GRC Engineer

Hampton North All jobs
12 hour(s) ago
Job Overview
Company Hampton North
Job Type Full-time
Job Level mid-senior
Category Information Technology
Posted 2026-08-28
Last Seen 12 hour(s) ago

Job Description

GRC Consultant You will run SOC 2 and ISO 27001 programs for a diverse client base owning control implementation and audit readiness from kickoff through external audit. Much of the work is hands-on in client cloud environments assessing AWS and Azure against control requirements hardening what falls short and building evidence that holds up under audit. A multi-year SOC 2 program supports a client expanding through M&A with room to grow into GRC engineering and automation as the practice scales.

Compensation

$160000 to $180000

Logistics

Remote Here's

what you'll be doing

Lead SOC 2 scope expansions and stand up ISO 27001 ISMS programs from scratch for clients

  • Assess AWS and Azure environments against compliance controls and flag gaps in configuration identity and cloud posture
  • Harden client systems and cloud infrastructure run enterprise patch management and drive vulnerability remediation to resolution
  • Operate GRC automation platforms such as Drata Vanta and Secureframe to run evidence collection and audit prep
  • Write scripts to automate evidence collection control checks and routine security tasks
  • Interpret framework and regulatory requirements and build them into client systems platforms and workflows as controls
  • Run audit readiness end to end walkthroughs with control owners evidence collection readiness timelines and coordination with external auditors
  • Build and maintain control mappings and crosswalks across SOC 2 ISO 27001 CMMC and NIST 800-171
  • Author and maintain compliance policies procedures and accreditation documentation including SSPs POA&Ms DR plans and IR plans
  • Automate compliance and audit workflows with integrations APIs and AI tooling
  • Perform third-party and vendor risk assessments maintain security questionnaires and mature the third-party risk framework
  • Report compliance and risk maturity to executives through metrics and crosswalks
  • Facilitate incident response tabletop exercises and maintain runbooks and playbooks
  • Evaluate new security products and support proof of concept implementations And what you need to have
  • Professional auditing experience
  • Hands-on experience leading SOC 2 scope expansions and standing up ISO 27001 ISMS programs from scratch
  • Hands-on experience assessing and hardening AWS and Azure environments against compliance controls
  • Fluency with GRC automation platforms Drata Vanta Secureframe
  • Scripting ability to automate evidence collection and security tasks
  • A habit of tracking regulatory trends executive orders and framework updates before clients ask Bonus points for
  • CMMC implementation experience
  • NIST 800-171 experience
  • Microsoft GCC High experience No CTC or sponsorship at this time.

Unlock: Sign Up for free / Sign In and use the searches from your home page or the links in the footer.