintech / healthcare, or other security-conscious tech companies. - Familiari
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.