hirq
← All jobs

jobgether

Commercial GRC Engineer - Sr. Security Engineer

US · Remote · Full-time · IT

Apply well, not just fast

Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.

About the role

SOC 2ISO 27001ComplianceHIPAA
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Commercial GRC Engineer - Sr. Security Engineer based in United States. This role brings an engineering mindset to commercial Governance, Risk, and Compliance, transforming compliance from a manual process into an automated, continuously monitored capability. You will build control automation, evidence pipelines, and technical integrations across cloud, identity, endpoint, and SaaS environments. The position combines hands-on security engineering with GRC expertise, translating compliance requirements into technical controls that engineering teams can implement and consume. You will help shift compliance left by embedding control requirements into architecture, development workflows, and existing engineering systems. The role also offers significant ownership across SOC 2, ISO 27001/27017/27701, HIPAA, and related commercial frameworks. Success means improving audit readiness, reducing repetitive evidence collection, and addressing the root causes of control gaps rather than managing symptoms. This is a builder-focused environment where automation, continuous assurance, systems thinking, and collaboration are central to the way compliance is delivered.