45 grc engineer jobs at 37 companies in California

3mo
Save
Mark Applied
Hide
GRC Engineer
Palo Alto or San Francisco
$130k-$170k/yr OnsiteAll Commitments Available
Zania
Zania: Agentic AI software helping enterprise security, risk, and compliance teams automate GRC workflows.
3+ YOE3–8 years in GRC, information security, risk management, audit, or enterprise tech customer success; strong frameworks knowledge (SOC 2, ISO 27001, NIST CSF, FedRAMP, HIPAA, PCI-DSS); proven stakeholder management and communication; SaaS/technical product experience.
GRC frameworks, SOC 2, ISO 27001, NIST CSF, FedRAMP, HIPAA, PCI-DSS
3mo
Save
Mark Applied
Hide
GRC Engineer
Foster City, California, United States
$210k-$320k/yr HybridFull Time
SolutionBox Insight
SolutionBox Insight: Agentic software creation platform that lets anyone build applications using natural language.
8+ YOE8+ years in GRC or information security; deep cloud (GCP/AWS) and security architecture; strong regulatory experience; automation mindset with GRC tools.
GCP, AWS, Vanta, Drata, SOC 2, ISO 27001, PCI, HIPAA
2d
Save
Mark Applied
Hide
Lead GRC Engineer
San Francisco or California or United States
$220k-$280k/yr HybridFull Time
Higgsfield AI
Higgsfield AI: AI-native video and image creation platform for creators, marketers, brands, agencies, and studios.
6+ YOERequires 6+ years across security, GRC, software or automation engineering; experience automating technical controls, Python scripting, APIs, integrations, SOC 2, ISO 27001, and continuous monitoring.
Python, APIs, SOC 2, ISO 27001, cloud infrastructure, IdP, HRIS, source control, CI/CD, SaaS
3w
Save
Mark Applied
Hide
GRC Controls Automation Engineer
Austin or Chicago or New York City or Redwood City or San Francisco or United States
$130k-$145k/yr HybridFull Time
Box
BoxNYSE: BOX: Intelligent content management and collaboration platform.
5+ YOE5+ years in SaaS GRC or information security; GCP, AI architectures, data governance, model validation, NIST, PCI, ISO, SOC 2, communication, and process improvement experience.
GCP, AI, NIST 800-53, PCI, ISO 27x, AICPA SOC, SOC 2
1w
Save
Mark Applied
Hide
GRC Engineer
San Mateo, California, United States
$200k-$250k/yr OnsiteFull Time
Verkada
Verkada: Physical security platform for enterprise buildings and facilities.
7+ YOERequires 7+ years in security or IT compliance, cloud service experience, software compliance experience, and SOC 2 or ISO 27001 audit, risk, and compliance experience.
AWS, GitHub, Python, JSON
1w
Save
Mark Applied
Hide
Principal GRC Business Engineer
California, United States
$168k-$271k/yr OnsiteFull Time
Palo Alto Networks
Palo Alto NetworksNASDAQ: PANW: Global cybersecurity platform providing network, cloud, and AI-driven security solutions.
10+ YOERequires 10+ years in information security or IT risk, including 6+ years in GRC, a computer science or cybersecurity-related degree, and active CISSP, CRISC, CISM, or CISA certification.
AWS, Azure, GCP, NIST SP 800-53, NIST CSF, SOC 2 Type II, PCI-DSS, GDPR, NIST AI RMF, ISO 42001
1mo
Save
Mark Applied
Hide
Security Engineer, GRC
San Francisco or Seattle or New York City
$156k-$214k/yr HybridFull Time
Plaid
Plaid: Fintech data network connecting consumers’ financial accounts to apps and services.
Strong Python and SQL, AWS and cloud security experience, Terraform and policy-as-code (OPA/Rego, Sentinel), CI/CD integration, continuous controls monitoring, GRC framework knowledge, and AI tooling experience.
Python, SQL, AWS, GitHub, Terraform, OPA/Rego, Sentinel, Mode, Claude, OpenAI, Anecdotes, Drata, Vanta, Paramify
1mo
Save
Mark Applied
Hide
Senior Security GRC Analyst
San Mateo, California, United States
$224k-$272k/yr HybridFull Time
Roblox
RobloxNYSE: RBLX: Global platform for user-created immersive digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
3mo
Save
Mark Applied
Hide
GRC & Incident Manager
Los Angeles, California, United States
$145k-$163k/yr OnsiteFull Time
Lendistry
Lendistry: Minority-led CDFI fintech lender providing loans and grant programs to underserved small businesses nationwide.
3+ YOE3-5 years in GRC, data privacy, risk management; SOC 2 and GLBA; cloud experience (AWS/Azure); privacy engineering; CIPT/CDPSE required; CIPM/CISSP preferred; B.S. in CS/Info Security or equivalent.
AWS, Azure, SQL, Python, data mapping, PIA, DPIA
4d
Save
Mark Applied
Hide
Lead Security Engineer, GRC
Boston or Costa Mesa or Seattle or Washington
$166k-$253k/yr OnsiteFull Time
Anduril Industries
Anduril Industries: Defense technology developing AI-powered autonomous military systems.
6+ YOE6+ years in security engineering or GRC, programming and automation experience, compliance framework expertise, cloud and SaaS integrations, infrastructure as code, technical leadership, and eligibility for a U.S. Secret clearance.
Go, Python, Rust, Terraform, AWS CDK, Vanta, Drata, Hyperproof, OneTrust, Kubernetes
1w
Save
Mark Applied
Hide
GRC Pre-Sales Consultant / Solutions Engineer – EMEA
Dublin or London or San Francisco or New York City or Tel Aviv or Sydney
HybridFull Time
Vanta
Vanta: Private software that helps businesses automate compliance, manage risk, and prove security trust.
5+ YOERequires 5+ years of customer-facing technical experience, B2B SaaS experience, cloud platform and architecture expertise, scripting knowledge, project management skills, and preferably cybersecurity, GRC, or audit experience.
AWS, Google Cloud, Microsoft Azure, Windows, macOS, Linux, Python, Ruby, Bash, JavaScript, REST API, SOC 2, ISO 27001, HIPAA
1mo
Save
Mark Applied
Hide
Security Engineer - GRC Fintech & Financial Services
New York or Palo Alto or Washington
$152k-$228k/yr OnsiteFull Time
xAI
xAI: Artificial intelligence research and development.
8+ YOE8+ years GRC/security compliance experience in fintech or financial services; hands-on PCI/NYDFS/FFIEC experience; Compliance-as-Code and GRC automation; technical fluency with cloud and security architecture.
Vanta, AWS, GCP, Azure
5d
Save
Mark Applied
Hide
Security Engineer, GRC
San Francisco or Denver or New York City
HybridFull Time
Candid Health
Candid Health: Private revenue cycle management software automating billing for healthcare providers.
3+ YOERequires 3+ years in technical security, Python, TypeScript, SQL, API and database experience, cloud security expertise, and familiarity with Terraform, CI/CD, Git, Docker, or Kubernetes.
Python, TypeScript, SQL, GCP, Terraform, CI/CD, Git, Docker, Kubernetes, Vanta, Drata, Anecdotes
2mo
Save
Mark Applied
Hide
Principal, GRC Automation and Cyber Risk
Seattle or San Jose
$167k-$251k/yr HybridFull Time
F5
F5NASDAQ: FFIV: Delivering and securing applications across any multi-cloud environment.
10+ YOEBachelor's degree required; 10+ years in cybersecurity/GRC with 3–5 years hands-on engineering; Python, API, and systems-integration experience; ServiceNow IRM and Agentic/LLM framework familiarity; professional certs preferred.
Python, pandas, NumPy, FastAPI, Celery, Airflow, LangChain, AutoGen, LangGraph, CrewAI, ServiceNow IRM, RESTful APIs, GraphQL, OpenAPI/Swagger, Kafka, RabbitMQ, MuleSoft, Boomi, Workato, OAuth
2mo
Save
Mark Applied
Hide
AI Security Engineer (GRC)
Long Beach, California, United States
$125k-$216k/yr HybridFull Time
SCAN Group
SCAN Group: Nonprofit healthcare organization providing Medicare Advantage coverage and care services for older adults.
7+ YOE7+ years information security experience (2+ years in AI security), Bachelor's in related field required (Master's preferred). Hands-on experience with AI platforms and vendor risk assessment; knowledge of HIPAA, NIST AI RMF, HITRUST, threat modeling, and AI red-teaming.
Microsoft Copilot Studio, Microsoft Azure AI Foundry, Snowflake Cortex, Claude Code, Anthropic APIs, GitHub Copilot, Cursor, OpenAI API, LangChain, AutoGen, Semantic Kernel, Model Context Protocol (MCP), Claude Code CLI, GitHub Copilot CLI, Microsoft Azure Developer CLI, Microsoft Copilot Enterprise, Microsoft Power Platform, Snowpark, Hugging Face, Azure Model Catalog, Garak, PyRIT, PromptBench, MITRE ATLAS, MITRE ATT&CK, SIEM, SOAR, OAuth 2.0, mTLS, OIDC, SAML, HITRUST CSF, NIST AI RMF, OWASP Top 10 for LLM Applications, STRIDE, PASTA, retrieval-augmented generation (RAG)
2mo
Save
Mark Applied
Hide
Security and Compliance Engineer
Bangalore or San Francisco
OnsiteFull Time
Hevo Data
Hevo Data: The Only True ELT for AI-ready Data.
5+ YOE5+ years in security or compliance engineering; hands-on SOC 2 Type II audit ownership; cloud security (AWS/GCP/Azure); GRC tooling experience; strong written communication and policy authorship skills.
SOC 2 Type II, ISO 27001, GDPR, CCPA, AWS, GCP, Azure, Sprinto, Tugboat Logic, GRC, CI/CD, infrastructure-as-code, DevSecOps, SDLC, IAM
2mo
Save
Mark Applied
Hide
Staff+ Software Engineer, GRC Platform
San Francisco or New York City or Seattle
$405k/yr HybridFull Time
Anthropic
Anthropic: AI research developing safe and steerable AI systems.
8+ YOE8+ years building backend systems, data pipelines, or internal platforms; proficiency in Python or Go; experience with cloud platforms and infrastructure-as-code; strong systems thinking and experience with integrations or data infrastructure.
Python, Go, AWS, GCP, Azure, Claude, ServiceNow, Vanta, Drata, OneTrust, REST APIs, webhooks, CI/CD, ELT, ETL, infrastructure-as-code, version control
3mo
Save
Mark Applied
Hide
Staff Software Engineer, Core GRC
San Francisco, California, United States
$201k-$272k/yr HybridFull Time
Drata
Drata: Compliance automation platform for businesses that automates compliance, manages risk, and continuously proves trust.
10+ YOE10+ yrs software eng; 3+ yrs Node.js or React; 1+ yr NestJS; CS degree or equivalent; OAuth/SCIM/OIDC/RBAC experience; cloud platforms; REST, TS/JS; CI/CD; Git.
Node.js, React, NestJS, JavaScript, TypeScript, OAuth, SCIM, OIDC, RBAC, REST, Git, CI/CD, AWS, GCP, Azure, Terraform, Pulumi, TypeORM, Jest, Redis, ElasticSearch
3mo
Save
Mark Applied
Hide
Forward Deployed Security Engineer
Seattle or San Francisco or United States
$125k-$175k/yr RemoteFull Time
Clearly AI
Clearly AI: AI-powered security and privacy review software for enterprise security, privacy, and compliance teams.
2+ YOE2+ years in GRC, privacy, or security engineering; hands-on threat modeling, vendor risk, and security tool integrations; strong project management and customer debugging skills.
Jira, ServiceNow, Confluence, GitHub, Linear
3w
Save
Mark Applied
Hide
GRC Program Manager, Assurance Engineering & Control Systems
San Francisco, California, United States
$216k-$252k/yr HybridFull Time
OpenAI
OpenAI: AI research and deployment focused on beneficial AGI.
Experience owning audits or assurance outcomes, designing controls, testing evidence, and managing remediation; technical fluency in cloud, identity, logging, APIs, data flows, automation, and operational workflows.
Codex, SQL, APIs, SOC 2, ISO 27001, ISO 27017, PCI DSS, NIST, FedRAMP