Commercial GRC Engineer - Sr. Security Engineer I
Smartsheet · Bellevue, WA, USA
About this role
**About the Role** Smartsheet is looking for a **Sr. Security Engineer I** to bring an engineering mindset to our **commercial GRC (Governance, Risk, and Compliance) program**. You’ll help automate control monitoring, build evidence pipelines, and improve continuous readiness—so audit season doesn’t become a scramble. You’ll work hands-on with our **GRC platform, cloud, and identity tooling**, partnering with engineering teams to translate compliance requirements into technical control logic they can build and maintain. **Location**: Bellevue, WA (office) or **remote anywhere in the US** where Smartsheet is a registered employer. --- **You Will** - **Own control automation** for **SOC 2, ISO 27001/27017/27701, HIPAA**, and related frameworks—design and build automated evidence collection and continuous control monitoring across **cloud, identity, endpoint, and SaaS**. - Express **controls, control tests, and cross-framework mappings** as **version-controlled code** (reviewable, testable, reusable). - Translate compliance requirements into **technical control logic, workflows, and integrations**, embedding controls into existing systems and pipelines. - **Shift compliance left**: participate in architecture/design reviews, define control requirements as acceptance criteria, and help teams build compliant-by-default infrastructure. - Design the **engineer-facing compliance experience** (self-service control status, guardrails/paved-road patterns, and feedback in tools like **CI/CD, Jira, Slack**). - Evaluate whether controls **reduce relevant risk** (not just whether they exist) and propose alternatives when needed. - Support **full audit cycles end-to-end**: coordinate evidence requests, maintain the evidence library, respond to auditor follow-ups, and track remediation through closure. - Build and maintain **dashboards and reporting** for real-time visibility into control health, evidence freshness, and audit readiness. - Eliminate **duplicate evidence gathering** by mapping controls once and reusing mappings across SOC 2, ISO, and HIPAA. - Diagnose root causes of recurring control failures or stale evidence and fix underlying process/tooling/ownership gaps. - Partner with the **GRC Team Lead** and satellite engineering to extend the internal GRC platform’s control, evidence, and risk-lifecycle capabilities. --- **You Have** - **4+ years** experience in **GRC engineering, security engineering, compliance automation, or IT audit support**, including hands-on ownership of at least one full certification cycle (SOC 2, ISO 27001, or similar). - Practical experience with **GRC/compliance automation platforms** (e.g., **Vanta, Drata, Secureframe**, or equivalent), including configuring integrations and building evidence pipelines. - Cloud security fundamentals (e.g., **AWS/GCP/Azure IAM, logging, encryption**) and how they map to control requirements. - Working knowledge of **SOC 2, ISO 27001** (ideally 27017/27701) and **HIPAA**, including mapping controls across frameworks. - Comfort with **scripting/light development** (e.g., **Python, JavaScript**) to build integrations and automate evidence pulls via API. - Strong written communication—able to document controls, gaps, and remediation clearly for both auditors and engineers. - A stakeholder-centric mindset focused on making compliance easy for engineers. - Ability to trace control failures/audit findings to root causes and drive durable fixes across teams. - Legally eligible to work
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.