Enhance global compliance posture and embed data governance principles into the business
Design and automate control testing and evidence collection to reduce manual effort and improve accuracy
Build and maintain scripts and APIs across infrastructure, endpoints, and SaaS platforms (e.g., AWS, GitHub, Okta) that interface with compliance tooling
Support recurring internal and external audits (SOC 2, ISO 27001, PCI DSS) by ensuring reliable control monitoring
Champion security, compliance, data governance strategies and processes including data deletion, data retention, and data storage
Leverage AI/ML tools to improve efficiency and outcomes for GRC processes
Define technical control requirements and collaborate with partners to embed compliance checks into CI/CD pipelines and infrastructure deployment workflows
Report to the Head of GRC and help shape the next iteration of the GRC program
Requirements
Experience in scripting or automation with a focus on security, infrastructure, or GRC
Knowledge of audit processes, evidence requirements, and remediation actions for security and compliance frameworks (i.e., SOC 2, ISO 27001, PCI DSS)
Ability to write scripts and basic code to automate audit and evidence gathering processes
Ability to build API end points and command-line tools, work with structured data (JSON, CSV, YAML), and extract compliance-relevant information from security, IT, and GRC systems
Experience owning a project or scope, building relationships, collaborating with both technical and non-technical teams and driving initiatives to completion
Familiarity with data governance, compliance or software development tools and systems (e.g., Drata, Satori, Github, etc.) (bonus)
Experience with frontend cloud, AI/ML systems, and open source development (bonus)
Experience with FedRAMP or NIST frameworks, such as 800-53, 800-171, RMF (bonus)