Role Overview ButterflyMX is seeking a GRC Engineer who is equal parts practitioner and builder. You will own the governance, risk, and compliance program. But more importantly, you will re-engineer ...
Role Overview ButterflyMX is seeking a GRC Engineer who is equal parts practitioner and builder. You will own the governance, risk, and compliance program. But more importantly, you will re-engineer ...
Senior Director - GRC Engineer
Indianapolis, IN · On-site
$101K - $138K/yr
The GRC Engineer bridges the gap between what regulatory and policy obligations require, and how those obligations are implemented as operational controls by business control owners across the ...
Senior Director - GRC Engineer
Indianapolis, IN · On-site
$101K - $138K/yr
The GRC Engineer bridges the gap between what regulatory and policy obligations require, and how those obligations are implemented as operational controls by business control owners across the ...
GRC Engineer at San Jose CA
San Jose, CA · On-site
GRC Engineer Location: San Jose CA Duration: 6 Months 100% Onsite- ** LOCAL CANDIDATES ONLY** Seeking a hands-on GRC Engineer with expertise in Python, API development, and modern architectures ...
Quick apply
GRC Engineer at San Jose CA
San Jose, CA · On-site
GRC Engineer Location: San Jose CA Duration: 6 Months 100% Onsite- ** LOCAL CANDIDATES ONLY** Seeking a hands-on GRC Engineer with expertise in Python, API development, and modern architectures ...
Senior GRC Engineer
San Francisco, CA · On-site
$180K - $200K/yr
We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills to build and scale automation across governance, risk, and compliance. This is a hands-on technical role ...
Senior GRC Engineer
San Francisco, CA · On-site
$180K - $200K/yr
We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills to build and scale automation across governance, risk, and compliance. This is a hands-on technical role ...
Cybersecurity GRC Engineer
Manhattan, NY · On-site
$110 - $160/hr
We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment.This role is ...
Cybersecurity GRC Engineer
Manhattan, NY · On-site
$110 - $160/hr
We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment.This role is ...
GRC Engineer
Chicago, IL · On-site +1
$130K - $145K/yr
What you'll do: We're looking for a mid-level GRC Engineer to help us scale our compliance program through automation and run audits across SOC 2, ISO 27001, and SOX. This is a hands-on, technical ...
GRC Engineer
Chicago, IL · On-site +1
$130K - $145K/yr
What you'll do: We're looking for a mid-level GRC Engineer to help us scale our compliance program through automation and run audits across SOC 2, ISO 27001, and SOX. This is a hands-on, technical ...
Staff GRC Engineer
San Francisco, CA · On-site
About the Role As the Staff GRC Engineer, you will report to the Lead of Security and be the first dedicated hire establishing Kikoff's Trust & Assurance function within Security. You will own the ...
Staff GRC Engineer
San Francisco, CA · On-site
About the Role As the Staff GRC Engineer, you will report to the Lead of Security and be the first dedicated hire establishing Kikoff's Trust & Assurance function within Security. You will own the ...
Cybersecurity GRC Engineer
New York, NY · On-site
$99K - $150K/yr
We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment. This role is ...
Cybersecurity GRC Engineer
New York, NY · On-site
$99K - $150K/yr
We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment. This role is ...
Security (GRC) Engineer
San Jose, CA · On-site
MUST HAVE SKILLS: Data Governance, AI development and Governance, Security Risk Management The GRC Engineer will contribute to the development and operational execution of the program.
Security (GRC) Engineer
San Jose, CA · On-site
MUST HAVE SKILLS: Data Governance, AI development and Governance, Security Risk Management The GRC Engineer will contribute to the development and operational execution of the program.
Senior Cyber Security & GRC Engineer
Hartford, CT · On-site
$140 - $180/hr
Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations.
Senior Cyber Security & GRC Engineer
Hartford, CT · On-site
$140 - $180/hr
Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations.
Staff GRC Engineer
San Francisco, CA · On-site
$260K - $304K/yr
About the Role As the Staff GRC Engineer, you will report to the Lead of Security and be the first dedicated hire establishing Kikoff's Trust & Assurance function within Security. You will own the ...
Staff GRC Engineer
San Francisco, CA · On-site
$260K - $304K/yr
About the Role As the Staff GRC Engineer, you will report to the Lead of Security and be the first dedicated hire establishing Kikoff's Trust & Assurance function within Security. You will own the ...
GRC Engineer
San Mateo, CA · On-site
Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... GRC goals. * Implement the development and oversight of required corrective action plans relating ...
GRC Engineer
San Mateo, CA · On-site
Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... GRC goals. * Implement the development and oversight of required corrective action plans relating ...
Cybersecurity GRC Engineer
Manhattan, NY · On-site
$99K - $150K/yr
We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment. This role is ...
Cybersecurity GRC Engineer
Manhattan, NY · On-site
$99K - $150K/yr
We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment. This role is ...
Senior Cyber Security & GRC Engineer
Hartford, CT · On-site
$130 - $180/hr
Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations.
Senior Cyber Security & GRC Engineer
Hartford, CT · On-site
$130 - $180/hr
Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations.
Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... GRC goals. * Implement the development and oversight of required corrective action plans relating ...
Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... GRC goals. * Implement the development and oversight of required corrective action plans relating ...
Senior Cyber Security & GRC Engineer
Hartford, CT · On-site
$150K - $170K/yr
Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations.
Senior Cyber Security & GRC Engineer
Hartford, CT · On-site
$150K - $170K/yr
Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations.
Senior Cyber Security & GRC Engineer
Hartford, CT · On-site
$107K - $145K/yr
Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations.
Senior Cyber Security & GRC Engineer
Hartford, CT · On-site
$107K - $145K/yr
Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations.
Senior GRC Engineer, Trust
Manhattan, NY · On-site
$140 - $190/hr
Role Summary We re looking for a Senior GRC Engineer to lead technical control implementation, own remediation work end to end, and improve how evidence is gathered and maintained across the business.
Senior GRC Engineer, Trust
Manhattan, NY · On-site
$140 - $190/hr
Role Summary We re looking for a Senior GRC Engineer to lead technical control implementation, own remediation work end to end, and improve how evidence is gathered and maintained across the business.
SAP Security & GRC Engineer (S/4HANA & Fiori) C2C jobs Dearborn, MI
Dearborn, MI · On-site
$120 - $180/hr
Senior SAP Security & GRC Engineer (S/4HANA & Fiori) Location:Dearborn, MI (Hybrid) Duration: Long Term Overview We are seeking an experienced SAP Security & GRC Engineer with expertise in SAP S ...
SAP Security & GRC Engineer (S/4HANA & Fiori) C2C jobs Dearborn, MI
Dearborn, MI · On-site
$120 - $180/hr
Senior SAP Security & GRC Engineer (S/4HANA & Fiori) Location:Dearborn, MI (Hybrid) Duration: Long Term Overview We are seeking an experienced SAP Security & GRC Engineer with expertise in SAP S ...
Senior Cyber Security & GRC Engineer
Houston, TX · On-site
$120 - $160/hr
Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations.
Senior Cyber Security & GRC Engineer
Houston, TX · On-site
$120 - $160/hr
Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations.
Grc Engineer information
See salary details
$59.5K - $72.5K
14% of jobs
$80.3K is the 25th percentile. Wages below this are outliers.
$72.5K - $85.6K
19% of jobs
$85.6K - $98.6K
12% of jobs
The median wage is $103.1K / yr.
$98.6K - $111.7K
17% of jobs
$111.7K - $124.7K
12% of jobs
$127K is the 75th percentile. Wages above this are outliers.
$124.7K - $137.8K
14% of jobs
$137.8K - $150.8K
7% of jobs
$150.8K - $163.9K
3% of jobs
$163.9K - $176.9K
0% of jobs
$176.9K - $190K
1% of jobs
$190K - $203K
2% of jobs
$59.5K
$111.6K
$203K
How much do grc engineer jobs pay per year?
What is a GRC engineer?
What are the key skills and qualifications needed to thrive as a GRC engineer?
What are some common challenges faced by GRC engineers when implementing new compliance frameworks?
What is the difference between Grc Engineer vs Security Analyst?
| Aspect | Grc Engineer | Security Analyst |
|---|---|---|
| Certifications | ISO 27001, CISSP, CISA | CISSP, CompTIA Security+ |
| Work Environment | Policy development, compliance, risk management | Monitoring, incident response, threat analysis |
| Industry Usage | Corporate governance, compliance teams | Security operations centers, IT departments |
Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.
Are GRC engineer jobs hard to get?
How much do GRC engineers make?
Is GRC engineer an entry-level job?
What cities are hiring for Grc Engineer jobs?
Cities with the most Grc Engineer job openings:
What states have the most Grc Engineer jobs?
States with the most job openings for Grc Engineer jobs include:
What job categories do people searching Grc Engineer jobs look for?
The top searched job categories for Grc Engineer jobs are:

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 10 days ago
Job description
ButterflyMX is on a mission to empower people to open and manage doors & gates from a smartphone. Our products are installed in more than 20,000+ multifamily, commercial, gated communities, and student-housing properties worldwide, including properties developed, owned, and managed by the most trusted names in real estate. Our features are designed for developers, owners, property managers, and tenants and our products lower operating costs and improve tenant satisfaction.
Our Solution
Developers and owners no longer need to run building wiring or install in-unit hardware. Property managers can grant building access, revoke permissions, and review entry logs from an online dashboard. Residents can open doors from their smartphones, issue visitor access, and see who is trying to enter the building.
Our Culture & Values
Fantastic people are the key to our success. As a distributed, primarily remote workforce, we're looking for more intelligent, passionate, collaborative, ai-forward, and down-to-earth individuals to join our growing team. We're driven by a shared commitment to excellence and innovation, grounded in our core values: We delight our customers, We take ownership, We are a community of collaborators, We speak up, We think big and do small, and We are tenacious.
Role Overview
ButterflyMX is seeking a GRC Engineer who is equal parts practitioner and builder. You will own the governance, risk, and compliance program. But more importantly, you will re-engineer how that program operates: replacing manual, point-in-time processes with AI-assisted, automated, and agentic workflows wherever possible. From continuous controls monitoring to automated vendor risk intake to AI-accelerated policy drafting, you will design a GRC function built for scale.
This is a generalist role that spans the full GRC surface: compliance operations, risk management, audit management, trust and assurance, vendor/supply chain risk, and operational privacy support. You will own the day-to-day operations of our compliance posture: managing audit readiness, maintaining our risk register, driving policy development, coordinating vendor risk assessments, and building sustainable processes through engineering automations.
You are equally comfortable automating a controls evidence request (not just handing it to the control owner!); conducting a supply chain risk analysis (software, firmware, hardware); and building automations and workflows to reduce compliance and documentation burdens. It is an individual contributor position reporting directly to the CISO to build and sustain our governance, risk, and compliance program.
Responsibilities
- Own and continuously mature the company risk register; design a risk management workflow that uses AI tooling to surface, score, and route emerging risks with minimal manual intervention, ensuring the register reflects real-time posture, not a quarterly snapshot.
- Lead external audit management (SOC 2 Type II); automate evidence collection pipelines in Vanta so that audit cycles are driven by continuous monitoring rather than evidence sprints, and begin scoping a readiness path for ISO 42001 (AI management systems).
- Engineer the Trust and Assurance program for scale: build automated intake and triage workflows for security questionnaire requests, deploy AI-assisted response generation against a curated knowledge base, and expand the trust portal so that partner due diligence is largely self-service.
- Build a vendor and supply chain risk program that goes beyond static spreadsheets. Design automated vendor intake, tiered risk scoring, and continuous monitoring triggers (news alerts, rating service integrations, release notes, expiration tracking) that surface risk without requiring manual sweeps.
- Redesign and maintain security and privacy policies; use AI to draft, version, and track policy updates, and build a lightweight workflow for owner review, approval, and attestation that doesn't require a ticketing system to chase people down.
- Own common controls monitoring in Vanta. Configure and tune integrations, checks, and alerting so that control failures surface automatically to the right owners, not just to a GRC inbox. Drive the organization toward an always-on compliance posture.
- Modernize the security awareness and training program.
- Design and operationalize an integrated compliance calendar covering SOC 2, security and IT systems licensing renewals, applicable state privacy regulations, and any other active frameworks with automated reminders and status tracking rather than manual coordination.
- Support the CISO and General Counsel on operational privacy practices: administer cookie consent management tooling, handle or route data subject requests (DSRs) through a documented and auditable workflow, and help maintain the company's privacy notice and data mapping inventory.
- Monitor the regulatory and compliance landscape, including AI governance developments (EU AI Act, NIST AI RMF, ISO 42001). Proactively surface changes that require a policy, control, or product response.
- Leverage AI tools across every GRC workflow; this role is expected to demonstrate measurable efficiency gains through automation and tooling, not simply to own a portfolio of manual processes.
Requirements
- 3+ years of experience in GRC, information security compliance, or risk management.
- Working knowledge of SOC 2 (Trust Services Criteria), with hands-on experience supporting or leading audits.
- Familiarity with additional frameworks is a strong plus: CIS Controls v8, NIST CSF, NIST AI RMF, NIST Privacy Framework, NIST SP 1800 series, NIST 800-53 r5, ISO 42001, ISO 27701, ISO 27001, OWASP Top 10 for Agentic Applications, MITRE D3FEND, MITRE SoT, MITRE ALTAS.
- Experience conducting rapid third-party/vendor risk assessments and managing a supply chain risk program.
- Strong organizational skills with the ability to manage multiple concurrent workstreams and deadlines.
- Excellent written communication, capable of drafting clear, audience-appropriate policy documents and executive risk summaries.
- Experience with Vanta platform (or equivalent).
- Relevant certifications a plus: CISA, CRISC, CISSP, CIPP, or equivalent.
- Proven experience with leveraging AI tools in both professional and personal settings. ButterflyMX is an AI-forward organization and the ability to optimize efficiency using AI is crucial in every role.
The expected base salary range for this position is $130,000-$170,000. Actual compensation will depend on factors including budget, skills, experience, location, and internal equity. This position may also be eligible for bonuses, equity, or other forms of compensation, where applicable.
Benefits
- Comprehensive Medical, Dental and Vision plans (ButterflyMX covers 80% of the cost) starting day 1
- 401(k) plan with a match
- 10 paid holidays, 20 vacation days, 5 sick days, 3 floating holidays
- Basic Life and Accidental Death and Dismemberment Insurance (ButterflyMX covers 100% of the cost)
- Short and Long Term Disability (ButterflyMX covers 100% of the cost)
- Paid Family Leave
- Employee Assistance Program
- Quarterly self-care stipends
- Access to optional benefits including pre-tax flexible healthcare spending accounts (FSA and HSA), Dependent Care FSA, and Commuter Benefits, as well as optional Supplemental Life, AD&D, Hospital Indemnity, Legal, Accident, Critical Illness, Pet, and Personal Liability Insurance
- And more!
ButterflyMX is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. You must have the authorization to work in the US to become an employee. We strive to create an accessible and inclusive experience for all candidates and employees. If you need reasonable accommodations during the application or the recruiting process, please let our recruiting team know.
About ButterflyMX
Sourced by ZipRecruiter
Industry
Software development
Company size
11 - 50 Employees
Headquarters location
NY, US
Year founded
2014