1

Grc Engineer Jobs (NOW HIRING)

GRC Engineer

$108K - $131K/yr

Treasure AI is hiring a GRC Engineer to design, build, and help operate the systems that power our Trust & Assurance (T&A) program. The right person for this role gets frustrated by manual compliance ...

As a GRC Engineer here at Chubb, you will apply engineering, automation, and data analytics principles to strengthen governance, risk, and compliance across our cybersecurity environment. You will ...

$125 - $150/hr

As a GRC Engineer here at Chubb, you will apply engineering, automation, and data analytics principles to strengthen governance, risk, and compliance across our cybersecurity environment. You will ...

GRC Engineer

Palo Alto, CA · On-site

$100 - $125/hr

GRC Engineer Why Zania Every enterprise spends millions of dollars on Governance, Risk, and Compliance (GRC). It's one of the most critical, yet universally painful, parts of running a business. For ...

As a GRC Engineer here at Chubb, you will apply engineering, automation, and data analytics principles to strengthen governance, risk, and compliance across our cybersecurity environment. You will ...

GRC Engineer Department: Engineering Employment Type: Full Time Location: Remote Reporting To: Thomas Montgomery Description ZBD is building the financial operating system for the gaming economy: the ...

GRC Engineer

Palo Alto, CA · On-site

$130K - $170K/yr

GRC Engineer Why Zania Every enterprise spends millions of dollars on Governance, Risk, and Compliance (GRC). It's one of the most critical, yet universally painful, parts of running a business. For ...

GRC Engineer

New York, NY · On-site

$151K - $273K/yr

You will sit in the Security organization and work daily with the GRC Lead, Engineering, and Corporate Security. This is an engineering seat with a compliance domain, and it exists because we sell AI ...

GRC Engineer

Foster City, CA · On-site

$210K - $320K/yr

We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust ...

GRC Engineer

Manhattan, NY · On-site

$150 - $200/hr

You will sit in the Security organization and work daily with the GRC Lead, Engineering, and Corporate Security. This is an engineering seat with a compliance domain, and it exists because we sell AI ...

$100 - $125/hr

Get to know the GRC Engineering (GOV) Team Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment ...

$150 - $200/hr

Get to know the GRC Engineering (GOV) Team Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800‑171, NIST SP 800‑53, FedRAMP, and ...

Role Overview ButterflyMX is seeking a GRC Engineer who is equal parts practitioner and builder. You will own the governance, risk, and compliance program. But more importantly, you will re-engineer ...

$125 - $150/hr

The Opportunity We are seeking a GRC Engineer to lead the transformation of our Technology Compliance program. In this role, you will replace manual audit testing with Compliance-as-Code (CaC ...

GRC Engineer

Manhattan, NY · On-site

$150 - $200/hr

Role Overview ButterflyMX is seeking a GRC Engineer who is equal parts practitioner and builder. You will own the governance, risk, and compliance program. But more importantly, you will re-engineer ...

$100 - $125/hr

Get to know the GRC Engineering (GOV) Team Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment ...

GRC Engineer (CMMC)

$58.50 - $72/hr

Get to know the GRC Engineering (GOV) Team Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment ...

GRC Engineer Location: San Jose CA Duration: 6 Months 100% Onsite- ** LOCAL CANDIDATES ONLY** Seeking a hands-on GRC Engineer with expertise in Python, API development, and modern architectures ...

Get to know the GRC Engineering (GOV) Team Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment ...

GRC Engineer - REMOTE

$110K - $143K/yr

The Opportunity We are seeking a GRC Engineer to lead the transformation of our Technology Compliance program. In this role, you will replace manual audit testing with Compliance-as-Code (CaC ...

next page

Showing results 1-20

Grc Engineer information

See salary details

$59.5K

$111.6K

$203K

How much do grc engineer jobs pay per year?

As of Sep 8, 2026, the average yearly pay for grc engineer in the United States is $111,632.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,500.00 and $132,500.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Are GRC engineer jobs hard to get?

GRC (Governance, Risk, and Compliance) engineer jobs can be competitive, especially for entry-level positions, but having relevant skills in cybersecurity, risk management, and certifications like CISSP or CISA can improve chances. The difficulty of securing a GRC engineer role depends on experience, education, and the demand within the industry or organization. Strong knowledge of compliance frameworks and tools is often required to stand out.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions may be available but often require foundational skills, certifications, or internships in cybersecurity or IT governance.
More about Grc Engineer jobs

What cities are hiring for Grc Engineer jobs?

Cities with the most Grc Engineer job openings:

What states have the most Grc Engineer jobs?

States with the most job openings for Grc Engineer jobs include:

What are popular job titles related to Grc Engineer jobs?

For Grc Engineer jobs, the most frequently searched job titles are:

Infographic showing various Grc Engineer job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 92% Full Time, 3% Part Time, and 4% Contract. Highlights an 85% Physical, 4% Hybrid, and 11% Remote job distribution, with an average salary of $111,632 per year, or $53.7 per hour.

$108K - $131K/yr

Full-time

Medical, Dental, Vision, Life, Retirement

Re-posted 10 days ago


Job description

Treasure AI:
Treasure AI is the agentic experience platform built to acquire, retain, and grow your most valuable customers. Powered by AI, Treasure AI is shaped by human creativity and always-on through continuous, context-driven action.
Furthermore, Treasure AI employees are enthusiastic, data-driven, and customer-obsessed. We are a team of drivers-self-starters who take initiative, anticipate needs, and proactively jump in to solve problems. Our actions reflect our values of honesty, reliability, openness, and humility.
Your Role:
Treasure AI is hiring a GRC Engineer to design, build, and help operate the systems that power our Trust & Assurance (T&A) program. The right person for this role gets frustrated by manual compliance work - not because it's beneath them, but because they know it doesn't have to exist.
This role sits at the intersection of security engineering and GRC. You will design, operate, and maintain the systems that make compliance continuous, visible in real-time, and GRC insights actionable. You will treat the GRC platform as a programmable surface, extend it via APIs and agent workflows, and integrate it with the rest of Treasure AI's tech stack.
You will work closely with GRC Specialists, taking program requirements and translating them into technical implementations - automations, integrations, dashboards, guardrails, and tooling. You will also work directly with Security, IT, Engineering, and Product teams to embed compliance into the systems and pipelines they already use.
AI fluency is a baseline expectation. You will use agentic tools to accelerate your own work and will build AI-powered automations into GRC workflows - from evidence ingestion to questionnaire response to executive reporting.
Responsibilities & Duties:
  • Build AI agent workflows (using Claude, MCP integrations, or similar) to automate repeatable GRC tasks.
  • Configure and maintain the technical configuration and extension of our GRC platform - architect data relationships, configure control workflows, build custom rules, and extend the platform via APIs and webhooks rather than relying on the default UI.
  • Build automated executive readout workflows so monthly and quarterly GRC reporting is a 30-minute review, not a multi-day build.
  • Design and operate automated evidence collection pipelines and continuous control monitoring - pulling signals directly from source systems in real time so drift is surfaced before audit time, not during it.
  • Translate controls into testable, codified checks. Identify gaps in compliance coverage across CI/CD pipelines and IaC (Terraform) and contribute compliance logic where gaps exist.
  • Embed lightweight compliance checkpoints into design review workflows, ensuring control-relevant changes are flagged before deployment.
  • Support FAIR-informed quantitative risk modeling with data pipelines and tooling that make risk scenarios computable rather than narrative-only.
  • Build and maintain automation for the TPRM lifecycle - vendor intake, risk scoring, questionnaire distribution, evidence analysis, and remediation tracking - using AI-assisted tooling to reduce per-vendor manual effort.
  • Build tooling and dashboards that give the GRC Specialist and business stakeholders a continuous view of privileged access, access exceptions, and open remediation items - replacing point-intime UAR reports with an always-on IGA posture.
  • Build and maintain automation across the customer trust surface - AI-assisted questionnaire response pipelines, RFP contribution workflows, and trust center content management - so customer assurance accelerates deals rather than bottlenecking them.
  • Build automation across the security awareness and training lifecycle - detecting end-user risk signals or policy violations to improve the culture of security.

Required Qualifications:
  • At least 3+ years in Security Engineering, DevSecOps, Technical GRC, or a closely adjacent function - with a demonstrably strong engineering track record in automation and tooling, not just program ownership.
  • Strong coding foundation: proficient in Python and/or TypeScript, comfortable calling REST APIs, handling JSON/YAML payloads, building webhooks, and shipping integrations from scratch without hand-holding or assistance. You treat Jira, Confluence, Slack, and similar enterprise tools as systems to integrate with, not just UIs to click through.
  • Hands-on experience building automation and integrations in enterprise environments - not just configuring OOTB features, but writing code to extend or connect systems.
  • Practical hands-on experience with a modern GRC platform (Vanta, anecdotes, Drata, Secureframe, or similar) - you've configured custom workflows, written rules, and used the APIs; not just the UI.
  • Working knowledge of SOC 2, ISO 27001/17/18, ISO 42001 and HIPAA - enough to read a control and determine how to test it programmatically.
  • Demonstrated experience shipping AI-assisted automation: agent workflows, prompt pipelines, LLM-integrated integrations, or similar. Comfort with agentic coding tools (Claude Code, Cursor, or equivalent).
  • Familiarity with the AWS security control surface (IAM, CloudTrail, Config, GuardDuty) and how to consume compliance signals via API; working knowledge of CI/CD workflows (GitHub Actions or similar) and IaC (Terraform or equivalent) - you understand where compliance checks can be embedded in a deployment pipeline.
  • Strong collaboration and written communication skills - able to work across multiple Security domains, IT, Engineering, Legal/Privacy, and GTM, and able to write clear technical documentation.

Travel Requirements:
Annual team on-site in the US/CAN (total travel: <10%)
Perks and Benefits (US):
Our benefit package showcases our culture of care and empathy with
  • Comprehensive medical, dental, vision plans and Employee Assistance Program (EAP)
  • Competitive compensation packages
  • Company paid life insurance 3x salary
  • Company paid short- and long-term disability coverage
  • Retirement planning (401K) with 4% company match
  • Restricted Stock Units (RSU)
  • Flexible Time Off (FTO)
  • Up to 26 weeks paid parental leave including a post-partum night nurse
  • Comprehensive support and access to care for everyone, everywhere through Carrot - our global reproductive health and family-building benefit.

Our Dedication to You:
We value and promote diversity, equity, inclusion, and belonging in all aspects of our business and at all levels. Success comes from acknowledging, welcoming, and incorporating diverse perspectives.
Diverse representation alone is not the desired outcome. We also strive to create an inclusive culture that encourages growth, ownership of your role, and achieving innovation in new and unique ways. Your voice will be heard, and we will help amplify it.
Agencies and Recruiters:
We cannot consider your candidate(s) without a contract in place. Any resumes received without having an active agreement will be considered gratis referrals to us. Thank you for your understanding and cooperation!
This description captures the core of the role today. As we adopt AI and new ways of working, responsibilities may evolve, and we encourage team members to take initiative, lean into change, and help expand the impact of their role beyond what's listed here.
Locations Remote Remote status Fully Remote Yearly salary $108,600 - $131,000 Employment type Full-time