1

Grc Engineer Jobs (NOW HIRING)

GRC Engineer

Austin, TX · On-site

$150 - $200/hr

Automation & Engineering: Develop and implement automated solutions to improve GRC processes and operations, integrating with existing security, engineering, and AI tools. You will build modules and ...

About the role: We're looking for a Lead GRC Engineer to build the technical foundation of our security and compliance program as Higgsfield scales. This is not a traditional GRC role focused ...

Lead GRC Engineer

San Francisco, CA · On-site

$220K - $280K/yr

About the role: We're looking for a Lead GRC Engineer to build the technical foundation of our security and compliance program as Higgsfield scales. This is not a traditional GRC role focused ...

Lead GRC Engineer

San Francisco, CA · Remote

$220K - $280K/yr

About the role: We're looking for a Lead GRC Engineer to build the technical foundation of our security and compliance program as Higgsfield scales. This is not a traditional GRC role focused ...

MUST HAVE SKILLS: Data Governance, AI development and Governance, Security Risk Management The GRC Engineer will contribute to the development and operational execution of the program.

Cybersecurity GRC Engineer

New York, NY · On-site

$101K - $154K/yr

We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment. This role is ...

$80 - $100/hr

... GRC-Ansatzes mit Engineering-Fokus * Mitarbeit an der Automatisierung von GRC-Prozessen (z. B. Evidence Collection, Control Monitoring, Reporting) * Unterstützung bei der Übersetzung von Policies ...

As our GRC Engineer on the Platform Team, you'll own the controls, evidence, and processes that keep Taktile secure, compliant, and continuously audit-ready. You'll be the engineering-minded backbone ...

Get to know the GRC Engineering (GOV) Team Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment ...

Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... GRC goals. * Implement the development and oversight of required corrective action plans relating ...

Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... GRC goals. * Implement the development and oversight of required corrective action plans relating ...

We're looking for a Senior GRC Engineer to lead technical control implementation, own remediation work end to end, and improve how evidence is gathered and maintained across the business. You'll ...

GRC Engineer

San Mateo, CA · On-site

$200 - $250/hr

Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... • GRC goals. * Implement the development and oversight of required corrective action plans ...

Showing results 21-40

Grc Engineer information

See salary details

$59.5K

$111.6K

$203K

How much do grc engineer jobs pay per year?

As of Sep 9, 2026, the average yearly pay for grc engineer in the United States is $111,632.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,500.00 and $132,500.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Are GRC engineer jobs hard to get?

GRC (Governance, Risk, and Compliance) engineer jobs can be competitive, especially for entry-level positions, but having relevant skills in cybersecurity, risk management, and certifications like CISSP or CISA can improve chances. The difficulty of securing a GRC engineer role depends on experience, education, and the demand within the industry or organization. Strong knowledge of compliance frameworks and tools is often required to stand out.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions may be available but often require foundational skills, certifications, or internships in cybersecurity or IT governance.
More about Grc Engineer jobs

What cities are hiring for Grc Engineer jobs?

Cities with the most Grc Engineer job openings:

What states have the most Grc Engineer jobs?

States with the most job openings for Grc Engineer jobs include:

What are popular job titles related to Grc Engineer jobs?

For Grc Engineer jobs, the most frequently searched job titles are:

Infographic showing various Grc Engineer job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 92% Full Time, 3% Part Time, and 4% Contract. Highlights an 85% Physical, 4% Hybrid, and 11% Remote job distribution, with an average salary of $111,632 per year, or $53.7 per hour.

GRC Engineer

Austin, TX • On-site

$150 - $200/hr

Other

Posted 7 days ago


Job description

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.

At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a “normalized” problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.

Available Locations

Austin, TX

About the role

Security is at the heart of Cloudflare’s mission to help build a better Internet. Anytime we push code, it automatically affects the millions of Internet properties (powering websites, remote teams, APIs, mobile apps, etc.) running on our global network. Cloudflare’s network is one of the largest in the world, spanning over 330 cities in more than 125 countries, and operating within 50 milliseconds of 95% of the Internet-connected population.

The Security Governance, Risk and Compliance team (GRC) is a sub-team of Security. Our job is to make sure that Cloudflare has the right controls in place to secure our systems and customer data. We work cross-functionally with almost every team at Cloudflare to implement new controls, manage risk, and demonstrate our security posture to auditors and customers.

What you’ll do
  • Automation & Engineering:Develop and implement automated solutions to improve GRC processes and operations, integrating with existing security, engineering, and AI tools. You will build modules and maintain our GRC platform and other similar initiatives.
  • AI Governance:Architect and maintain a technical governance framework for the safe deployment of autonomous AI agents. This includes ensuring that agentic workflows operate within deterministic “action gates” and predefined risk thresholds.
  • Audit & Infrastructure:Support Cloudflare’s security assessments (e.g., SOC 2, ISO 27001, PCI DSS, FedRAMP). You will treat “Audit Readiness” as a product, ensuring our global edge network remains compliant through automated drift detection and self-healing configurations.
  • Security Integration:Work cross-functionally with Legal, People, Engineering, and Finance teams to integrate security into the fabric of the company, moving away from “gatekeeping” toward a paved-road security model where compliance is the default state for every developer.
Desirable Skills, Knowledge, and Experience:
  • Experience:Have 5+ years of experience in security, compliance, automation, or engineering functions in a fast-paced environment.
  • The Builder Mindset:You are a builder and enjoy building technical solutions to complex and messy problems. You’d rather write a script to solve a problem forever than manually check a box twice.
  • AI Mastery:Experience designing or implementing AI-powered automation and agentic workflows. You understand the unique risks of non-deterministic systems and how to govern them.
  • Compliance-as-Code:Deep experience with Infrastructure as Code (Terraform, Pulumi) and Policy as Code (OPA/Rego) implementation. You know how to enforce security guardrails before code is ever deployed.
  • The Motto:Driven by curiosity, anchored by empathy, and defined by a relentless ability to get things done. You seek to understand the “why,” support your peers, and ship high-quality outcomes.
Bonus Points:
  • Community & Passion:Demonstrated passion for security and software development, such as personal projects, open-source contributions, or active participation in the security research community.
  • Cloudflare Native:You’ve built something with our developer platform using our products (e.g.,Cloudflare Workers, R2, D1, or Workers AI). You understand our ecosystem because you’ve used it.
Equity

This role is eligible to participate in Cloudflare’s equity plan.

Project Galileo : Since 2014, we’ve equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers–at no cost.

Athenian Project : In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we’ve provided services to more than 425 local government election websites in 33 states.

1.1.1.1 : We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use – it is the first consumer-focused service Cloudflare has ever released. Here’s the deal – we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

#J-18808-Ljbffr