{"schemaVersion":"jobsearcher.job.v1","id":"c3703598dfd6359e9066b2cd","url":"https://jobsearcher.com/jobs/c3703598dfd6359e9066b2cd","canonicalUrl":"https://jobsearcher.com/jobs/c3703598dfd6359e9066b2cd","title":"Senior GRC Engineer","description":"About The RoleThe Senior GRC Engineer owns audit evidence collection and technical control maintenance across A-LIGN's growing portfolio of compliance frameworks, including FedRAMP Moderate Equivalency, FedRAMP 20x, ISO 27001, ISO 42001, and SOC 2. This role bridges the GRC function and A-LIGN's technical teams, working hands-on in GCP, GitHub, and Microsoft 365 to collect evidence, verify controls, and keep A-LIGN continuously audit-ready. The Senior GRC Engineer works cross-functionally with every technical department in the company to reduce audit burden on engineering and IT while protecting the certifications that A-LIGN's clients and platforms depend on. The role also supports broader information security activities, including risk assessments, threat modeling, security reviews, and AI technical safeguards.Reports toChief Information Security OfficerPay ClassificationFull-Time, ExemptResponsibilitiesOwn end-to-end audit evidence collection, validation, and organization across A-LIGN's compliance frameworks, including FedRAMP (Moderate Equivalency and FedRAMP 20x), ISO 27001, ISO 42001, SOC 2, NIST 800-53, and NIST 800-171Maintain and continuously verify technical controls across A-LIGN's cloud and corporate environments, including Google Cloud Platform (GCP/GKE), GitHub, and Microsoft 365/Entra IDServe as the primary liaison between the GRC function and technical departments (IT, Engineering, DevOps) to gather evidence, validate control implementation, and reduce audit burden on those teamsSupport FedRAMP continuous monitoring activities, including Key Security Indicator (KSI) evidence, vulnerability scan artifact collection, POA&M tracking, and assessor (3PAO) requestsBuild and maintain evidence automation, including integrations between GRC tooling and source systems (identity provider, cloud platforms, code repositories, ticketing, endpoint management) to reduce manual collection effortSupport A-LIGN's ISO 42001 Artificial Intelligence Management System (AIMS), including AI risk register evidence, AI control monitoring, and nonconformity remediation trackingPrepare audit-ready evidence packages and coordinate directly with external assessors and certification bodies during assessment windowsMonitor control health between audit cycles, identify control drift or failures, and drive remediation with control owners before findings occurMaintain compliance documentation, including control narratives, policies, and proceduresSupport supplier and vendor security reviews with framework-specific evidence requirementsTrack framework changes (FedRAMP 20x requirements, ISO standard revisions, SOC 2 criteria updates) and translate them into actionable control and evidence updatesConduct security risk assessments and contribute to A-LIGN's corporate risk management program and risk registerParticipate in threat modeling for A-SCEND features, internal systems, and AI use cases, and translate findings into control improvementsPerform security reviews of new tools, vendors, and internal initiatives, including support for Vendor Review Board activitiesImplement and validate AI technical controls and safeguards, including data loss prevention, AI connector and agent governance, and acceptable use enforcement, in support of A-LIGN's AI Management SystemReport compliance posture, evidence status, and audit readiness metrics to the CISO and GRC leadershipMinimum QualificationsEDUCATIONBachelor's degree in Information Systems, Cybersecurity, Business, or equivalent combination of education and experienceExperience5+ years of experience in information security, GRC, IT audit, or compliance engineering rolesHands-on experience with audit evidence collection and technical control validation for at least two of the following: FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171DevSecOps or cloud engineering experience sufficient to independently locate and extract evidence from GCP, GitHub, and Microsoft 365/Entra ID environmentsExperience with GRC platforms and evidence automation (AuditBoard, Vanta, Drata, or similar)Experience supporting external audits and assessor interactions, including 3PAO assessmentsWorking knowledge of vulnerability management, CI/CD pipelines, infrastructure-as-code, and identity and access management conceptsExperience scripting or automating evidence collection (Python, PowerShell, or similar) preferredFamiliarity with risk assessment methodologies, threat modeling (e.g., STRIDE), and security review processes preferredCERTIFICATIONS CISA, CISSP, CCSK/CCSP, ISO Lead Auditor/Implementer, or relevant certifications preferred but not requiredSkillsStrong cross-functional collaboration and project management skillsAbility to translate framework requirements into clear, actionable requests for technical teamsHighly organized with the ability to manage evidence deadlines across multiple concurrent audit cyclesExcellent written communication for control narratives, evidence descriptions, and assessor responsesSelf-directed with strong follow-through in a fast-paced, deadline-driven environmentProven experience utilizing AI tools to automate manual tasks, streamline workflows, and increase team efficiencyExperience operating in PE-backed or high-growth environments preferredBenefitsHealthcare, Dental, and Vision BenefitsEmployer Paid Life Insurance and Disability InsuranceEAP - Employee Assistance ProgramPet Insurance401(k) Plan with Employer MatchingCompetitive Bonus StructureHome Office ReimbursementCertification ReimbursementPersonalized Career CoachingGenerous Paid Time OffPaid Office Closure December 25-January 1Vacation BonusSummer HoursAbout A-LIGNA-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor. To learn more, visit a-lign.com.Come Work for A-LIGN! Apply online today at A-LIGN.com and learn about life at A-LIGN by following us on LinkedIn. A-LIGN is an Equal Opportunity Employer. Minorities, women, disabled, and veterans encouraged to apply!","company":"Align","rawCompany":"align","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-09-09T11:36:20.497Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"11-9199.02","title":"Compliance Managers","slug":"compliance-managers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior GRC Engineer","description":"About The RoleThe Senior GRC Engineer owns audit evidence collection and technical control maintenance across A-LIGN's growing portfolio of compliance frameworks, including FedRAMP Moderate Equivalency, FedRAMP 20x, ISO 27001, ISO 42001, and SOC 2. This role bridges the GRC function and A-LIGN's technical teams, working hands-on in GCP, GitHub, and Microsoft 365 to collect evidence, verify controls, and keep A-LIGN continuously audit-ready. The Senior GRC Engineer works cross-functionally with every technical department in the company to reduce audit burden on engineering and IT while protecting the certifications that A-LIGN's clients and platforms depend on. The role also supports broader information security activities, including risk assessments, threat modeling, security reviews, and AI technical safeguards.Reports toChief Information Security OfficerPay ClassificationFull-Time, ExemptResponsibilitiesOwn end-to-end audit evidence collection, validation, and organization across A-LIGN's compliance frameworks, including FedRAMP (Moderate Equivalency and FedRAMP 20x), ISO 27001, ISO 42001, SOC 2, NIST 800-53, and NIST 800-171Maintain and continuously verify technical controls across A-LIGN's cloud and corporate environments, including Google Cloud Platform (GCP/GKE), GitHub, and Microsoft 365/Entra IDServe as the primary liaison between the GRC function and technical departments (IT, Engineering, DevOps) to gather evidence, validate control implementation, and reduce audit burden on those teamsSupport FedRAMP continuous monitoring activities, including Key Security Indicator (KSI) evidence, vulnerability scan artifact collection, POA&M tracking, and assessor (3PAO) requestsBuild and maintain evidence automation, including integrations between GRC tooling and source systems (identity provider, cloud platforms, code repositories, ticketing, endpoint management) to reduce manual collection effortSupport A-LIGN's ISO 42001 Artificial Intelligence Management System (AIMS), including AI risk register evidence, AI control monitoring, and nonconformity remediation trackingPrepare audit-ready evidence packages and coordinate directly with external assessors and certification bodies during assessment windowsMonitor control health between audit cycles, identify control drift or failures, and drive remediation with control owners before findings occurMaintain compliance documentation, including control narratives, policies, and proceduresSupport supplier and vendor security reviews with framework-specific evidence requirementsTrack framework changes (FedRAMP 20x requirements, ISO standard revisions, SOC 2 criteria updates) and translate them into actionable control and evidence updatesConduct security risk assessments and contribute to A-LIGN's corporate risk management program and risk registerParticipate in threat modeling for A-SCEND features, internal systems, and AI use cases, and translate findings into control improvementsPerform security reviews of new tools, vendors, and internal initiatives, including support for Vendor Review Board activitiesImplement and validate AI technical controls and safeguards, including data loss prevention, AI connector and agent governance, and acceptable use enforcement, in support of A-LIGN's AI Management SystemReport compliance posture, evidence status, and audit readiness metrics to the CISO and GRC leadershipMinimum QualificationsEDUCATIONBachelor's degree in Information Systems, Cybersecurity, Business, or equivalent combination of education and experienceExperience5+ years of experience in information security, GRC, IT audit, or compliance engineering rolesHands-on experience with audit evidence collection and technical control validation for at least two of the following: FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171DevSecOps or cloud engineering experience sufficient to independently locate and extract evidence from GCP, GitHub, and Microsoft 365/Entra ID environmentsExperience with GRC platforms and evidence automation (AuditBoard, Vanta, Drata, or similar)Experience supporting external audits and assessor interactions, including 3PAO assessmentsWorking knowledge of vulnerability management, CI/CD pipelines, infrastructure-as-code, and identity and access management conceptsExperience scripting or automating evidence collection (Python, PowerShell, or similar) preferredFamiliarity with risk assessment methodologies, threat modeling (e.g., STRIDE), and security review processes preferredCERTIFICATIONS CISA, CISSP, CCSK/CCSP, ISO Lead Auditor/Implementer, or relevant certifications preferred but not requiredSkillsStrong cross-functional collaboration and project management skillsAbility to translate framework requirements into clear, actionable requests for technical teamsHighly organized with the ability to manage evidence deadlines across multiple concurrent audit cyclesExcellent written communication for control narratives, evidence descriptions, and assessor responsesSelf-directed with strong follow-through in a fast-paced, deadline-driven environmentProven experience utilizing AI tools to automate manual tasks, streamline workflows, and increase team efficiencyExperience operating in PE-backed or high-growth environments preferredBenefitsHealthcare, Dental, and Vision BenefitsEmployer Paid Life Insurance and Disability InsuranceEAP - Employee Assistance ProgramPet Insurance401(k) Plan with Employer MatchingCompetitive Bonus StructureHome Office ReimbursementCertification ReimbursementPersonalized Career CoachingGenerous Paid Time OffPaid Office Closure December 25-January 1Vacation BonusSummer HoursAbout A-LIGNA-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor. To learn more, visit a-lign.com.Come Work for A-LIGN! Apply online today at A-LIGN.com and learn about life at A-LIGN by following us on LinkedIn. A-LIGN is an Equal Opportunity Employer. Minorities, women, disabled, and veterans encouraged to apply!","datePosted":"2026-09-09T11:36:20.497Z","dateModified":"2026-09-09T11:36:20.497Z","hiringOrganization":{"@type":"Organization","name":"Align","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"c3703598dfd6359e9066b2cd"},"url":"https://jobsearcher.com/jobs/c3703598dfd6359e9066b2cd"}}