Cybersecurity GRC Engineer

$130,000 - $140,000 Per Annum

New York City

posted 04 Aug 26

About this role

Cybersecurity GRC Engineer

About the Opportunity

Our client is a nationally recognized organization undergoing a significant cybersecurity and digital transformation. As they continue modernizing their technology landscape, they are seeking a Cybersecurity GRC Engineer to help bridge the gap between governance, risk, compliance, and hands-on security engineering.

This is not a traditional GRC position. The ideal candidate will combine a strong understanding of security frameworks and regulatory requirements with the technical ability to validate, automate, and improve security controls across modern cloud and enterprise environments.

You'll partner closely with Security Engineering, Infrastructure, Cloud, Networking, Application Development, and Compliance teams to build scalable security processes, improve risk visibility, and enhance the organization's overall security posture.

Responsibilities

  • Translate security, regulatory, and compliance requirements into practical technical controls and engineering solutions.
  • Design and implement automated processes for security control validation, evidence collection, compliance monitoring, and audit readiness.
  • Develop scripts, tooling, and repeatable processes that reduce manual compliance activities and improve operational efficiency.
  • Perform technical risk assessments across infrastructure, cloud environments, applications, vendors, and enterprise technologies.
  • Evaluate security controls across operating systems, cloud platforms, network infrastructure, and business applications.
  • Partner with engineering teams to embed secure-by-design principles into technology initiatives.
  • Assess vulnerabilities, identify control gaps, and help prioritize remediation efforts based on technical and business risk.
  • Support cloud security initiatives across AWS and/or Azure environments.
  • Produce clear documentation including security standards, risk assessments, remediation plans, control evidence, and technical reports.
  • Support internal and external audits while helping drive continuous compliance initiatives.
  • Develop dashboards, metrics, and reporting that communicate security posture to both technical and business stakeholders.
  • Contribute to incident response activities, forensic investigations, and security automation where appropriate.

What We're Looking For

  • Experience within Cybersecurity Engineering, Security Operations, GRC Engineering, Cloud Security, or related cybersecurity disciplines.
  • Strong understanding of security frameworks such as NIST, ISO 27001, CIS Controls, SOC 2, or similar.
  • Hands-on experience with AWS and/or Azure cloud environments.
  • Strong scripting or programming experience (Python, PowerShell, Bash, or similar).
  • Experience automating security controls, compliance processes, or security operations.
  • Knowledge of vulnerability management, risk assessments, and security architecture principles.
  • Strong communication skills with the ability to collaborate across technical and business teams.
  • A naturally curious mindset with strong problem-solving abilities and a passion for continuous improvement.

What Makes This Opportunity Different

  • Opportunity to help shape the future of a rapidly evolving cybersecurity organization.
  • Highly collaborative engineering culture that values innovation and technical ownership.
  • Significant investment in automation, AI, cloud technologies, and modern security practices.
  • Exposure to enterprise-wide security initiatives with visibility across multiple technology domains.
  • Strong emphasis on professional growth, cross-functional collaboration, and technical development.
CONTRACT TYPEPermanent
SPECIALISMTechnology & Data
JOB REF3134
EXPIRY DATE03 Sept 26