1

Grc Engineer Jobs in Colorado (NOW HIRING)

GRC automation & tooling (e.g. compliance automation platforms, API integrations, scripted evidence ... Serve as a trusted advisor to Engineering and Product teams, embedding compliance-by-design into ...

IRM GRC ServiceNow Developer Senior

Englewood, CO · On-site

$53.25 - $73.25/hr

Job Title: IRM GRC ServiceNow Developer Senior Location: Englewood, CO Type: Contract To Hire Compensation: 130-160K Contractor Work Model: On-site Security Clearance: Clearable for a secret ...

IRM GRC ServiceNow Developer Senior

Englewood, CO · On-site

$53.25 - $73.25/hr

Job Title: IRM GRC ServiceNow Developer Senior Location: Englewood, CO Type: Contract To Hire Compensation: 130-160K Contractor Work Model: On-site Security Clearance: Clearable for a secret ...

IRM GRC ServiceNow Developer Senior

Englewood, CO · On-site

$53.25 - $73.25/hr

Job Title: IRM GRC ServiceNow Developer Senior Location: Englewood, CO Type: Contract To Hire Compensation: 130-160K Contractor Work Model: On-site Security Clearance: Clearable for a secret ...

IRM GRC ServiceNow Developer Senior

Englewood, CO · On-site

$53.25 - $73.25/hr

Job Title: IRM GRC ServiceNow Developer Senior Location: Englewood, CO Type: Contract To Hire Compensation: 130-160K Contractor Work Model: On-site Security Clearance: Clearable for a secret ...

Analyst-Cyber GRC, Sr.

Lakewood, CO · On-site

$99K - $128K/yr

The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy ... Engineering, and business stakeholders on contract reviews, obligation mapping, risk assessments ...

Analyst-Cyber GRC, Sr.

Lakewood, CO · On-site

$100K - $129K/yr

The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy ... Engineering, and business stakeholders on contract reviews, obligation mapping, risk assessments ...

Sr. Principal, GRC

Boulder, CO · On-site

$196K - $287K/yr

... in Computer Engineering, Computer Science, Management Information Systems or related field plus ... GRC-related occupation. 7 years (84 months) of experience in EMEA cybersecurity standards and ...

Analyst-Cyber GRC, Sr.

Lakewood, CO

$100K - $129K/yr

... Engineering, and business stakeholders on contract reviews, obligation mapping, risk assessments ... Familiarity with GRC tools, third-party risk management platforms, or similar systems.

next page

Showing results 1-20

Grc Engineer information

See Colorado salary details

$62.6K

$117.4K

$213.5K

How much do grc engineer jobs pay per year?

As of Aug 10, 2026, the average yearly pay for grc engineer in Colorado is $117,383.00, according to ZipRecruiter salary data. Most workers in this role earn between $84,600.00 and $139,300.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions in GRC may be available but usually require foundational skills, certifications, or internships to qualify for more advanced roles.
What are popular job titles related to Grc Engineer jobs in Colorado? For Grc Engineer jobs in Colorado, the most frequently searched job titles are:
What job categories do people searching Grc Engineer jobs in Colorado look for? The top searched job categories for Grc Engineer jobs in Colorado are:
What cities in Colorado are hiring for Grc Engineer jobs? Cities in Colorado with the most Grc Engineer job openings:
Infographic showing various Grc Engineer job openings in Colorado as of August 2026, with employment types broken down into 90% Full Time, 5% Part Time, and 5% Contract. Highlights an 86% Physical, 5% Hybrid, and 9% Remote job distribution, with an average salary of $117,383 per year, or $56.4 per hour.

Senior Security Compliance Engineer

Klaviyo

Denver, CO • On-site

Other

Re-posted 9 days ago


Job description

At Klaviyo, we're on a mission to empower creators to own their destiny. Our AI-first B2C CRM platform empowers 176,000+ brands in 80+ countries to cultivate relationships with hundreds of millions of consumers. We love solving hard problems and look for people who specialize in certain areas while being passionate about building, owning, and scaling solutions end-to-end, overcoming any obstacle in their way. We are a team of ambitious, customer-obsessed peers who are insatiably curious and meticulous in our craft. We push each other to grow beyond our comfort zone, learn new things, and work hard to ensure each day is better than the last.

An exciting opportunity within the Security Trust and Risk (STAR) team whose mission is to ensure the safety and security of our customers, partners and Klaviyos as well as deliver best in class technology solutions, infrastructure and services. This is achieved by providing a robust and secure technology foundation to do great work. We solve problems using technology, embrace automation and AI, and support Klaviyo's continued scalability and sustainable employee growth in a rapidly evolving environment.

About this role

We're seeking a highly motivated Senior Security Compliance Engineer to serve as a trusted advisor and hands-on engineer within our Security Trust & Compliance team. You'll design, build, and optimize automated solutions that streamline compliance operations, strengthen continuous control monitoring, and integrate GRC tooling across Klaviyo's systems. You'll partner closely with cross-functional teams, such as Engineering, IT, Security, Legal, Internal Audit, and more. You'll help Klaviyo scale securely, sustainably deliver more value for our customers, and bolster their trust in us.

As a Senior Security Compliance Engineer, you'll focus primarily on:

  • Compliance operations & audits (for SOC 2, ISO 27001, ISO 27017, PCI, and SOX ITGCs)
  • Continuous control monitoring
  • GRC automation & tooling (e.g. compliance automation platforms, API integrations, scripted evidence collection and control validation)

How you'll have an impact

  • Design, develop, and maintain automated compliance workflows using scripting, APIs, and GRC tooling to streamline evidence collection, control validation, and audit readiness across SOC 2, ISO 27001, ISO 27017, PCI, and SOX ITGCs
  • Build and improve continuous control monitoring capabilities that provide real-time visibility into Klaviyo's compliance posture and proactively surface control gaps
  • Partner with the Security Risk team to streamline end-to-end Security Compliance-to-Risk operations, ensuring compliance findings and control observations flow efficiently into risk management workflows
  • Implement and customize compliance automation platforms (e.g. Drata, Vanta, Anecdotes) and integrate them with Klaviyo's internal systems, CI/CD pipelines, and cloud infrastructure
  • Serve as a trusted advisor to Engineering and Product teams, embedding compliance-by-design into architecture decisions and helping teams understand and meet security control requirements
  • Identify and drive high-value opportunities to use AI and automation to eliminate toil, improve compliance operations, and scale our programs alongside Klaviyo's growth

Who you are

  • 3-5 years of experience in security compliance, GRC engineering, security engineering, or a closely related field with a strong emphasis on automation and scalable processes
  • Understanding of modern cloud-native web application architectures and related security best practices, especially in the context of AWS, Kubernetes, and AI
  • Experience implementing and operating Compliance Automation platforms, such as Drata, Vanta, Anecdotes, HyperProof, etc.
  • Hands-on experience executing compliance programs for SOC 2, ISO 27001, ISO 27017, PCI, and/or SOX ITGCs
  • Proficiency in one or more programming/scripting languages (e.g. Python, Go, SQL) with hands-on experience building automation for compliance workflows, integrating REST APIs, and working with GRC tooling
  • Experience applying GRC Engineering principles and values in practice, especially with regard to automation, systems + design thinking, and threat-informed GRC

Everyone on our team must have

  • A strong bias toward evidence, logic, math, and reason when communicating risk (instead of fear, uncertainty, and doubt)
  • A strong bias toward "guardrails, not gates" and "paved security roads" philosophies (instead of rigid "centralized command-and-control" processes and operating styles)
  • Excellent ability to plan, prioritize, and deliver results cross-functionally and in a timely fashion
  • Proficiency discussing complex, nuanced topics with technical & non-technical audiences alike, especially software engineers
  • Strong alignment with Klaviyo's core values

Ideally, you may also have any of the following:

  • Experience implementing Identity Governance tools and processes, such as for user access reviews (UARs) and just-in-time access (JITA)
  • Experience working in security operations, security engineering, and/or security architecture roles
  • Experience with additional compliance frameworks such as ISO 27018, HIPAA, GDPR, CCPA, or NIS2