1

Grc Engineer Jobs (NOW HIRING)

Sr. GRC Engineer

New York, NY · On-site +1

$148K - $175K/yr

The Role The Governance Risk and Compliance Engineer role will be a core, individual contributor member of Ro's GRC team. The GRC team enables Ro to manage risk by vigorously assessing our operations ...

They are seeking a Staff GRC Engineer to enhance their governance, risk, compliance, and data security capabilities, focusing on building and automating security controls and ensuring effective ...

ezCater is looking for a Staff GRC Engineer to join the Security Engineering & Compliance team as a senior individual contributor who can help mature our governance, risk, compliance, and data ...

For restaurant partners, ezCater helps grow their business by bringing them new high-value customers and large orders. ezCater is looking for a Staff GRC Engineer to join the Security Engineering ...

Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... GRC goals. * Implement the development and oversight of required corrective action plans relating ...

Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... GRC goals. * Implement the development and oversight of required corrective action plans relating ...

Senior GRC Engineer Brex is the intelligent finance platform that enables companies to spend smarter and move faster in more than 200 markets. By combining global corporate cards and banking with ...

Senior GRC Engineer Brex is the intelligent finance platform that enables companies to spend smarter and move faster in more than 200 markets. By combining global corporate cards and banking with ...

New

We're hiring a Senior Security Engineer 1, GRC to join our Security Team. Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving ...

Senior GRC Engineer

$115K - $213K/yr

Build the cross-functional relationships that make GRC work in practice. Engineering, Legal, Privacy, Internal Audit and Procurement are all load-bearing parts of this program - own those ...

The Opportunity We are seeking a highly motivated and detail-oriented GRC Engineer I to join our fast-growing team. The ideal candidate will have a solid background in cybersecurity compliance ...

Job Summary We are seeking a skilled GRC Developer with expertise in Archer GRC platforms to join our dynamic team. The ideal candidate will be responsible for designing, customizing, and ...

next page

Showing results 1-20

Grc Engineer information

See salary details

$59.5K

$111.6K

$203K

How much do grc engineer jobs pay per year?

As of Jun 20, 2026, the average yearly pay for grc engineer in the United States is $111,632.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,500.00 and $132,500.00 per year, depending on experience, location, and employer.

What are GRC Engineers?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC Engineer, and why are they important?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What engineers make $500,000?

Senior engineers in specialized fields such as software engineering, data engineering, or cybersecurity can earn $500,000 or more annually, especially with extensive experience, advanced skills, and in high-demand industries. Executive or leadership roles like engineering managers or directors may also reach this compensation level. Achieving this often requires advanced certifications, a strong track record, and working in competitive or high-paying markets.

What are some common challenges faced by GRC Engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

Is GRC high paying?

GRC (Governance, Risk, and Compliance) engineers typically earn competitive salaries due to their specialized skills in security frameworks, compliance standards, and risk management. Salaries vary based on experience, certifications, and location, but overall, GRC roles are considered well-paying within cybersecurity careers.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

What does a GRC engineer do?

A GRC engineer specializes in Governance, Risk, and Compliance (GRC) processes within an organization. They implement and manage security policies, conduct risk assessments, and ensure compliance with industry standards and regulations, often using tools like GRC software. Strong knowledge of cybersecurity, regulatory frameworks, and relevant certifications are essential for this role.

What jobs make $10,000 a month without a degree?

GRC (Governance, Risk, and Compliance) engineers typically require specialized knowledge and certifications rather than a traditional degree. High-paying roles in cybersecurity, sales, or entrepreneurship can also reach or exceed $10,000 monthly through experience, skills, and certifications like CISSP or cloud platform credentials. These positions often demand technical expertise, industry experience, and sometimes remote or flexible work environments.
More about Grc Engineer jobs
What cities are hiring for Grc Engineer jobs? Cities with the most Grc Engineer job openings:
What states have the most Grc Engineer jobs? States with the most job openings for Grc Engineer jobs include:
Infographic showing various Grc Engineer job openings in the United States as of June 2026, with employment types broken down into 43% Full Time, and 57% Contract. Highlights an 71% In-person, and 29% Remote job distribution, with an average salary of $111,632 per year, or $53.7 per hour.
Sr. GRC Engineer

Sr. GRC Engineer

Ro

New York, NY • On-site, Remote

$148K - $175K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted yesterday


Job description

Join Tech @ Ro to build the future of healthcare, from the ground up!
At Ro, we believe that when people achieve their health goals, they can achieve their life goals. The highest-leverage way to move society forward is to give people their health, and the current healthcare system isn't built to do that. It was built to bill, not to serve patients.
We're building a new system. One where the patient is in control. One designed from scratch for the digital age.
At Ro, technology isn't just a function... It's core to how we deliver care. We've built a vertically integrated healthcare platform that connects telehealth, diagnostics, pharmacy, and logistics into a seamless, end-to-end experience for millions of patients.
...and we're just getting started.
As part of Tech @ Ro, you'll work on systems that operate at scale, with an opportunity to:
  • Solve complex, high-concurrency problems across a full-stack platform
  • Build and ship quickly with tight feedback loops and real-world impact
  • Own systems end-to-end, from architecture to production performance
  • Work alongside experienced operators, technical leaders, and clinicians
  • Help define how modern healthcare should be delivered

We're a performance-driven team with a strong sense of ownership and urgency. We move fast, learn quickly, and hold a high bar for what we build, and do so with a big heart - because patients depend on it.
If you're motivated by impact, scale, and the chance to help lead the patient revolution, come build with us.
The Role
The Governance Risk and Compliance Engineer role will be a core, individual contributor member of Ro's GRC team.
The GRC team enables Ro to manage risk by vigorously assessing our operations against leading compliance frameworks and standing legislation. This individual contributor role will be a key player in both leading our audit readiness program while driving continuous compliance using leading AI and automation platforms.
What You'll Do:
  • Serve as both a risk practitioner and automation engineer. Automate everything.
  • Own and maintain the compliance platform (Vanta), including control mapping, evidence collection, continuous monitoring, and audit workflows
  • Perform risk assessments, vendor security reviews, and control gap analyses, and track remediation through to completion
  • Manage control documentation, policies, procedures, and supporting artifacts across multiple compliance frameworks
  • Partner with Security, IT, Infrastructure, and Engineering teams to ensure technical and administrative controls align with documented policies and compliance requirements
  • Support internal and external audits (SOC 2, HIPAA, HITRUST)
  • Own and maintain the cyber risk register, collaborating with risk owners to quantify risks and develop remediation plans.
  • Develop and maintain risk reporting, metrics, and executive summaries with BI tools (Looker, Hex, etc)

What You'll Bring to the Team:
  • 5+ years of combined experience across governance, risk, compliance, security engineering, or adjacent technical roles, including hands-on experience working with compliance frameworks such as SOC 2, HIPAA, HITRUST, NIST, and PCI in modern, technology-driven environments.
  • 3+ years of experience with ongoing compliance operations, with demonstrated progression from manual evidence collection to automated, continuously monitored controls.
  • 2+ years of hands-on experience implementing and administering continuous compliance and evidence automation platforms (e.g., Vanta, Drata, SecureFrame), including configuring and creating custom integrations as well as optimizing automated evidence workflows.
  • Working knowledge of cloud computing platforms (AWS, Azure, GCP) and how their native services and configurations support security and compliance requirements.
  • Expertise in using Looker (or similar BI tool; HEX) to create dashboards, generate reports, and visualize GRC data for stakeholders, with a focus on simplifying complex data into actionable insights.
  • Ability to automate data ingestion, transformation, and reporting using scripting or programmatic approaches (e.g., Python, JavaScript, APIs, Tines.)
  • Strong analytical and root cause analysis skills
  • Kindness, and an ability to communicate to all levels of the organization

Bonus Points
  • Advanced GRC Automation & Engineering Mindset (custom automatons or workflows beyond out-of-the-box compliance tools)

We've Got You Covered:
  • Full medical, dental, and vision insurance + OneMedical membership
  • Healthcare and Dependent Care FSA
  • 401(k) with company match
  • Flexible PTO
  • Wellbeing + Learning & Growth reimbursements
  • Paid parental leave + Fertility benefits
  • Pet insurance
  • Student loan refinancing
  • Virtual resources for mindfulness, counseling, and fitness

The target base salary for this position ranges from $148,000 to $175,000, in addition to a competitive equity and benefits package (as applicable). When determining compensation, we analyze and carefully consider several factors, including location, job-related knowledge, skills and experience. These considerations may cause your compensation to vary.
Ro is consistently recognized as a top workplace in Health Care, in New York, and for Women and Parents-earning more than 20 honors from Fortune, Great Place to Work, and PEOPLE since 2021. In 2025 alone, we ranked top 5 among medium workplaces in Health Care and New York, and top 50 nationwide.
At Ro, we believe that our diverse perspectives are our biggest strengths - and that embracing them will create real change in healthcare. As an equal opportunity employer, we provide equal opportunity in all aspects of employment, including recruiting, hiring, compensation, training and promotion, termination, and any other terms and conditions of employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, familial status, age, disability and/or any other legally protected classification protected by federal, state, or local law.
Ro is committed to providing reasonable accommodations for qualified individuals with disabilities in our application and interview process. If you require a reasonable accommodation in the application or interview process, please contact us at [email protected].
See our California Privacy Policy here.
We may use automated tools, including artificial intelligence (AI), to assist with parts of our recruiting and hiring process, such as reviewing applications, evaluating resumes, and assessing responses or job-related qualifications. These tools are used to support our recruitment team and do not replace human judgment. Final hiring decisions are made by humans.