1

Grc Engineer Salary Jobs (NOW HIRING)

GRC Engineer

New York, NY · On-site

$232K - $273K/yr

You will sit in the Security organization and work daily with the GRC Lead, Engineering, and ... Comprehensive salary, benefits, and tools for success. * Meaningful work: Your efforts shape how ...

GRC Engineer

Foster City, CA · On-site

$210K - $320K/yr

We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and ... Competitive Salary & Equity 401(k) Program with a 4% match (US Only) Health, Dental, Vision and ...

GRC Engineer

Manhattan, NY · On-site

$120 - $190/hr

You will sit in the Security organization and work daily with the GRC Lead, Engineering, and ... Comprehensive salary, benefits, and tools for success. * Meaningful work: Your efforts shape how ...

Lead GRC Engineer

San Francisco, CA · On-site

$220K - $280K/yr

About the role: We're looking for a Lead GRC Engineer to build the technical foundation of our ... Base Salary: The anticipated salary range for this role is $220,000 - $280,000, depending on ...

Lead GRC Engineer

San Francisco, CA · On-site

$220 - $280/hr

About the role: We're looking for a Lead GRC Engineer to build the technical foundation of our ... Base Salary: The anticipated salary range for this role is $220,000 - $280,000, depending on ...

Lead GRC Engineer

San Francisco, CA · Remote

$220K - $280K/yr

About the role: We're looking for a Lead GRC Engineer to build the technical foundation of our ... Base Salary: The anticipated salary range for this role is $220,000 - $280,000, depending on ...

Cybersecurity GRC Engineer

New York, NY · On-site

$99K - $150K/yr

The salary of the finalist selected for this role will be determined based on various factors ... We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk ...

Senior GRC Engineer

$130K - $150K/yr

Partner with Engineering, Security, Legal, Privacy, and Product teams to integrate compliance ... Base salary is determined by job-related experience, education/training, as well as market ...

## Senior GRC Programmer/AnalystApplyremote type: Officelocations: Columbus, OH: Chicago, IL: Detroit ... Compensation Range:**$57,000 - $113,000 Annual Salary The compensation range represents the ...

Senior Director, GRC

San Francisco, CA · On-site

$264K - $363K/yr

We don't view Governance, Risk, and Compliance (GRC) as a passive reporting function or an ... Engineering, or equivalent experience. #LI-CH1 #P25608_3520635 The annual base salary range for ...

Senior Director, GRC

San Francisco, CA · On-site

$264 - $363/hr

Drive rapid, engineering-led remediation of audit findings and control gaps. * Cross-Functional ... salary range for this position for candidates located in the San Francisco Bay area is between ...

next page

Showing results 1-20

Grc Engineer Salary information

See salary details

$59.5K

$111.6K

$203K

How much do grc engineer salary jobs pay per year?

As of Sep 5, 2026, the average yearly pay for grc engineer salary in the United States is $111,632.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,500.00 and $132,500.00 per year, depending on experience, location, and employer.

What is the average salary for a GRC engineer?

The average salary for a GRC (Governance, Risk, and Compliance) Engineer typically ranges from $90,000 to $140,000 per year in the United States, depending on experience, location, and the specific industry. Entry-level roles may start around $80,000, while senior GRC Engineers can earn upwards of $150,000 or more, especially in major tech hubs or highly regulated industries. Factors such as certifications, advanced skills in cybersecurity, and knowledge of relevant frameworks can also influence salary levels.

What factors can influence the salary range for a GRC engineer?

The salary for a GRC (Governance, Risk, and Compliance) Engineer can vary significantly based on several factors, including the candidate’s level of experience, certifications (such as CISSP, CISM, or CRISC), and the industry in which they work. Additionally, salaries may be higher in regions with a greater demand for cybersecurity and compliance professionals, such as major metropolitan areas or technology hubs. The size and complexity of the organization, as well as the scope of responsibilities—like managing enterprise-wide risk assessments or implementing compliance frameworks—also play a crucial role in determining compensation. Career advancement in this field often leads to higher salaries through senior or managerial GRC roles.

What are the key skills and qualifications needed to thrive as a GRC engineer, and why are they important?

To thrive as a GRC (Governance, Risk, and Compliance) Engineer, you need a solid understanding of information security, risk management frameworks, and compliance standards, often supported by a relevant degree or certifications like CISSP, CISA, or CRISC. Familiarity with GRC platforms such as RSA Archer, ServiceNow GRC, or LogicManager is typically required. Strong analytical thinking, attention to detail, and effective communication skills help GRC Engineers interpret complex regulations and collaborate across departments. These skills ensure organizations effectively manage risk, maintain compliance, and safeguard critical assets.

What is the difference between Grc Engineer Salary vs Security Analyst?

AspectGrc EngineerSecurity Analyst
Required CredentialsCertifications like CISSP, CISA, CISMCertifications like CompTIA Security+, CISSP, GIAC
Work EnvironmentIT security teams, compliance departmentsSecurity operations centers, IT departments
Industry UsageFinancial, healthcare, tech sectorsFinancial, government, tech sectors

Grc Engineers and Security Analysts often share certifications and work in security-focused environments. While Grc Engineers focus on governance, risk, and compliance frameworks, Security Analysts primarily monitor and respond to security threats. Both roles are vital in maintaining organizational security posture, but their daily tasks and focus areas differ.

Are GRC engineer jobs hard to get?

GRC engineer jobs can be competitive due to the specialized skills required, such as knowledge of governance, risk management, and compliance frameworks. Candidates with relevant certifications, experience with security tools, and strong understanding of regulations tend to have better prospects. The difficulty of securing a position varies based on industry demand and individual qualifications.
More about Grc Engineer Salary jobs

What cities are hiring for Grc Engineer Salary jobs?

Cities with the most Grc Engineer Salary job openings:

What states have the most Grc Engineer Salary jobs?

States with the most job openings for Grc Engineer Salary jobs include:

What job categories do people searching Grc Engineer Salary jobs look for?

The top searched job categories for Grc Engineer Salary jobs are:

Infographic showing various Grc Engineer Salary job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 11% Part Time, and 2% Contract. Highlights an 90% Physical, 3% Hybrid, and 7% Remote job distribution, with an average salary of $111,632 per year, or $53.7 per hour.

GRC Engineer

Legora

New York, NY • On-site

$232K - $273K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 13 days ago


Key responsibilities

  • Build pipelines and integrations to aggregate control, asset, and identity data and turn it into automated checks, dashboards, and audit evidence.

  • Implement and maintain a unified controls library to ensure evidence collection satisfies multiple frameworks and is audit-ready.

  • Design and run agentic workflows for evidence analysis, control testing, and audit response preparation, incorporating human oversight where necessary.


Job description

About Us
Legora is redefining how legal work gets done. Not built for lawyers, built with them. We work alongside the world's best legal teams, who expect excellence, precision, and speed, and we hold ourselves to the same bar.
Our AI-native workspace lets legal professionals move faster, think more clearly, and operate with sharper precision. By analysing thousands of documents in minutes and powering end-to-end workflows, we cut through complexity, teams can focus on what matters: judgment, strategy, and outcomes.
1,000+ customers across 50+ countries trust us, including Cleary Gottlieb, Goodwin, Linklaters, White & Case, Dentons, and Barclays. We've scaled to $100M+ in ARR, with teams across Europe, North America and APAC, and continue to expand through acquisitions including Qura, Walter AI and Graceview.
We partner with world-class performers: including Aaron Judge and the New York Yankees, Ludvig Åberg (and his caddie), and campaigns featuring Jude Law.
Joining Legora means three things.
  • We lean in: ownership over titles, outcomes over intentions.
  • We fight for excellence: high standards, direct, ego-free feedback.
  • We grow together: as a team and with our customers.

Mission before ego. Everyone contributes. No one coasts.
If you're driven by impact, pace, and raising the bar. This is the place.
ABOUT THE ROLE
You will build the platform Legora's assurance program runs on: pipelines that collect evidence continuously, checks that enforce policy in CI/CD, and agents that test controls and draft audit responses. The GRC Lead owns the program and the judgment calls; you own the machinery that turns certifications into an output of normal operations.
You will sit in the Security organization and work daily with the GRC Lead, Engineering, and Corporate Security. This is an engineering seat with a compliance domain, and it exists because we sell AI agents to law firms: proving how our systems behave is part of the product.
WHAT YOU'LL DO
Evidence & controls platform
  • Build the pipelines and integrations that aggregate control, asset, and identity data across our stack (cloud, IdP, HRIS, source control, CI/CD) and turn it into automated checks, live dashboards, and audit evidence.
  • Implement the unified controls library so one control satisfies many frameworks, with evidence collected once and mapped everywhere.
  • Ingest from what partners already own - Corporate Security's technical controls, the SaaS portfolio's system of record - rather than building parallel collectors; system owners keep their evidence, your platform makes it audit-ready.
  • Build the technical evidence base for our AI certifications (ISO/IEC 42001 and emerging AI-agent assurance standards): agent action logging, evaluation evidence, tool-call restrictions, and failure-mode documentation, working with Product and Engineering.

Continuous assurance & agentic workflows
  • Translate written policies and regulatory requirements into enforceable rules: automated checks in CI/CD and infrastructure deployment, continuous controls monitoring, and drift alerts routed to owners.
  • Instrument control effectiveness so the GRC Lead reports risk posture from live data.
  • Design and run agentic workflows for evidence analysis, control testing, and audit response preparation, with a human in the loop where assurance demands it. Anything manual twice a quarter gets automated.
WHAT WE'RE LOOKING FOR
  • 6-8+ years spanning software or automation engineering and security compliance - an engineer who learned GRC, or a GRC operator who became a builder.
  • Production-grade scripting (Python or similar) against APIs - code you ship and own.
  • Hands-on experience building LLM/agent workflows and daily use of AI in your own work, with grounded judgment on what to delegate to agents, what needs a human, and how to evidence both to an auditor.
  • Enough GRC domain fluency to work inside SOC 2 / ISO 27001 control language and know what an auditor will accept as evidence.
  • Clear technical writing - your evidence and documentation will be read by auditors and customer security teams.
NICE TO HAVE
  • Experience with compliance platform APIs and when to build past them.
  • OSCAL or other machine-readable control/catalog formats.
  • Infrastructure-as-code (Terraform or similar) and CI/CD pipeline engineering.
  • Prior work on AI product assurance: evals, red-teaming evidence, or model/agent documentation.
WHAT'S IN IT FOR YOU
  • Global collaboration: Partner with teams and clients across Europe, APAC, and North America.
  • Competitive package: Comprehensive salary, benefits, and tools for success.
  • Meaningful work: Your efforts shape how thousands of lawyers use AI daily.
  • In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.
  • Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
    Medical, Dental & Vision
    • Multiple medical plan options through Aetna and Kaiser Permanente
    • HSA or Healthcare FSA (based on plan selection)
    • Dental plans via MetLife
    • Vision plans via Vision Care

    Family Support
    • Generous parental leave
    • Free access to Maven Clinic
    • Dependent Care FSA
    • Free One Medical membership for employees and dependents

    Additional Perks
    • Pre-tax commuter benefits
    • Life Insurance + STD/LTD
    • 401(K) with generous company match
    • Unlimited PTO
    • Robust voluntary benefits, including identity protection (via Aura), legal coverage via MetLife, pet savings programs, and more

Legora is an Equal Opportunity Employer
At Legora, we believe great teams are built on diversity of thought and experience. We're proud to be an equal opportunity employer and committed to creating an inclusive, high-performance culture where everyone can do their best work. We welcome people of all backgrounds and don't discriminate based on race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law.