1

Grc Engineer Jobs (NOW HIRING)

About the Role The GRC Engineer is responsible for transforming Charlie Health's compliance, risk and control programs into automated, measurable and continuously monitored systems. This is a hands ...

As a GRC Engineer here at Chubb, you will apply engineering, automation, and data analytics principles to strengthen governance, risk, and compliance across our cybersecurity environment. You will ...

They are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment. The role ...

About the Role The GRC Engineer is responsible for transforming Charlie Health's compliance, risk and control programs into automated, measurable and continuously monitored systems. This is a hands ...

This role seeks a hands-on GRC Engineer with strong development and cloud engineering experience, focusing on building secure, scalable systems. The ideal candidate will possess expertise in Python ...

As a GRC Engineer here at Chubb, you will apply engineering, automation, and data analytics principles to strengthen governance, risk, and compliance across our cybersecurity environment. You will ...

GRC Engineer

New York, NY · On-site

$188K - $221K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

You will sit in the Security organization and work daily with the GRC Lead, Engineering, and Corporate Security. This is an engineering seat with a compliance domain, and it exists because we sell AI ...

GRC Engineer Department: Engineering Employment Type: Full Time Location: Remote Reporting To: Thomas Montgomery Description ZBD is building the financial operating system for the gaming economy: the ...

GRC Engineer

Foster City, CA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust ...

GRC Engineer

Palo Alto, CA · On-site

$130K - $170K/yr

  • Medical

  • Dental

  • Vision

  • PTO

GRC Engineer Why Zania Every enterprise spends millions of dollars on Governance, Risk, and Compliance (GRC). It's one of the most critical, yet universally painful, parts of running a business. For ...

GRC Engineer

Foster City, CA · On-site

$210K - $320K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust ...

Senior GRC Engineer

San Francisco, CA · On-site

$180K - $200K/yr

We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills to build and scale automation across governance, risk, and compliance. This is a hands-on technical role ...

GRC Engineer

New York, NY · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Role Overview ButterflyMX is seeking a GRC Engineer who is equal parts practitioner and builder. You will own the governance, risk, and compliance program. But more importantly, you will re-engineer ...

GRC Engineer

Chicago, IL · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

What you'll do: We're looking for a mid-level GRC Engineer to help us scale our compliance program through automation and run audits across SOC 2, ISO 27001, and SOX. This is a hands-on, technical ...

GRC Engineer

Vienna, VA · On-site

$175K - $225K/yr

Run the GRC calendar: tabletop exercises, prepare security committee meetings, security awareness training, and annual reviews * Identify control gaps and drive remediation across Engineering, IT, HR ...

GRC Engineer

Chicago, IL · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

What you'll do: We're looking for a mid-level GRC Engineer to help us scale our compliance program through automation and run audits across SOC 2, ISO 27001, and SOX. This is a hands-on, technical ...

Senior GRC Engineer

San Francisco, CA · On-site

$180K - $200K/yr

  • Medical

  • PTO

We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills to build and scale automation across governance, risk, and compliance. This is a hands-on technical role ...

next page

Showing results 1-20

Grc Engineer information

See salary details

$59.5K

$111.6K

$203K

How much do grc engineer jobs pay per year?

As of Aug 17, 2026, the average yearly pay for grc engineer in the United States is $111,632.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,500.00 and $132,500.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions in GRC may be available but usually require foundational skills, certifications, or internships to qualify for more advanced roles.
More about Grc Engineer jobs

What cities are hiring for Grc Engineer jobs?

Cities with the most Grc Engineer job openings:

What states have the most Grc Engineer jobs?

States with the most job openings for Grc Engineer jobs include:

Infographic showing various Grc Engineer job openings in the United States as of August 2026, with employment types broken down into 92% Full Time, 2% Part Time, and 6% Contract. Highlights an 86% Physical, 5% Hybrid, and 9% Remote job distribution, with an average salary of $111,632 per year, or $53.7 per hour.

Full-time

Re-posted 15 days ago


Charlie Health rating

8.5

Company rating: 8.5 out of 10

Based on 12 frontline employees who took The Breakroom Quiz


Job description

About the Role

The GRC Engineer is responsible for transforming Charlie Health's compliance, risk and control programs into automated, measurable and continuously monitored systems. This is a hands-on engineering role focused on building the technical foundations that support HIPAA, SOC 2, NIST and other compliance requirements.

This role will partner closely with Information Security, IT Engineering, Compliance, Legal, Engineering and business teams to translate regulatory, contractual and risk requirements into automated controls, evidence pipelines, dashboards, workflows and continuous control monitoring.

Our Information Security and IT organizations treat compliance as an engineering discipline. We value ownership, automation, measurable outcomes, reliability, auditability and continuous improvement. The GRC Engineer will help move Charlie Health from manual, point-in-time compliance activities toward scalable, system-driven assurance.

Charlie Health operates in a highly regulated healthcare environment. This role will help ensure that controls protecting patient, clinician, employee and company data are well-designed, consistently operated and supported by reliable evidence.

ResponsibilitiesCompliance Engineering & Control Automation
  • Design, build and operate automated controls that support HIPAA, SOC 2, NIST, ISO 27001 and other applicable frameworks
  • Translate compliance requirements into technical control logic, workflows, integrations, dashboards and evidence pipelines
  • Build scalable systems that reduce manual compliance work and improve confidence in control effectiveness
  • Partner with Security, IT, Compliance and Engineering teams to embed control requirements into systems and operating processes
Continuous Control Monitoring
  • Build and maintain continuous control monitoring capabilities across identity, endpoints, cloud, SaaS platforms, security tools and business systems
  • Define control health metrics, thresholds, alerts and reporting mechanisms
  • Identify control gaps, exceptions and drift, then partner with control owners to drive remediation
  • Improve visibility into the design, operation and effectiveness of key controls
Evidence Automation & Audit Readiness
  • Automate audit evidence collection across systems such as Okta, Google Workspace, Jamf, Intune, SentinelOne, Wiz, AWS, Jira, Confluence, Slack and GRC platforms
  • Build repeatable evidence workflows that support HIPAA, SOC 2, customer due diligence, vendor assessments and internal risk reviews
  • Improve the quality, consistency and traceability of audit evidence
  • Partner with Compliance, Legal and external auditors to reduce audit burden and improve readiness
GRC Systems, Integrations & Reporting
  • Configure and improve GRC platforms, compliance tools, ticketing systems, documentation repositories and reporting workflows
  • Build integrations between GRC systems and source systems of record using APIs, webhooks, scripts and workflow automation tools
  • Develop dashboards and reports that show control health, remediation status, audit readiness and risk trends
  • Maintain documentation for control logic, data sources, automations and operational procedures
Risk, Remediation & Exception Management
  • Support risk and control assessments by providing technical analysis, control evidence and remediation tracking
  • Build workflows for risk acceptance, exception management, corrective action plans and control remediation
  • Partner with control owners to ensure findings are tracked, prioritized and resolved
  • Help define metrics that measure risk reduction, compliance maturity and control reliability
AI Governance & Emerging Compliance Automation
  • Help evaluate how AI tools, LLM platforms and AI-enabled workflows affect compliance, privacy and security requirements
  • Support governance controls for enterprise AI adoption, including access, logging, data protection, review workflows and evidence collection
  • Identify opportunities to use automation and AI responsibly to improve GRC operations
  • Stay current on emerging approaches to compliance automation, continuous assurance and AI-enabled GRC
Required Qualifications
  • 3+ years of experience in GRC engineering, security engineering, compliance automation, IT risk, security operations, cloud security, infrastructure engineering or a related technical discipline
  • Hands-on experience translating compliance, risk or security requirements into technical controls, workflows or automations
  • Experience with frameworks such as HIPAA, SOC 2, NIST, ISO 27001, HITRUST, PCI or FedRAMP
  • Experience working with enterprise systems such as Okta, Google Workspace, AWS, Jamf, Intune, SentinelOne, Wiz, Jira, Confluence, Slack or similar platforms
  • Experience using APIs, scripting or workflow automation tools such as Python, Bash, PowerShell, Workato, Terraform, REST APIs, webhooks or JSON
  • Experience with audit evidence collection, control testing, remediation tracking or compliance reporting
  • Familiarity with GRC platforms, compliance automation tools, ticketing systems or control monitoring systems
  • Strong understanding of access control, endpoint security, cloud security, logging, vulnerability management and data protection concepts
  • Ability to work cross-functionally with Security, IT Engineering, Compliance, Legal and business stakeholders
  • Strong analytical thinking, ownership and ability to operate independently in ambiguous environments
Preferred Qualifications
  • Experience in healthcare or other regulated environments
  • Experience supporting HIPAA, SOC 2, NIST, HITRUST, ISO 27001 or similar programs
  • Experience building automated evidence pipelines or continuous control monitoring capabilities
  • Experience with GRC or compliance automation platforms such as Vanta, Drata, Secureframe, AuditBoard, Archer, ServiceNow GRC or similar tools
  • Experience with data analytics, dashboards, SQL, BI tools or control reporting
  • Experience supporting customer security reviews, vendor assessments or audit response workflows
  • Experience with AI governance, AI risk management, LLM platforms or AI-enabled compliance automation
  • Familiarity with Zero Trust principles and identity-centric security models
Benefits

Charlie Health is pleased to offer comprehensive benefits to all full-time employees. Read more about our benefits here.

Additional Information

The total target base compensation for this role will be between $130,000 and $175,000 per year at the commencement of employment. Please note, pay will be determined on an individualized basis and will be impacted by location, experience, leveling, expertise, internal pay equity, and other relevant business considerations. Further, cash compensation is only part of the total compensation package, which, depending on the position, may include stock options and other Charlie Health-sponsored benefits.


What Charlie Health employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom