GRC Engineer
Butterflymx · US Remote
About this role
## ButterflyMX — GRC Engineer ### Mission ButterflyMX empowers people to automate property access, operations, and security from a single platform—supporting developers, owners, property managers, and residents worldwide. ### Role Overview ButterflyMX is seeking a **GRC Engineer** to own and continuously mature the **governance, risk, and compliance (GRC)** program. You’ll re-engineer how GRC operates by replacing manual, point-in-time processes with **AI-assisted, automated, and agentic workflows**—at scale. This is an **individual contributor** role reporting directly to the **CISO**. ### Responsibilities - Own and continuously mature the **company risk register** using AI tooling to surface, score, and route emerging risks with minimal manual intervention. - Lead **external audit management (SOC 2 Type II)**; automate evidence collection pipelines in **Vanta** for continuous monitoring (not evidence sprints). Begin scoping a readiness path for **ISO 42001**. - Engineer **Trust & Assurance** at scale: automate intake/triage for security questionnaires, use AI-assisted responses against a curated knowledge base, and expand a trust portal for largely self-service partner due diligence. - Build a **vendor and supply chain risk** program beyond spreadsheets: automated vendor intake, tiered risk scoring, and continuous monitoring triggers (news alerts, rating integrations, release notes, expiration tracking). - Redesign and maintain **security and privacy policies**: use AI to draft/version/track updates and implement a lightweight owner review/approval/attestation workflow. - Own **common controls monitoring in Vanta**: configure/tune integrations, checks, and alerting so control failures reach the right owners automatically. - Modernize the **security awareness and training** program. - Design and operationalize an integrated **compliance calendar** (SOC 2, licensing renewals, applicable state privacy regulations, and other active frameworks) with automated reminders and status tracking. - Support the **CISO and General Counsel** on operational privacy practices: cookie consent tooling, documented/auditable workflow for **data subject requests (DSRs)**, and privacy notice/data mapping inventory. - Monitor the regulatory/compliance landscape (including **AI governance** such as EU AI Act, NIST AI RMF, ISO 42001) and proactively surface changes requiring policy/control/product response. - Leverage AI across every GRC workflow and demonstrate measurable efficiency gains through automation. ### Requirements - **3+ years** experience in GRC, information security compliance, or risk management. - Working knowledge of **SOC 2 (Trust Services Criteria)** with hands-on audit support/leadership experience. - Familiarity with additional frameworks (strong plus), including: - CIS Controls v8, NIST CSF, **NIST AI RMF**, NIST Privacy Framework, NIST SP 1800 series, NIST 800-53 r5 - **ISO 42001**, ISO 27701, ISO 27001 - OWASP Top 10 for Agentic Applications, MITRE D3FEND / SoT / ALTAS - Experience conducting rapid third-party/vendor risk assessments and managing supply chain risk. - Strong organizational skills; ability to manage multiple concurrent workstreams. - Excellent written communication (policy documents + executive risk summaries). - Experience with **Vanta** (or equivalent). - Relevant certifications a plus: **CISA, CRISC, CISSP, CIPP** (or equivalent). - Proven ability to leverage AI tools effectively. ### Compensation - Expecte
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.