Skip to content
NEXTMOVEFDE careers · United States

Senior GRC Engineer

AI summary of the role

A hands-on Senior GRC Engineer owns audit evidence collection and technical control maintenance across FedRAMP, ISO 27001/42001, and SOC 2 at a cybersecurity compliance firm.

What you’ll do

  • Own end-to-end audit evidence collection and validation across FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, and NIST 800-171
  • Maintain and verify technical controls in GCP/GKE, GitHub, and Microsoft 365/Entra ID
  • Serve as primary liaison between GRC and technical teams to reduce audit burden
  • Support FedRAMP continuous monitoring including KSI evidence, POA&M tracking, and 3PAO requests

What you’ll bring

  • 5+ years in information security, GRC, IT audit, or compliance engineering
  • Hands-on evidence collection and control validation for at least two frameworks (FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171)
  • DevSecOps or cloud engineering experience to extract evidence from GCP, GitHub, and Microsoft 365/Entra ID
  • Experience with GRC platforms and evidence automation (AuditBoard, Vanta, Drata, or similar)

Technologies

GCP · GKE · GitHub · Microsoft 365 · Entra ID · FedRAMP · ISO 27001 · ISO 42001 · SOC 2 · NIST 800-53 · NIST 800-171 · AuditBoard

About A-LIGN

Cybersecurity compliance auditor (SOC 2, ISO 27001, FedRAMP, HITRUST, PCI, CMMC) bundling human assessors with the A-SCEND audit-management SaaS.

Private Late · 500–1000 people

Source and classification

Internal deployment & tooling · Evidence for this classification:

About the Role The Senior GRC Engineer owns audit evidence collection and technical control maintenance across A-LIGN's growing portfolio of compliance frameworks, including FedRAMP Moderate Equivalency, FedRAMP 20x, ISO 27001, ISO 42001, and SOC 2. This role bridges the GRC function and A-LIGN's technical teams, working hands-on in GCP, GitHub, and Microsoft 365 to collect evidence, verify controls, and keep A-LIGN continuously audit-ready. The Senior GRC Engineer works cross-functionally with every technical department in the company to reduce audit burden on engineering and IT while protecting the certifications that A-LIGN's clients and platforms depend on. The role also supports broader information security activities, including risk assessments, threat modeling, security reviews, and AI technical safeguards. Reports to Chief Information Security Officer Pay Classification
More from the job description

About the Role The Senior GRC Engineer owns audit evidence collection and technical control maintenance across A-LIGN's growing portfolio of compliance frameworks, including FedRAMP Moderate Equivalency, FedRAMP 20x, ISO 27001, ISO 42001, and SOC 2. This role bridges the GRC function and A-LIGN's technical teams, working hands-on in GCP, GitHub, and Microsoft 365 to collect evidence, verify controls, and keep A-LIGN continuously audit-ready. The Senior GRC Engineer works cross-functionally with every technical department in the company to reduce audit burden on engineering and IT while protecting the certifications that A-LIGN's clients and platforms depend on. The role also supports broader information security activities, including risk assessments, threat modeling, security reviews, and AI technical safeguards. Reports to Chief Information Security Officer Pay Classification Full-Time, Exempt Responsibilities Own end-to-end audit evidence collection, validation, and organization across A-LIGN's compliance frameworks, including FedRAMP (Moderate Equivalency and FedRAMP 20x), ISO 27001, ISO 42001, SOC 2, NIST 800-53, and NIST 800-171 Maintain and continuously verify technical controls across A-LIGN's cloud and corporate environments, including Google Cloud Platform (GCP/GKE), GitHub, and Microsoft 365/Entra ID Serve as the primary liaison between the GRC function and [... source excerpt omitted ...] ngs occur Maintain compliance documentation, including control narratives, policies, and procedures Support supplier and vendor security reviews with framework-specific evidence requirements Track framework changes (FedRAMP 20x requirements, ISO standard revisions, SOC 2 criteria updates) and translate them into actionable control and evidence updates Conduct security risk assessments and contribute to A-LIGN's corporate risk management program and risk register Participate in threat modeling for A-SCEND features, internal systems, and AI use cases, and translate findings into control improvements Perform security reviews of new tools, vendors, and internal initiatives, includi [... source excerpt omitted ...] table use enforcement, in support of A-LIGN's AI Management System Report compliance posture, evidence status, and audit readiness metrics to the CISO and GRC leadership Minimum Qualifications EDUCATION Bachelor's degree in information systems, cybersecurity, business, or equivalent combination of education and experience EXPERIENCE 5+ years of experience in information security, GRC, IT audit, or compliance engineering roles Hands-on experience with audit evidence collection and technical control validation for at least two of the following: FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171 DevSecOps or cloud engineering experience sufficient to independently loc

How jobs are selected

Employer postings · Data from · Sources