CronJobs

security jobs

GRC Engineer

Butterflymx · US Remote

remotemid$130,000–$170,000Posted Aug 5, 2026SOC 2VantaNIST CSFNIST AI RMFISO 27001ISO 42001ISO 27701OWASP Top 10

Apply on the employer site

About this role

## ButterflyMX — GRC Engineer ### Mission ButterflyMX empowers people to automate property access, operations, and security from a single platform—supporting developers, owners, property managers, and residents worldwide. ### Role Overview ButterflyMX is seeking a **GRC Engineer** to own and continuously mature the **governance, risk, and compliance (GRC)** program. You’ll re-engineer how GRC operates by replacing manual, point-in-time processes with **AI-assisted, automated, and agentic workflows**—at scale. This is an **individual contributor** role reporting directly to the **CISO**. ### Responsibilities - Own and continuously mature the **company risk register** using AI tooling to surface, score, and route emerging risks with minimal manual intervention. - Lead **external audit management (SOC 2 Type II)**; automate evidence collection pipelines in **Vanta** for continuous monitoring (not evidence sprints). Begin scoping a readiness path for **ISO 42001**. - Engineer **Trust & Assurance** at scale: automate intake/triage for security questionnaires, use AI-assisted responses against a curated knowledge base, and expand a trust portal for largely self-service partner due diligence. - Build a **vendor and supply chain risk** program beyond spreadsheets: automated vendor intake, tiered risk scoring, and continuous monitoring triggers (news alerts, rating integrations, release notes, expiration tracking). - Redesign and maintain **security and privacy policies**: use AI to draft/version/track updates and implement a lightweight owner review/approval/attestation workflow. - Own **common controls monitoring in Vanta**: configure/tune integrations, checks, and alerting so control failures reach the right owners automatically. - Modernize the **security awareness and training** program. - Design and operationalize an integrated **compliance calendar** (SOC 2, licensing renewals, applicable state privacy regulations, and other active frameworks) with automated reminders and status tracking. - Support the **CISO and General Counsel** on operational privacy practices: cookie consent tooling, documented/auditable workflow for **data subject requests (DSRs)**, and privacy notice/data mapping inventory. - Monitor the regulatory/compliance landscape (including **AI governance** such as EU AI Act, NIST AI RMF, ISO 42001) and proactively surface changes requiring policy/control/product response. - Leverage AI across every GRC workflow and demonstrate measurable efficiency gains through automation. ### Requirements - **3+ years** experience in GRC, information security compliance, or risk management. - Working knowledge of **SOC 2 (Trust Services Criteria)** with hands-on audit support/leadership experience. - Familiarity with additional frameworks (strong plus), including: - CIS Controls v8, NIST CSF, **NIST AI RMF**, NIST Privacy Framework, NIST SP 1800 series, NIST 800-53 r5 - **ISO 42001**, ISO 27701, ISO 27001 - OWASP Top 10 for Agentic Applications, MITRE D3FEND / SoT / ALTAS - Experience conducting rapid third-party/vendor risk assessments and managing supply chain risk. - Strong organizational skills; ability to manage multiple concurrent workstreams. - Excellent written communication (policy documents + executive risk summaries). - Experience with **Vanta** (or equivalent). - Relevant certifications a plus: **CISA, CRISC, CISSP, CIPP** (or equivalent). - Proven ability to leverage AI tools effectively. ### Compensation - Expecte

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord