1

Grc Engineer Jobs in Oregon (NOW HIRING)

Lead Saviynt Engineer

Tualatin, OR · On-site

$106K - $140K/yr

You will serve as the technical authority for SAP-related identity and GRC capabilities, partnering ... Establish engineering standards for Saviynt configuration, custom development, testing, deployment ...

Senior Security Automation Engineer

OR · On-site +1

$114K - $156K/yr

... GRC functions. This capability exists to solve a real problem: as we scale and mature, we must move beyond manual evidence gathering, point-in-time audits, and disconnected identity workflows. We are ...

This role will support cybersecurity engineering, risk management, and security modernization ... Work within eMASS, ServiceNow GRC, or similar risk management systems to support ATO artifacts ...

Senior IT Security Engineer

OR · On-site +1

$130K - $155K/yr

... Engineer to drive our ISO 27001 and SOC 2 certification efforts, ensuring IT security is fully ... Build and mature NetBrain's GRC (Governance, Risk & Compliance) program - conduct risk assessments ...

Senior Product Security Engineer

OR · On-site +1

$114K - $156K/yr

... GRC. Our team is looking for an experienced, hands-on security practitioner, who will drive the ... Collaborate with engineering and product on improving existing and building new product features ...

Principal Software Engineer

OR · On-site +1

$134K - $180K/yr

Experience building security automation, governance, risk and compliance (GRC) platforms, or ... with sound engineering judgment. Position Location - This role is available in the following ...

Principal Platform Engineer

Beaverton, OR · On-site

$104.30 - $193.70/hr

Partner with Security Architecture and GRC to translate security and compliance requirements into ... Support and mentor engineering teams on best practices for infrastructure, automation, and platform ...

Senior Software Engineer

OR · On-site +1

$122K - $161K/yr

As a Senior Software Engineer, you will design and build internal applications that power critical ... Knowledge of governance, risk, and compliance (GRC) platforms, security tooling, or operational ...

Staff Cloud Security Engineer

OR · On-site +1

$225K - $275K/yr

Summary Join our dynamic team as a Staff Cloud Security Engineer, where you'll play a pivotal role ... Expertise in other areas of security (AppSec, CorpSec, GRC) * Security conference talks or ...

We empower our clients to reimagine GRC and protect and grow their business. Our innovative ... Work collaboratively with developers and product owners to identify corrective actions or effective ...

Senior Risk & Compliance Engineer - Data

OR · On-site +1

$105K - $143K/yr

Overview Instacart's Governance, Risk and Compliance (GRC) team sits at the intersection of security, data, and business impact - and we're building an automated, engineering-grade risk program that ...

next page

Showing results 1-20

Grc Engineer information

See Oregon salary details

$62.9K

$118K

$214.6K

How much do grc engineer jobs pay per year?

As of Aug 24, 2026, the average yearly pay for grc engineer in Oregon is $118,027.00, according to ZipRecruiter salary data. Most workers in this role earn between $85,100.00 and $140,100.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Are GRC engineer jobs hard to get?

GRC (Governance, Risk, and Compliance) engineer jobs can be competitive, especially for entry-level positions, but having relevant skills in cybersecurity, risk management, and certifications like CISSP or CISA can improve chances. The difficulty of securing a GRC engineer role depends on experience, education, and the demand within the industry or organization. Strong knowledge of compliance frameworks and tools is often required to stand out.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions may be available but often require foundational skills, certifications, or internships in cybersecurity or IT governance.

What are popular job titles related to Grc Engineer jobs in Oregon?

For Grc Engineer jobs in Oregon, the most frequently searched job titles are:

What job categories do people searching Grc Engineer jobs in Oregon look for?

The top searched job categories for Grc Engineer jobs in Oregon are:

What cities in Oregon are hiring for Grc Engineer jobs?

Cities in Oregon with the most Grc Engineer job openings:

Infographic showing various Grc Engineer job openings in Oregon as of August 2026, with employment types broken down into 100% Contract. Highlights an 100% In-person job distribution, with an average salary of $118,027 per year, or $56.7 per hour.

Manager, Information Security (GRC) (Remote)

Neumo Holdings LLC

Salem, OR • On-site

Full-time

Posted 4 days ago


Job description

Job Summary:

We are seeking a Manager, Information Security (GRC) to own and mature Neumo's Governance, Risk, and Compliance program. This role is critical to maintaining our SOC 1, SOC 2, and PCI certifications and to raising our overall information security maturity. You will build the foundation for data governance, risk acceptance and exceptions processes, and a recurring cadence of monthly, quarterly, and annual risk mitigation. This is a hands-on leadership role: you will manage 1–2 direct reports while personally driving audits, risk assessments, and control automation, and participate in incident management alongside the broader security team.

You will be the connective tissue between security engineering, legal, engineering, and executive leadership: translating regulatory and contractual requirements into practical controls, and translating control performance into risk language leadership can act on.
This role directly protects Neumo's ability to do business: Our certifications are foundational to customer trust and revenue. You will have the mandate to modernize how we manage risk and compliance, including building automation and AI-driven workflows that scale the program without scaling headcount linearly.


Duties and Responsibilities:

Leadership & Program Ownership

  • Own and execute Neumo's GRC strategy and roadmap, in partnership with the CISO.
  • Manage, mentor, and grow 1–2 direct reports supporting compliance, risk, and audit activities.
  • Set the foundation for data governance: data classification, ownership, retention, and handling standards.
  • Build and maintain the risk register; lead monthly, quarterly, and annual risk mitigation cycles.
  • Own the risk acceptance and policy exception process, including documentation, approval workflows, and periodic review.
  • Report on compliance posture, audit status, and risk trends to executive stakeholders and the board as needed.

Compliance & Audit Management

  • Own end-to-end readiness and execution for SOC 1, SOC 2, and PCI DSS audits, including evidence collection, auditor coordination, and remediation tracking.
  • Maintain and continuously improve the internal control framework mapped to SOC 1/2, PCI, and other applicable frameworks (e.g., ISO 27001, NIST CSF).
  • Track control ownership, testing cadence, and control health across the organization using the GRC platform and Jira.
  • Partner with engineering and IT teams to close control gaps and drive remediation of audit findings within SLA.

Risk, Automation & Cross-Functional Work

  • Design and implement control automation to reduce manual evidence collection and continuous control monitoring (CCM).
  • Leverage AI/LLM tooling to accelerate evidence review, policy drafting, control testing, and risk analysis, with appropriate human oversight.
  • Participate in incident management as the GRC/risk representative: assessing regulatory and contractual impact and ensuring proper documentation.
  • Manage third-party/vendor risk assessments and questionnaires (customer security questionnaires, vendor due diligence).
  • Partner with Legal and Privacy on data protection, regulatory, and contractual compliance requirements.


Education and Experience:

  • 6+ years of experience in GRC, information security compliance, or IT audit, including experience managing or mentoring others.
  • Direct experience owning SOC 1, SOC 2, and PCI DSS compliance programs end-to-end, including audit management.
  • Hands-on experience with GRC platforms (e.g., Vanta, Drata, ServiceNow GRC, OneTrust, Archer, or similar).
  • Experience building risk management programs: risk registers, risk acceptance/exception processes, and recurring risk mitigation cadences.
  • Foundational experience with data governance concepts (classification, ownership, retention).
  • Relevant certifications (e.g., CISA, CRISC, CISSP, CISM) are a plus but not required.


Knowledge, Skills and Abilities:

  • Strong working knowledge of Jira for control tracking, remediation workflows, and cross-team coordination.
  • Demonstrated ability to build or deploy control automation and continuous control monitoring.
  • Comfort leveraging AI tools to scale GRC operations (evidence review, policy generation, risk analysis).
  • Ability to participate effectively in incident management, translating technical incidents into risk and compliance impact.
  • Excellent written and verbal communication skills; able to translate technical and regulatory detail for executive audiences.


Work Environment:

  • Office setting with a moderate noise level.
  • The employee will work at an individual workstation, using a telephone and computer.
  • Periodic flexibility outside standard business hours may be required to support audits or incident response.


Physical Demands
:

  • Must be able to remain seated for extended periods.
  • Regular use of a computer and other office machinery, such as printers and copy machines.
  • Occasional movement around the office.
  • Frequent communication via telephone.


Neumo Summary:

With the backing of four decades of public sector expertise and corporate capability, Neumo has successfully supported government services. Neumo was honored and recognized for four (4) consecutive years as a GovTech 100 Company representing the top 100 companies focused on making a difference in and selling to state and local government agencies across the United States.

Neumo is committed to helping communities thrive and brings a wealth of experience combined with innovation. Today, Neumo offers more administrative and financial support to government officials than any other organization. And with a responsive, client-focused approach, we foster partnerships that give our customers the certainty they need to accomplish more.

Neumo offers a competitive benefits and compensation package and are looking for team members who will thrive in our dynamic environment.

Neumo is an Equal Opportunity Employer. Selection for a position will be made without regard to race, religion, national origin, sex, political affiliation, marital status, non-disqualifying physical handicap, and age.