Jobs › Pennsylvania › Panama City › Senior GRC Engineer
Senior GRC Engineer
Align Technology is hiring for the job of Senior GRC Engineer, Panama City, Panama - In-Office Hybrid (On-site). This is a Governance job in the governance, risk, and compliance field. Review the full details below and apply directly with Align Technology.
About the Role
The Senior GRC Engineer owns audit evidence collection and technical control maintenance across A-LIGN s growing portfolio of compliance frameworks, including FedRAMP Moderate Equivalency, FedRAMP 20x, ISO 27001, ISO 42001, and SOC 2. This role bridges the GRC function and A-LIGN s technical teams, working hands-on in GCP, GitHub, and Microsoft 365 to collect evidence, verify controls, and keep A-LIGN continuously audit-ready. The Senior GRC Engineer works cross-functionally with every technical department in the company to reduce audit burden on engineering and IT while protecting the certifications that A-LIGN s clients and platforms depend on. The role also supports broader information security activities, including risk assessments, threat modeling, security reviews, and AI technical safeguards.
Reports to
Chief Information Security Officer
Pay Classification
Full-Time
Responsibilities
Own end-to-end audit evidence collection, validation, and organization across A-LIGN s compliance frameworks, including FedRAMP (Moderate Equivalency and FedRAMP 20x), ISO 27001, ISO 42001, SOC 2, NIST 800-53, and NIST 800-171
Maintain and continuously verify technical controls across A-LIGN s cloud and corporate environments, including Google Cloud Platform (GCP/GKE), GitHub, and Microsoft 365/Entra ID
Serve as the primary liaison between the GRC function and technical departments (IT, Engineering, DevOps) to gather evidence, validate control implementation, and reduce audit burden on those teams
Support FedRAMP continuous monitoring activities, including Key Security Indicator (KSI) evidence, vulnerability scan artifact collection, POA and M tracking, and assessor (3PAO) requests
Build and maintain evidence automation, including integrations between GRC tooling and source systems (identity provider, cloud platforms, code repositories, ticketing, endpoint management) to reduce manual collection effort
Support A-LIGN s ISO 42001 Artificial Intelligence Management System (AIMS), including AI risk register evidence, AI control monitoring, and nonconformity remediation tracking
Prepare audit-ready evidence packages and coordinate directly with external assessors and certification bodies during assessment windows
Monitor control health between audit cycles, identify control drift or failures, and drive remediation with control owners before findings occur
Maintain compliance documentation, including control narratives, policies, and procedures
Support supplier and vendor security reviews with framework-specific evidence requirements
Track framework changes (FedRAMP 20x requirements, ISO standard revisions, SOC 2 criteria updates) and translate them into actionable control and evidence updates
Conduct security risk assessments and contribute to A-LIGN s corporate risk management program and risk register
Participate in threat modeling for A-SCEND features, internal systems, and AI use cases, and translate findings into control improvements
Perform security reviews of new tools, vendors, and internal initiatives, including support for Vendor Review Board activities
Implement and validate AI technical controls and safeguards, including data loss prevention, AI connector and agent governance, and acceptable use enforcement, in support of A-LIGN s AI Management System
Report compliance posture, evidence status, and audit readiness metrics to the CISO and GRC leadership
Minimum Qualifications
EDUCATION
Bachelor s degree in information systems, cybersecurity, business, or equivalent combination of education and experience
EXPERIENCE
5+ years of experience in information security, GRC, IT audit, or compliance engineering roles
Hands-on experience with audit evidence collection and technical control validation for at least two of the following: FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171
DevSecOps or cloud engineering experience sufficient to independently locate and extract evidence from GCP, GitHub, and Microsoft 365/Entra ID environments
Experience with GRC platforms and evidence automation (AuditBoard, Vanta, Drata, or similar)
Experience supporting external audits and assessor interactions, including 3PAO assessments
Working knowledge of vulnerability management, CI/CD pipelines, infrastructure-as-code, and identity and access management concepts
Experience scripting or automating evidence collection (Python, PowerShell, or similar) preferred
Familiarity with risk assessment methodologies, threat modeling (e.g., STRIDE), and security review processes preferred
CERTIFICATIONS
CISA, CISSP, CCSK/CCSP, ISO Lead Auditor/Implementer, or relevant certifications preferred but not required
SKILLS
Strong cross-functional collaboration and project management skills
Ability to translate framework requirements into clear, actionable requests for technical teams
Highly organized with the ability to manage evidence deadlines across multiple concurrent audit cycles
Excellent written communication for control narratives, evidence descriptions, and assessor responses
Self-directed with strong follow-through in a fast-paced, deadline-driven environment
Proven experience utilizing AI tools to automate manual tasks, streamline workflows, and increase team efficiency
Experience operating in PE-backed or high-growth environments preferred
Benefits
Employer Paid Life and Health Insurance
Competitive Bonus Structure
Home Office Reimbursement
Technology Allowance
Certification Reimbursement
BeneficiaT Discount Loyalty Program
Personalized Career Coaching
Generous Paid Time Off
Paid Office Closure December 25-January 1
Summer Hours
About A-LIGN
A-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor. To learn more, visit a-lign.com.
Come Work for A-LIGN!
Apply online today at A-LIGN.com and learn about life at A-LIGN by following us on strong a LinkedIn.
A-LIGN is an Equal Opportunity Employer.
Certifications this role asks for
Studying for one of these? Try the free CISA practice questions in our academy. No signup, no cost.
Location and market context
This job is based in Panama City on-site. Local candidates benefit from being close to Align Technology's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About governance jobs
Governance jobs design the structures, policies, and oversight that keep complex programs accountable, coordinating across legal, risk, compliance, and technology. Jobs like this one are typically evaluated against frameworks such as governance frameworks, policy standards, and oversight and reporting practices.
How to position yourself for this governance job
Strong candidates emphasize policy and standard-setting, committee and stakeholder coordination, oversight reporting, and translating strategy into durable operating structures. In your resume and outreach, tie your experience to how Align Technology would apply governance frameworks, policy standards, and oversight and reporting practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- Staff Security Governance Engineer, Policies & Standards · Gitlab · Remote
- Global Sanctions Advisory Oversight Specialist - Vice President · Deutsche Bank · 2 Locations
- Senior KYC Analyst, Onboarding Operations, EMEA · Airwallex · Vilnius, LT
- Lead Analyst, Financial Crimes · Chime · Chicago, IL
- Operations Associate, Sanctions · Stripe · Bengaluru
- Regulatory Control Analyst, NCT · Deutsche Bank · Bangalore, Velankani Tech Park
- Senior Anti Financial Crime Officer · Deutsche Bank · Geneva Place des Bergues 3
- Due Diligence Implementation Analyst (KYC) · Deutsche Bank · Luxembourg 2 Blvd K. Adenauer
Hiring for Governance?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Senior GRC Engineer in Panama City, Panama - In-Office Hybrid open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.