1

Grc Engineer Jobs (NOW HIRING)

GRC Engineer

Chicago, IL · On-site +1

$130K - $145K/yr

What you'll do: We're looking for a mid-level GRC Engineer to help us scale our compliance program through automation and run audits across SOC 2, ISO 27001, and SOX. This is a hands-on, technical ...

About the Role As the Staff GRC Engineer, you will report to the Lead of Security and be the first dedicated hire establishing Kikoff's Trust & Assurance function within Security. You will own the ...

MUST HAVE SKILLS: Data Governance, AI development and Governance, Security Risk Management The GRC Engineer will contribute to the development and operational execution of the program.

Cybersecurity GRC Engineer

New York, NY · On-site

$99K - $150K/yr

We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment. This role is ...

Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... GRC goals. * Implement the development and oversight of required corrective action plans relating ...

Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... GRC goals. * Implement the development and oversight of required corrective action plans relating ...

We're looking for a Senior GRC Engineer to lead technical control implementation, own remediation work end to end, and improve how evidence is gathered and maintained across the business. You'll ...

Work cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on ... GRC goals. * Implement the development and oversight of required corrective action plans relating ...

Get to know the GRC Engineering (GOV) Team Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment ...

We're looking for a Senior GRC Engineer to lead technical control implementation, own remediation work end to end, and improve how evidence is gathered and maintained across the business. You'll ...

Showing results 21-40

Grc Engineer information

See salary details

$59.5K

$111.6K

$203K

How much do grc engineer jobs pay per year?

As of Aug 25, 2026, the average yearly pay for grc engineer in the United States is $111,632.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,500.00 and $132,500.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Are GRC engineer jobs hard to get?

GRC (Governance, Risk, and Compliance) engineer jobs can be competitive, especially for entry-level positions, but having relevant skills in cybersecurity, risk management, and certifications like CISSP or CISA can improve chances. The difficulty of securing a GRC engineer role depends on experience, education, and the demand within the industry or organization. Strong knowledge of compliance frameworks and tools is often required to stand out.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions may be available but often require foundational skills, certifications, or internships in cybersecurity or IT governance.
More about Grc Engineer jobs

What cities are hiring for Grc Engineer jobs?

Cities with the most Grc Engineer job openings:

What states have the most Grc Engineer jobs?

States with the most job openings for Grc Engineer jobs include:

Infographic showing various Grc Engineer job openings in the United States as of August 2026, with employment types broken down into 100% Contract. Highlights an 100% In-person job distribution, with an average salary of $111,632 per year, or $53.7 per hour.

GRC Engineer

Chicago, IL • On-site, Remote

$130K - $145K/yr

Full-time

Retirement, PTO

Re-posted 24 days ago


Job description

What you'll do:

We're looking for a mid-level GRC Engineer to help us scale our compliance program through automation and run audits across SOC 2, ISO 27001, and SOX. This is a hands-on, technical role where you'll spend as much time writing code and integrating systems as you do reviewing controls. You'll serve as the bridge between Security, Engineering, and the business by transforming manual, evidence-heavy compliance work into automated, repeatable processes while helping leadership understand and prioritize risk.

This role is ideal for someone with GRC or security experience who wants to move beyond spreadsheets and checklists into building the tooling that makes a compliance program efficient, scalable, and audit-ready year-round.

In this role you will:

Automation & Tooling

  • Build and maintain automation for continuous control monitoring, evidence collection, and audit readiness through scripts, APIs, and GRC platform integrations
  • Integrate compliance workflows with cloud providers, identity systems, ticketing platforms, and CI/CD pipelines to automatically collect control data and evidence
  • Reduce manual compliance work by codifying control checks and pulling evidence directly from source systems
  • Develop dashboards and reporting that provide stakeholders with real-time visibility into control health and audit readiness

Audits & Frameworks

  • Run and coordinate audits for SOC 2 (Type I and Type II), ISO 27001, and SOX, including scoping, evidence collection, control walkthroughs, and auditor coordination
  • Map controls across multiple compliance frameworks to reduce duplication and maintain a unified control library
  • Track audit findings and control gaps through remediation and closure with business and technical stakeholders
  • Maintain audit-ready documentation including policies, procedures, control narratives, and evidence repositories

Risk Management

  • Identify, assess, and document organizational risks while maintaining the enterprise risk register
  • Support risk assessments, including likelihood and impact scoring, treatment planning, and remediation tracking
  • Partner with Engineering and IT to evaluate the control impact of new systems, vendors, and architectural changes
  • Contribute to the third-party risk management program

Cross-Functional Partnership

  • Partner with control owners to ensure controls are operating effectively and generating appropriate evidence
  • Translate compliance requirements into practical, engineering-focused guidance
  • Support customer security questionnaires, trust requests, and due diligence activities
What you'll need:
  • 3-5 years of experience in GRC, IT audit, security compliance, or a related field
  • Hands-on experience supporting or leading audits for SOC 2, ISO 27001, SOX, or a comparable framework
  • Working knowledge of SOC 2 Trust Services Criteria, ISO 27001 Annex A, COSO/SOX ITGCs, NIST, or similar control frameworks
  • Experience with scripting and automation using Python or a similar language, including working with REST APIs to automate evidence collection
  • Familiarity with at least one major cloud platform (AWS, GCP, or Azure) and its security and logging services
  • Strong understanding of access management, change management, logging and monitoring, vulnerability management, and SDLC controls
  • Excellent written communication skills with the ability to create clear control documentation, risk assessments, and stakeholder reporting
  • Ability to manage multiple priorities while driving audit findings and remediation efforts to completion
Bonus points for:
  • Experience with Infrastructure as Code (Terraform) and CI/CD pipeline security
  • Exposure to SOX ITGC testing within a public company or pre-IPO environment
  • Experience using SQL or data analysis for evidence collection and control sampling
  • Certifications such as CISA, CISSP, CCSK, ISO 27001 Lead Implementer or Lead Auditor, or cloud security certifications
  • Experience working directly with external auditors and managing audit timelines
Compensation:

The salary range for this role will be $130,000.00 - $145,000.00 USD. In addition, this position will also receive an annual target bonus of 10%. Bonus pay at NinjaTrader is based on individual performance (50%) as well as company/team performance (50%).

Salary and bonus earnings are only two components of the total compensation package offered by NinjaTrader. NinjaTrader offers a 401K plan through ADP under which the company will match up to 3.5% of employee contributions. Annual paid time off allowance accrues at a rate of 18 days per year (some positions may qualify for more) plus seven paid holidays.

Location:

This role is based in Chicago, IL. We are not open to remote candidates for this role.

Hybrid:

For Chicago-based employees, we follow a hybrid work schedule: In-office Tuesday through Thursday, with remote work on Mondays and Fridays. In addition to these weekly remote days, we offer:

  • 20 additional flex remote days annually
  • 5 Company Wide Office-Optional weeks tied to major holidays