Aegis AI Security logo
Aegis AI Security
Posted 2 days agoVerified live 1d ago

GRC Engineer

Brief overview

Remote
UndergradOr in progress
4+ yrsMinimum
SOC 2 Type IIGovernance, Risk, and Compliance (GRC)Security Compliance AuditingEnterprise Security QuestionnairesPythonAPI IntegrationPrivacy ComplianceISO 27001Compliance AutomationBusiness Continuity and Disaster RecoveryAI GovernanceClear Written Communication

About the company

Aegis AI Security logo
Aegis AI Securityaegisai.ai

Aegis AI is an AI-native Email Security platform.

Job description

Summary

Aegis AI Security is a security company founded by former Google engineers focused on defending organizations against adversarial AI attacks. The GRC Engineer will advance the company’s security program by owning SOC 2 compliance, risk management, policies, business continuity, incident response, vendor risk, customer security reviews, control mapping, and evidence automation.

Responsibilities

  • Own Compliance end to end: Keep the program audit-ready year round and run the auditor relationship
  • Pave the road to what's next: Keep us ahead of what our customers ask for, so when the business needs its next certification or framework, we're already on track
  • Run our risk management program: Maintain the risk register, keep treatments moving, and ensure we have an accurate picture of risk at all times
  • Own the policy suite: Keep our policies, standards and procedures current as we grow, aligned with how we operate, and clear to the customers who read them
  • Own BC/DR and incident response: Maintain and exercise our plans and playbooks, own the customer notification commitments behind them, and make sure everyone knows their part before it's needed
  • Answer the questions that gate deals: Own customer security questionnaires and TPRM reviews end to end, grow the answer library so answers stay accurate and consistent, and keep turnaround fast
  • Run vendor and subprocessor risk: Review the vendors we depend on, keep DPAs and the subprocessor list current, scale third-party risk management as our vendor footprint grows, and handle customer data requests end to end
  • Map controls across frameworks: Maintain our control set against the industry frameworks we build on, audit against it, and make one piece of evidence count everywhere it can
  • Expand evidence automation: Pull more proof straight from systems through APIs and scripts, so audits and questionnaires draw from live data

Skills

  • 4+ years in GRC, security compliance or audit at a SaaS company, and you've run a SOC 2 Type II end to end at least once
  • You've answered enterprise security questionnaires and you write clearly enough that your answers close the thread
  • Technical enough to read an architecture diagram, question an engineer's answer, and tell the difference between a control that exists and one that's written down
  • You script. Python or similar, comfortable with APIs, and allergic to collecting the same evidence twice
  • Working knowledge of the major privacy regimes and what they mean for a data processor
  • Organized, self-directed, and honest about what you don't know yet
  • You've implemented ISO 27001, or carried a company through certification
  • Compliance automation platform experience, especially custom tests and the API side of one
  • AI governance exposure: ISO 42001, NIST AI RMF, or building an AI policy from scratch
  • You've built or tested BC/DR for a production SaaS
  • Privacy certifications (CIPP or similar)
  • You've worked at a security vendor and know the standard your answers get held to

Qualifications

Must Haves

  • 4+ years in GRC, security compliance or audit at a SaaS company, and you've run a SOC 2 Type II end to end at least once
  • You've answered enterprise security questionnaires and you write clearly enough that your answers close the thread
  • Technical enough to read an architecture diagram, question an engineer's answer, and tell the difference between a control that exists and one that's written down
  • You script. Python or similar, comfortable with APIs, and allergic to collecting the same evidence twice
  • Working knowledge of the major privacy regimes and what they mean for a data processor
  • Organized, self-directed, and honest about what you don't know yet

Nice to Haves

  • You've implemented ISO 27001, or carried a company through certification
  • Compliance automation platform experience, especially custom tests and the API side of one
  • AI governance exposure: ISO 42001, NIST AI RMF, or building an AI policy from scratch
  • You've built or tested BC/DR for a production SaaS
  • Privacy certifications (CIPP or similar)
  • You've worked at a security vendor and know the standard your answers get held to

Benefits

  • Remote work
  • Flexible work arrangement

More jobs like this