Jobs › GRC Engineering
GRC Engineering Jobs
Open GRC Engineering jobs across governance, risk, and compliance, refreshed continuously.
GRC engineering is the part of governance that ships. Instead of a control living in a spreadsheet and an auditor asking for screenshots every quarter, a GRC engineer writes the control into the pipeline, collects the evidence automatically, and turns the audit into a query somebody can run on demand.
Open GRC Engineering jobs (24)
Staff Security Governance Engineer, Policies & Standards
Senior GRC Engineer
Staff Software Engineer - AI Governance
AI Governance Engineer
Senior Security Risk Engineer
Security GRC Engineer
Sr. GRC Engineer
Multi-Cloud Security & Compliance Engineer
Insider Risk Security Engineer
Senior Staff Software Engineer - AI Governance
Lead Security Compliance Engineer
Senior Risk & Governance Engineer
Compliance Engineering Lead
Staff Identity Governance and Access Engineer
Security Compliance, GRC Engineer
Senior Staff DevOps Engineer — Data Discovery & AI Governance
Senior Manager, Information Compliance, AI Governance & Privacy
GRC Engineer
AI Governance Engineer
AI Governance Engineer
Software Engineer, Privacy Engineering
Staff Software Engineer - Data Governance
Tech Governance - Security Compliance Engineer
Staff Security Engineer - Identity Risk & Governance
The title has not settled yet. The same job gets posted as GRC Engineer, Security Compliance Engineer, Compliance Engineering Lead, Governance Engineer, Privacy Engineer, and sometimes as a plain Software Engineer who happens to sit on a governance team. Read the requirements rather than the title, because the pay and the seniority vary more than the words do.
Who hires for it: companies carrying SOC 2 and ISO 27001 obligations at a scale where manual evidence stopped working, fintechs under examination, and AI companies now answering to ISO/IEC 42001 and the EU AI Act. The roles on this page come from that mix.
GRC Engineering jobs: what the market looks like right now
A snapshot built from the 24 GRC Engineering roles currently on this page.
What these roles pay
Of the 24 open GRC Engineering roles on this page, 8 publish a salary range. Across those:
- Median advertised midpoint: $147k
- Middle half of the market: $140k to $155k
- Full advertised range: $133k to $193k
Computed from the live postings on this page, not from survey data, and recalculated every time the board refreshes. Roles without a published range are excluded.
Where the work is
- Work mode: 4 remote, 3 hybrid, 17 on-site or unstated.
- Seniority mix: mid (15), senior (9)
- Employers hiring more than one: OneTrust (3), Gitlab (2), Dalio Family Office (2)
Skills these postings ask for
- board and committee reporting
- policy lifecycle ownership
- risk appetite and tolerance setting
- three-lines-of-defense operating models
- ISO/IEC 42001 and NIST AI RMF fluency
How to get a governance job — the full career guide for this field: entry routes, transferable backgrounds, certifications and salary by level.
Certifications that come up most
None of these are universally required, but they appear often enough in GRC Engineering postings to be worth knowing: CGEIT, CRISC, AIGP, CISA. The certification academy covers what each one actually tests and who it is for.
GRC Engineering jobs: tools, skills and workflows
What does a GRC engineer actually do?
Turns written control requirements into working software. That means infrastructure as code with the control built in, automated evidence collection so nobody is taking screenshots the week before an audit, continuous checks that fail loudly when a configuration drifts, and the tooling that maps one piece of evidence to the several frameworks that ask for it.
How is it different from a security engineering job?
A security engineer is measured on whether the system is safe. A GRC engineer is measured on whether you can prove it, to an auditor, a regulator or a customer's procurement team, without a manual scramble. The skills overlap heavily. The job is the proof.
What do employers test for?
Infrastructure as code, usually Terraform. Policy as code. Enough scripting to automate evidence out of cloud APIs. And the one that separates candidates: read a control objective out loud and say what evidence would genuinely satisfy it. Most people who come from pure security engineering have never had to answer that.
Do you need a certification?
No, and most of these postings do not ask for one. ISO 27001 and SOC 2 familiarity is assumed rather than certified. If you are moving across from a non-technical compliance seat, the engineering skills are the gap to close, not the credential.
Where does it lead?
Two directions. Deeper into platform and security engineering, or up into GRC leadership, where the person who automated the control program is the obvious candidate to run it. The AI governance side is pulling engineers in fast, because ISO/IEC 42001 and the EU AI Act ask for evidence that nobody can produce by hand.
Related engineering and governance roles
GRC engineering sits between the people who build controls and the people who attest to them. These hubs draw from the same candidates:
- Cybersecurity compliance jobs and SOC 2 jobs, the control frameworks most of this work automates.
- ISO 27001 jobs and ISO 42001 jobs, the management-system standards behind the evidence.
- Privacy jobs, where privacy engineering is the same discipline pointed at personal data.
- Data governance jobs, the lineage and quality work these controls depend on.
- AI governance jobs and AI GRC jobs, where the same automation is being asked for against models.
- GRC analyst jobs and GRC leadership jobs, the seats either side of this one.
Mapping the path rather than applying today? The career guides lay out how people reach these roles, and the certification academy has free practice exams on the frameworks named above.
Hiring for GRC Engineering?
We have 24 open GRC Engineering roles on the board right now. Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Cybersecurity compliance jobs · AI governance jobs · All GRC jobs · Job alerts