32 grc engineer jobs at 26 companies in American Canyon, CA

3mo
Save
Mark Applied
Hide
GRC Engineer
Palo Alto or San Francisco
$130k-$170k/yr OnsiteAll Commitments Available
Zania
Zania: Agentic AI software helping enterprise security, risk, and compliance teams automate GRC workflows.
3+ YOE3–8 years in GRC, information security, risk management, audit, or enterprise tech customer success; strong frameworks knowledge (SOC 2, ISO 27001, NIST CSF, FedRAMP, HIPAA, PCI-DSS); proven stakeholder management and communication; SaaS/technical product experience.
GRC frameworks, SOC 2, ISO 27001, NIST CSF, FedRAMP, HIPAA, PCI-DSS
3mo
Save
Mark Applied
Hide
GRC Engineer
Foster City, California, United States
$210k-$320k/yr HybridFull Time
SolutionBox Insight
SolutionBox Insight: Agentic software creation platform that lets anyone build applications using natural language.
8+ YOE8+ years in GRC or information security; deep cloud (GCP/AWS) and security architecture; strong regulatory experience; automation mindset with GRC tools.
GCP, AWS, Vanta, Drata, SOC 2, ISO 27001, PCI, HIPAA
14h
Save
Mark Applied
Hide
Lead GRC Engineer
San Francisco or California or United States
$220k-$280k/yr HybridFull Time
Higgsfield AI
Higgsfield AI: AI-native video and image creation platform for creators, marketers, brands, agencies, and studios.
6+ YOERequires 6+ years across security, GRC, software or automation engineering; experience automating technical controls, Python scripting, APIs, integrations, SOC 2, ISO 27001, and continuous monitoring.
Python, APIs, SOC 2, ISO 27001, cloud infrastructure, IdP, HRIS, source control, CI/CD, SaaS
3w
Save
Mark Applied
Hide
GRC Controls Automation Engineer
Austin or Chicago or New York City or Redwood City or San Francisco or United States
$130k-$145k/yr HybridFull Time
Box
BoxNYSE: BOX: Intelligent content management and collaboration platform.
5+ YOE5+ years in SaaS GRC or information security; GCP, AI architectures, data governance, model validation, NIST, PCI, ISO, SOC 2, communication, and process improvement experience.
GCP, AI, NIST 800-53, PCI, ISO 27x, AICPA SOC, SOC 2
5d
Save
Mark Applied
Hide
GRC Engineer
San Mateo, California, United States
$200k-$250k/yr OnsiteFull Time
Verkada
Verkada: Physical security platform for enterprise buildings and facilities.
7+ YOERequires 7+ years in security or IT compliance, cloud service experience, software compliance experience, and SOC 2 or ISO 27001 audit, risk, and compliance experience.
AWS, GitHub, Python, JSON
1mo
Save
Mark Applied
Hide
Security Engineer, GRC
San Francisco or Seattle or New York City
$156k-$214k/yr HybridFull Time
Plaid
Plaid: Fintech data network connecting consumers’ financial accounts to apps and services.
Strong Python and SQL, AWS and cloud security experience, Terraform and policy-as-code (OPA/Rego, Sentinel), CI/CD integration, continuous controls monitoring, GRC framework knowledge, and AI tooling experience.
Python, SQL, AWS, GitHub, Terraform, OPA/Rego, Sentinel, Mode, Claude, OpenAI, Anecdotes, Drata, Vanta, Paramify
1mo
Save
Mark Applied
Hide
Senior Security GRC Analyst
San Mateo, California, United States
$224k-$272k/yr HybridFull Time
Roblox
RobloxNYSE: RBLX: Global platform for user-created immersive digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
1w
Save
Mark Applied
Hide
GRC Pre-Sales Consultant / Solutions Engineer – EMEA
Dublin or London or San Francisco or New York City or Tel Aviv or Sydney
HybridFull Time
Vanta
Vanta: Private software that helps businesses automate compliance, manage risk, and prove security trust.
5+ YOERequires 5+ years of customer-facing technical experience, B2B SaaS experience, cloud platform and architecture expertise, scripting knowledge, project management skills, and preferably cybersecurity, GRC, or audit experience.
AWS, Google Cloud, Microsoft Azure, Windows, macOS, Linux, Python, Ruby, Bash, JavaScript, REST API, SOC 2, ISO 27001, HIPAA
3d
Save
Mark Applied
Hide
Security Engineer, GRC
San Francisco or Denver or New York City
HybridFull Time
Candid Health
Candid Health: Private revenue cycle management software automating billing for healthcare providers.
3+ YOERequires 3+ years in technical security, Python, TypeScript, SQL, API and database experience, cloud security expertise, and familiarity with Terraform, CI/CD, Git, Docker, or Kubernetes.
Python, TypeScript, SQL, GCP, Terraform, CI/CD, Git, Docker, Kubernetes, Vanta, Drata, Anecdotes
2mo
Save
Mark Applied
Hide
Security and Compliance Engineer
Bangalore or San Francisco
OnsiteFull Time
Hevo Data
Hevo Data: The Only True ELT for AI-ready Data.
5+ YOE5+ years in security or compliance engineering; hands-on SOC 2 Type II audit ownership; cloud security (AWS/GCP/Azure); GRC tooling experience; strong written communication and policy authorship skills.
SOC 2 Type II, ISO 27001, GDPR, CCPA, AWS, GCP, Azure, Sprinto, Tugboat Logic, GRC, CI/CD, infrastructure-as-code, DevSecOps, SDLC, IAM
2mo
Save
Mark Applied
Hide
Staff+ Software Engineer, GRC Platform
San Francisco or New York City or Seattle
$405k/yr HybridFull Time
Anthropic
Anthropic: AI research developing safe and steerable AI systems.
8+ YOE8+ years building backend systems, data pipelines, or internal platforms; proficiency in Python or Go; experience with cloud platforms and infrastructure-as-code; strong systems thinking and experience with integrations or data infrastructure.
Python, Go, AWS, GCP, Azure, Claude, ServiceNow, Vanta, Drata, OneTrust, REST APIs, webhooks, CI/CD, ELT, ETL, infrastructure-as-code, version control
3mo
Save
Mark Applied
Hide
Staff Software Engineer, Core GRC
San Francisco, California, United States
$201k-$272k/yr HybridFull Time
Drata
Drata: Compliance automation platform for businesses that automates compliance, manages risk, and continuously proves trust.
10+ YOE10+ yrs software eng; 3+ yrs Node.js or React; 1+ yr NestJS; CS degree or equivalent; OAuth/SCIM/OIDC/RBAC experience; cloud platforms; REST, TS/JS; CI/CD; Git.
Node.js, React, NestJS, JavaScript, TypeScript, OAuth, SCIM, OIDC, RBAC, REST, Git, CI/CD, AWS, GCP, Azure, Terraform, Pulumi, TypeORM, Jest, Redis, ElasticSearch
3mo
Save
Mark Applied
Hide
Forward Deployed Security Engineer
Seattle or San Francisco or United States
$125k-$175k/yr RemoteFull Time
Clearly AI
Clearly AI: AI-powered security and privacy review software for enterprise security, privacy, and compliance teams.
2+ YOE2+ years in GRC, privacy, or security engineering; hands-on threat modeling, vendor risk, and security tool integrations; strong project management and customer debugging skills.
Jira, ServiceNow, Confluence, GitHub, Linear
3w
Save
Mark Applied
Hide
GRC Program Manager, Assurance Engineering & Control Systems
San Francisco, California, United States
$216k-$252k/yr HybridFull Time
OpenAI
OpenAI: AI research and deployment focused on beneficial AGI.
Experience owning audits or assurance outcomes, designing controls, testing evidence, and managing remediation; technical fluency in cloud, identity, logging, APIs, data flows, automation, and operational workflows.
Codex, SQL, APIs, SOC 2, ISO 27001, ISO 27017, PCI DSS, NIST, FedRAMP
3w
Save
Mark Applied
Hide
Senior Cloud Security Engineer - InfoSec
San Francisco or New York or Portland or United States or Canada
$167k-$208k/yr RemoteFull Time
Mercury
Mercury: Private fintech providing business banking and financial workflow tools to startups and small businesses.
5+ YOE5+ years cloud security experience; familiarity with security frameworks, GRC, IaC, AWS; strong analytical and problem-solving skills; AWS certifications encouraged.
AWS
2mo
Save
Mark Applied
Hide
Sales Engineer - Mid-West US (OH/MN)
Ohio or Minnesota or San Francisco or Tel Aviv
OnsiteFull Time
BlinkOps
BlinkOps: Cybersecurity software providing an agentic security operations platform for security teams.
3+ YOE3+ years in sales/solutions engineering in cybersecurity, strong security operations knowledge, hands-on with APIs, JSON/YAML and jq, experience with SIEM/SOAR/EDR/IAM/GRC integrations, demo/POC and customer-facing skills.
APIs, JSON, YAML, jq, SIEM, SOAR, EDR, IAM, GRC, AWS, Azure, GCP, MEDDPICC, Value Selling
2w
Save
Mark Applied
Hide
Security Engineer
Guadalajara or San Francisco
OnsiteFull Time
Bright Machines
Bright Machines: Private software and robotics manufacturer building AI and data-center infrastructure for hyperscalers.
5+ YOERequires 5+ years in security engineering or related work, ISO 27001 ISMS experience, application security tooling, scripting, infrastructure-as-code, cloud security, GRC, and strong English communication.
ISO 27001:2022, SIG, CAIQ, SAST, DAST, SCA, Snyk, Semgrep, Checkmarx, Burp Suite, Python, Terraform, Ansible, AWS, Azure, GCP, IAM, EDR, SOC, IDS/IPS, MFA, SSO, SOC 2 Type II
2mo
Save
Mark Applied
Hide
Security Engineer
San Mateo, California, United States
$160k-$210k/yr HybridFull Time
Skydio
Skydio: American autonomous-drone manufacturer serving public safety, government, utility, and enterprise customers.
3+ YOE3+ years engineering experience; strong coding in Python or Go; experience automating workflows and integrating systems via APIs; working knowledge of cloud (ideally AWS); participation in on-call rotation; eligibility to access export-controlled technical data.
Python, Go, AWS, Kubernetes, SCIM, SIEM, IAM/IdP, EDR, GRC, APIs, FedRAMP, SOC 2, ISO 27001, Texas RAMP, CJIS
1d
Save
Mark Applied
Hide
Sr. Security Assurance Engineer
United States or San Francisco
$141k-$180k/yr RemoteFull Time
6sense
6sense: Private B2B revenue-intelligence and account-based marketing software serving sales and marketing teams.
5+ YOERequires 5+ years in GRC or similar, 2+ years building automation, Python and AWS experience, APIs and SQL, AI workflow experience, security frameworks, and ability to defend automated evidence to auditors.
Python, Git, CI/CD, AWS Config, AWS Security Hub, AWS CloudTrail, AWS Organizations, AWS SCPs, AWS IAM Access Analyzer, AWS Systems Manager, AWS EventBridge, AWS Lambda, AWS Athena, AWS S3, AWS CloudWatch, SQL, Terraform, CloudFormation, OPA/Rego, cfn-guard, KPMG, Deloitte, PwC, EY, LinkedIn Learning
2mo
Save
Mark Applied
Hide
Member of Technical Staff, DevSecOps
San Francisco or Europe or Australia
$180k-$280k/yr HybridFull Time
Vapi
Vapi: Private voice AI platform that lets developers and enterprises build, deploy, and manage conversational voice agents.
5+ YOE5+ years engineering experience in cloud-native SaaS; strong security experience for multi-tenant cloud environments; proficiency with AWS, Kubernetes, and Postgres; ability to write/review code and implement shift-left security.
AWS, Kubernetes, Postgres, VoIP, CI/CD, Drata, SOC 2, ISO 27001, HIPAA, GRC