GRC Engineer

Clerk
United States
Workplace: RemoteFull timeFunction: Legal, Risk & ComplianceExperience: 5+ yearsSkills: ["Hands-on execution","Automation","Policy writing","Technical ownership","Risk assessment"]

Build and run Clerk’s GRC program as a hands-on security engineer—owning SOC 2 Type II and HIPAA from scoping through evidence, auditor walkthroughs, and remediation. Scope and lead the next framework (likely ISO 27001), integrate GRC platforms with cloud providers and SaaS tools, and turn controls into continuous checks via policy-as-code, drift detection, and automated evidence pipelines. Reduce quarterly audit scramble by embedding compliance into the SDLC.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Clerk
Clerk
3 days ago

GRC Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 15 hours agoStatus: Live

Job Summary

Build and run Clerk’s GRC program as a hands-on security engineer—owning SOC 2 Type II and HIPAA from scoping through evidence, auditor walkthroughs, and remediation. Scope and lead the next framework (likely ISO 27001), integrate GRC platforms with cloud providers and SaaS tools, and turn controls into continuous checks via policy-as-code, drift detection, and automated evidence pipelines. Reduce quarterly audit scramble by embedding compliance into the SDLC.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Mid level

Key Responsibilities

  • •Own SOC 2 Type II and HIPAA end to end, including scoping, control design, evidence, auditor walkthroughs, and remediation.
  • •Scope and lead the next compliance framework (likely ISO 27001) based on what customers ask for.
  • •Build and maintain integrations feeding the GRC platform from cloud providers, SaaS tools, and internal systems.
  • •Turn controls into continuous checks using policy-as-code, config drift detection, and a detection-to-closure control-failure pipeline.
  • •Run the vendor security review program (intake through periodic re-review) and maintain risk assessments and a risk register that drive documented decisions.

Pay and Benefits

Perks:EquityHealth InsuranceHome OfficePaid Leave

Key Requirements

  • •5+ years in security, building automation for a GRC or compliance program.
  • •Technical ownership of at least one SOC 2 Type II or ISO 27001 audit, including knowing what you’d do differently.
  • •Write code and use LLMs to increase output without lowering standards.
  • •Hands-on with a GRC platform’s API (not just the dashboard).
  • •Cloud IAM and configuration depth on at least one provider, with GCP preferred.
Experience:5+ yearsGRCComplianceSecuritySecurity automation
Skills:Hands-on executionAutomationPolicy writingTechnical ownershipRisk assessment
Tech Stack:SOC 2HIPAAISO 27001GRC platform APIsPolicy-as-codeConfig drift detectionLLMsGCPCloud IAM

Company Brief

Clerk
Provides drop-in authentication and user-management developer tools (embeddable UIs, SDKs, APIs, and admin dashboards) focused on React/modern web apps to simplify sign-up, sign-in, profiles, MFA, and authorization workflows for SaaS companies.
Industry: Developer Tools
Company Size: Medium (51 to 250 employees)
Growth: Growth Stage Startup
Valuation: USD 100M to 250M
Funding: Series B
Headquarters: San Francisco, United States
Founded: 2019
Glassdoor
Glassdoor: 4.5
WebsiteLinkedInGlassdoor