1

Grc Engineer Jobs (NOW HIRING)

We are hiring a GRC Engineer to help modernize how Governance, Risk, and Compliance (GRC) operates across the organization. This role is focused on reducing compliance burden, improving scalability ...

About the Role The GRC Engineer is responsible for transforming Charlie Health's compliance, risk and control programs into automated, measurable and continuously monitored systems. This is a hands ...

Senior AI GRC Engineer

$227K - $267K/yr

As a Senior AI GRC Engineer at Vanta, you'll own and lead governance, risk, and compliance initiatives related to Vanta's internal AI adoption and customer-facing AI products. You'll apply deep ...

GRC Engineer

Palo Alto, CA · On-site

$130K - $170K/yr

GRC Engineer Why Zania Every enterprise spends millions of dollars on Governance, Risk, and Compliance (GRC). It's one of the most critical, yet universally painful, parts of running a business. For ...

We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills to build and scale automation across governance, risk, and compliance. This is a hands-on technical role ...

GRC Engineer

Foster City, CA · On-site

$210K - $320K/yr

We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust ...

GRC Engineer

New York, NY · On-site

$188K - $221K/yr

You will sit in the Security organization and work daily with the GRC Lead, Engineering, and Corporate Security. This is an engineering seat with a compliance domain, and it exists because we sell AI ...

GRC Engineer Department: Engineering Employment Type: Full Time Location: Remote Reporting To: Thomas Montgomery Description ZBD is building the financial operating system for the gaming economy: the ...

Senior GRC Engineer

Dallas, TX · On-site +1

$103K - $142K/yr

Lantern is seeking a Senior GRC Engineer to join our team as a key individual contributor. This role is built specifically for someone who builds compliance infrastructure, not just manages it. You ...

Role Overview ButterflyMX is seeking a GRC Engineer who is equal parts practitioner and builder. You will own the governance, risk, and compliance program. But more importantly, you will re-engineer ...

Senior GRC Engineer

Dallas, TX · Hybrid

$103K - $142K/yr

Lantern is seeking a Senior GRC Engineer to join our team as a key individual contributor. This role is built specifically for someone who builds compliance infrastructure, not just manages it. You ...

Senior GRC Engineer

New York, NY · On-site

$125K - $171K/yr

Aircall is hiring a Senior GRC Engineer to build and operate the engineering backbone of our Governance, Risk & Compliance program. You'll join the Security Engineering team, reporting to the ...

Senior GRC Engineer

New York, NY

$125K - $171K/yr

Aircall is hiring a Senior GRC Engineer to build and operate the engineering backbone of our Governance, Risk & Compliance program. You'll join the Security Engineering team, reporting to the ...

What you'll do: We're looking for a mid-level GRC Engineer to help us scale our compliance program through automation and run audits across SOC 2, ISO 27001, and SOX. This is a hands-on, technical ...

GRC Engineer

Vienna, VA · On-site

$140K - $170K/yr

Run the GRC calendar: tabletop exercises, prepare security committee meetings, security awareness training, and annual reviews * Identify control gaps and drive remediation across Engineering, IT, HR ...

Senior GRC Engineer

$130K - $150K/yr

The Opportunity We are hiring a US based, remote, SR GRC Engineer to support and scale our Assurance & Compliance function through an engineering-driven, automation-first approach. This role is ...

GRC Engineer Location: San Jose CA Duration: 6 Months 100% Onsite- ** LOCAL CANDIDATES ONLY** Seeking a hands-on GRC Engineer with expertise in Python, API development, and modern architectures ...

next page

Showing results 1-20

Grc Engineer information

See salary details

$59.5K

$111.6K

$203K

How much do grc engineer jobs pay per year?

As of Jul 27, 2026, the average yearly pay for grc engineer in the United States is $111,632.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,500.00 and $132,500.00 per year, depending on experience, location, and employer.

What are GRC Engineers?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

Is GRC still in demand?

GRC (Governance, Risk, and Compliance) engineers are in high demand due to increasing cybersecurity regulations and the need for organizations to manage risks effectively. Skills in risk assessment, compliance frameworks, and security tools like GRC software are valuable in this field, which is expected to grow as organizations prioritize security and regulatory adherence.

What engineers make $200,000 a year?

Senior GRC (Governance, Risk, and Compliance) engineers with extensive experience, specialized skills in cybersecurity frameworks, and relevant certifications such as CISSP or CISA can earn $200,000 or more annually. Compensation varies based on industry, location, and company size, with roles often requiring expertise in risk management, compliance standards, and security tools.

What are the key skills and qualifications needed to thrive as a GRC Engineer, and why are they important?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What engineers make $500,000?

Senior engineers in specialized fields such as software engineering, data engineering, or cybersecurity can earn $500,000 or more annually, especially with extensive experience, advanced skills, and in high-demand industries. Executive or leadership roles like engineering managers or directors may also reach this compensation level. Achieving this often requires advanced certifications, a strong track record, and working in competitive or high-paying markets.

What are some common challenges faced by GRC Engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

How much does a GRC engineer make?

A GRC (Governance, Risk, and Compliance) engineer's salary typically ranges from $80,000 to $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in security tools and frameworks can earn higher salaries.
More about Grc Engineer jobs
What cities are hiring for Grc Engineer jobs? Cities with the most Grc Engineer job openings:
What states have the most Grc Engineer jobs? States with the most job openings for Grc Engineer jobs include:
Infographic showing various Grc Engineer job openings in the United States as of July 2026, with employment types broken down into 96% Full Time, 1% Part Time, and 3% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $111,632 per year, or $53.7 per hour.

Job description

Why Charlie Health?
Millions of people across the country are navigating mental health conditions, substance use disorders, and eating disorders, but too often, they're met with barriers to care. From limited local options and long wait times to treatment that lacks personalization, behavioral healthcare can leave people feeling unseen and unsupported.
Charlie Health exists to change that. Our mission is to connect the world to life-saving behavioral health treatment. We deliver personalized, virtual care rooted in connection-between clients and clinicians, care teams, loved ones, and the communities that support them. By focusing on people with complex needs, we're expanding access to meaningful care and driving better outcomes from the comfort of home.
As a rapidly growing organization, we're reaching more communities every day and building a team that's redefining what behavioral health treatment can look like. If you're ready to use your skills to drive lasting change and help more people access the care they deserve, we'd love to meet you.
About the Role
The GRC Engineer is responsible for transforming Charlie Health's compliance, risk and control programs into automated, measurable and continuously monitored systems. This is a hands-on engineering role focused on building the technical foundations that support HIPAA, SOC 2, NIST and other compliance requirements.
This role will partner closely with Information Security, IT Engineering, Compliance, Legal, Engineering and business teams to translate regulatory, contractual and risk requirements into automated controls, evidence pipelines, dashboards, workflows and continuous control monitoring.
Our Information Security and IT organizations treat compliance as an engineering discipline. We value ownership, automation, measurable outcomes, reliability, auditability and continuous improvement. The GRC Engineer will help move Charlie Health from manual, point-in-time compliance activities toward scalable, system-driven assurance.
Charlie Health operates in a highly regulated healthcare environment. This role will help ensure that controls protecting patient, clinician, employee and company data are well-designed, consistently operated and supported by reliable evidence.
Responsibilities
Compliance Engineering & Control Automation
  • Design, build and operate automated controls that support HIPAA, SOC 2, NIST, ISO 27001 and other applicable frameworks
  • Translate compliance requirements into technical control logic, workflows, integrations, dashboards and evidence pipelines
  • Build scalable systems that reduce manual compliance work and improve confidence in control effectiveness
  • Partner with Security, IT, Compliance and Engineering teams to embed control requirements into systems and operating processes
Continuous Control Monitoring
  • Build and maintain continuous control monitoring capabilities across identity, endpoints, cloud, SaaS platforms, security tools and business systems
  • Define control health metrics, thresholds, alerts and reporting mechanisms
  • Identify control gaps, exceptions and drift, then partner with control owners to drive remediation
  • Improve visibility into the design, operation and effectiveness of key controls
Evidence Automation & Audit Readiness
  • Automate audit evidence collection across systems such as Okta, Google Workspace, Jamf, Intune, SentinelOne, Wiz, AWS, Jira, Confluence, Slack and GRC platforms
  • Build repeatable evidence workflows that support HIPAA, SOC 2, customer due diligence, vendor assessments and internal risk reviews
  • Improve the quality, consistency and traceability of audit evidence
  • Partner with Compliance, Legal and external auditors to reduce audit burden and improve readiness
GRC Systems, Integrations & Reporting
  • Configure and improve GRC platforms, compliance tools, ticketing systems, documentation repositories and reporting workflows
  • Build integrations between GRC systems and source systems of record using APIs, webhooks, scripts and workflow automation tools
  • Develop dashboards and reports that show control health, remediation status, audit readiness and risk trends
  • Maintain documentation for control logic, data sources, automations and operational procedures
Risk, Remediation & Exception Management
  • Support risk and control assessments by providing technical analysis, control evidence and remediation tracking
  • Build workflows for risk acceptance, exception management, corrective action plans and control remediation
  • Partner with control owners to ensure findings are tracked, prioritized and resolved
  • Help define metrics that measure risk reduction, compliance maturity and control reliability
AI Governance & Emerging Compliance Automation
  • Help evaluate how AI tools, LLM platforms and AI-enabled workflows affect compliance, privacy and security requirements
  • Support governance controls for enterprise AI adoption, including access, logging, data protection, review workflows and evidence collection
  • Identify opportunities to use automation and AI responsibly to improve GRC operations
  • Stay current on emerging approaches to compliance automation, continuous assurance and AI-enabled GRC
Required Qualifications
  • 3+ years of experience in GRC engineering, security engineering, compliance automation, IT risk, security operations, cloud security, infrastructure engineering or a related technical discipline
  • Hands-on experience translating compliance, risk or security requirements into technical controls, workflows or automations
  • Experience with frameworks such as HIPAA, SOC 2, NIST, ISO 27001, HITRUST, PCI or FedRAMP
  • Experience working with enterprise systems such as Okta, Google Workspace, AWS, Jamf, Intune, SentinelOne, Wiz, Jira, Confluence, Slack or similar platforms
  • Experience using APIs, scripting or workflow automation tools such as Python, Bash, PowerShell, Workato, Terraform, REST APIs, webhooks or JSON
  • Experience with audit evidence collection, control testing, remediation tracking or compliance reporting
  • Familiarity with GRC platforms, compliance automation tools, ticketing systems or control monitoring systems
  • Strong understanding of access control, endpoint security, cloud security, logging, vulnerability management and data protection concepts
  • Ability to work cross-functionally with Security, IT Engineering, Compliance, Legal and business stakeholders
  • Strong analytical thinking, ownership and ability to operate independently in ambiguous environments
Preferred Qualifications
  • Experience in healthcare or other regulated environments
  • Experience supporting HIPAA, SOC 2, NIST, HITRUST, ISO 27001 or similar programs
  • Experience building automated evidence pipelines or continuous control monitoring capabilities
  • Experience with GRC or compliance automation platforms such as Vanta, Drata, Secureframe, AuditBoard, Archer, ServiceNow GRC or similar tools
  • Experience with data analytics, dashboards, SQL, BI tools or control reporting
  • Experience supporting customer security reviews, vendor assessments or audit response workflows
  • Experience with AI governance, AI risk management, LLM platforms or AI-enabled compliance automation
  • Familiarity with Zero Trust principles and identity-centric security models
Benefits
Charlie Health is pleased to offer comprehensive benefits to all full-time employees. Read more about our benefits here.
Additional Information
The total target base compensation for this role will be between $130,000 and $175,000 per year at the commencement of employment. Please note, pay will be determined on an individualized basis and will be impacted by location, experience, leveling, expertise, internal pay equity, and other relevant business considerations. Further, cash compensation is only part of the total compensation package, which, depending on the position, may include stock options and other Charlie Health-sponsored benefits.
Our Values
  • Connection: Care deeply & inspire hope.
  • Congruence: Stay curious & heed the evidence.
  • Commitment: Act with urgency & don't give up.

Please do not call our public clinical admissions line in regard to this or any other job posting.
Please be cautious of potential recruitment fraud. If you are interested in exploring opportunities at Charlie Health, please go directly to our Careers Page: https://www.charliehealth.com/careers/current-openings. Charlie Health will never ask you to pay a fee or download software as part of the interview process with our company. In addition, Charlie Health will not ask for your personal banking information until you have signed an offer of employment and completed onboarding paperwork that is provided by our People Operations team. All communications with Charlie Health Talent and People Operations professionals will only be sent from @charliehealth.com email addresses. Legitimate emails will never originate from gmail.com, yahoo.com, or other commercial email services.
Recruiting agencies, please do not submit unsolicited referrals for this or any open role. We have a roster of agencies with whom we partner, and we will not pay any fee associated with unsolicited referrals.
At Charlie Health, we value being an Equal Opportunity Employer. We strive to cultivate an environment where individuals can be their authentic selves. Being an Equal Opportunity Employer means every member of our team feels as though they are supported and belong. We value diverse perspectives to help us provide essential mental health and substance use disorder treatments to all young people.
Charlie Health applicants are assessed solely on their qualifications for the role, without regard to disability or need for accommodation.
By clicking "Submit application" below, you agree to Charlie Health's Privacy Policy and Terms of Service.
By submitting your application, you agree to receive SMS messages from Charlie Health regarding your application. Message and data rates may apply. Message frequency varies. You can reply STOP to opt out at any time. For help, reply HELP.