Sr. GRC Engineer
Pendo · Raleigh, NC
About this role
**Sr. GRC Engineer** ## The Team + The Role Pendo’s Information Security team protects the data entrusted to Pendo and helps ensure our products are built with security and privacy by design. The team spans Security Operations, Product Security, and Compliance and Risk. The Sr. GRC Engineer is an AI-first technical leader who helps drive the evolution of Pendo’s governance, risk, and compliance program. This role independently leads complex compliance, risk, and incident-response work while identifying program maturity gaps, translating security risk into business terms, and contributing to security roadmap and investment decisions. Success means building durable controls and programs that reduce risk and operational friction—not simply completing audits. *Based in our Raleigh office.* ## What this looks like day-to-day - **AI-driven compliance and operations acceleration:** Use AI to accelerate audit evidence preparation, policy documentation, control testing workflows, and regulatory research. Evaluate GRC platform automation capabilities and integrate AI tooling where it reduces manual overhead, then document and share effective approaches with the team. - **Security program strategy and roadmap:** Identify maturity gaps across compliance and security operations and translate them into prioritized roadmap recommendations grounded in business risk. Contribute to security investment discussions, clarify tradeoffs between coverage, cost, and risk, and anticipate emerging regulatory requirements before they become audit findings. - **Compliance program ownership:** Own one or more regulatory compliance programs end-to-end, including **SOC 2 Type II, ISO 27001/42001, PCI-DSS, GovRAMP, or FedRAMP**. Lead control design, evidence collection, auditor relationships, and remediation tracking to maintain effective and durable compliance programs. - **Risk assessment and prioritization:** Conduct organizational risk assessments and present findings to leadership with clear prioritization and investment-level recommendations. Translate technical exposure into business-risk language that enables leaders to make informed decisions. - **Incident response leadership:** Lead incident response for complex, multi-system security events from investigation through resolution. Conduct root cause analysis, run post-incident reviews, and own resulting actions that turn incident findings into measurable program improvements. - **Cross-functional partnership:** Work directly with engineering, product, and IT teams to deliver compliance requirements, validate implementations, and embed security into day-to-day operations. Translate compliance obligations into actionable technical requirements and influence how partner teams approach security. ## Who You Are - **A builder, not a maintainer**—you identify gaps, shape solutions, and drive them forward. - **AI-curious (genuinely):** You’re not using AI occasionally—you’re rewiring how you work around it. You see AI as a multiplier, not a shortcut. ## Must-haves - **3–5 years** of hands-on security experience with demonstrated ownership of compliance programs or security operations work (not just participation). - Deep working knowledge of **at least two**: SOC 2, ISO 27001, PCI-DSS, FedRAMP, GovRAMP, or the NIST 800-series. - Demonstrated ability to **independently own auditor relationships** and manage an audit cycle end-to-end, including responding directly to auditor questions. - Experience leading incide
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.