Verified current Job

Senior GRC Engineer

About the Role 

Job Full source details
A-LIGN External Source published Sep 20, 2026 Verified 5 hours ago
✓ 100% verification score · Source: Align Careers · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.

Overview

About the Role 

Full job description

About the Role  The Senior GRC Engineer owns audit evidence collection and technical control maintenance across A-LIGN's growing portfolio of compliance frameworks, including FedRAMP Moderate Equivalency, FedRAMP 20x, ISO 27001, ISO 42001, and SOC 2. This role bridges the GRC function and A-LIGN's technical teams, working hands-on in GCP, GitHub, and Microsoft 365 to collect evidence, verify controls, and keep A-LIGN continuously audit-ready. The Senior GRC Engineer works cross-functionally with every technical department in the company to reduce audit burden on engineering and IT while protecting the certifications that A-LIGN's clients and platforms depend on. The role also supports broader information security activities, including risk assessments, threat modeling, security reviews, and AI technical safeguards. Reports to Chief Information Security Officer Pay Classification Full-Time  Responsibilities  Own end-to-end audit evidence collection, validation, and organization across A-LIGN's compliance frameworks, including FedRAMP (Moderate Equivalency and FedRAMP 20x), ISO 27001, ISO 42001, SOC 2, NIST 800-53, and NIST 800-171 Maintain and continuously verify technical controls across A-LIGN's cloud and corporate environments, including Google Cloud Platform (GCP/GKE), GitHub, and Microsoft 365/Entra ID Serve as the primary liaison between the GRC function and technical departments (IT, Engineering, DevOps) to gather evidence, validate control implementation, and reduce audit burden on those teams Support FedRAMP continuous monitoring activities, including Key Security Indicator (KSI) evidence, vulnerability scan artifact collection, POA&M tracking, and assessor (3PAO) requests Build and maintain evidence automation, including integrations between GRC tooling and source systems (identity provider, cloud platforms, code repositories, ticketing, endpoint management) to reduce manual collection effort Support A-LIGN's ISO 42001 Artificial Intelligence Management System (AIMS), including AI risk register evidence, AI control monitoring, and nonconformity remediation tracking Prepare audit-ready evidence packages and coordinate directly with external assessors and certification bodies during assessment windows Monitor control health between audit cycles, identify control drift or failures, and drive remediation with control owners before findings occur Maintain compliance documentation, including control narratives, policies, and procedures Support supplier and vendor security reviews with framework-specific evidence requirements Track framework changes (FedRAMP 20x requirements, ISO standard revisions, SOC 2 criteria updates) and translate them into actionable control and evidence updates Conduct security risk assessments and contribute to A-LIGN's corporate risk management program and risk register Participate in threat modeling for A-SCEND features, internal systems, and AI use cases, and translate findings into control improvements Perform security reviews of new tools, vendors, and internal initiatives, including support for Vendor Review Board activities Implement and validate AI technical controls and safeguards, including data loss prevention, AI connector and agent governance, and acceptable use enforcement, in support of A-LIGN's AI Management System Report compliance posture, evidence status, and audit readiness metrics to the CISO and GRC leadership Minimum Qualifications  EDUCATION  Bachelor's degree in information systems, cybersecurity, business, or equivalent combination of education and experience EXPERIENCE  5+ years of experience in information security, GRC, IT audit, or compliance engineering roles Hands-on experience with audit evidence collection and technical control validation for at least two of the following: FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171 DevSecOps or cloud engineering experience sufficient to independently locate and extract evidence from GCP, GitHub, and Microsoft 365/Entra ID environments Experience with GRC platforms and evidence automation (AuditBoard, Vanta, Drata, or similar) Experience supporting external audits and assessor interactions, including 3PAO assessments Working knowledge of vulnerability management, CI/CD pipelines, infrastructure-as-code, and identity and access management concepts Experience scripting or automating evidence collection (Python, PowerShell, or similar) preferred Familiarity with risk assessment methodologies, threat modeling (e.g., STRIDE), and security review processes preferred CERTIFICATIONS   CISA, CISSP, CCSK/CCSP, ISO Lead Auditor/Implementer, or relevant certifications preferred but not required SKILLS  Strong cross-functional collaboration and project management skills Ability to translate framework requirements into clear, actionable requests for technical teams Highly organized with the ability to manage evidence deadlines across multiple concurrent audit cycles Excellent written communication for control narratives, evidence descriptions, and assessor responses Self-directed with strong follow-through in a fast-paced, deadline-driven environment Proven experience utilizing AI tools to automate manual tasks, streamline workflows, and increase team efficiency Experience operating in PE-backed or high-growth environments preferred Benefits  Employer Paid Life & Health Insurance  Competitive Bonus Structure  Home Office Reimbursement  Technology Allowance  Certification Reimbursement  BeneficiaT Discount Loyalty Program  Personalized Career Coaching  Generous Paid Time Off  Paid Office Closure December 25-January 1  Summer Hours  About A-LIGN  A-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor. To learn more, visit a-lign.com.  Come Work for A-LIGN!  Apply online today at A-LIGN.com and learn about life at A-LIGN by following us on  LinkedIn .   A-LIGN is an Equal Opportunity Employer.

Tips for this job

Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

laptop-ats-crawler v3

Original authoritative source

Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Align Careers ↗

Browse current Job and Scholarship listings from Align Careers →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books