EngineerJobs.io
← Back to all jobs

Job Description

The Senior Cybersecurity Engineer role in GRC Automation and Continuous Control Monitoring is a strategic and technical position focused on converting governance, risk, and compliance into an operational trust engine. You will serve as a technical focal point for GRC automation by building automated evidence collection, control testing, risk intelligence, and AI-enabled governance across cloud, on-premises, identity, OT, and security platforms.

Core Responsibilities

  • Perform detailed analysis of changes to cybersecurity solutions and how they affect internal and external systems to assess control effectiveness and cybersecurity risk, resolving complex multi-functional technical issues.
  • Apply cybersecurity assessments, standards, control testing methodologies, and compliance frameworks to support compliance across security systems.
  • Increase the efficiency and effectiveness of security solutions, governance processes, automated controls, and monitoring capabilities.
  • Review existing processes and procedures and lead implementation efforts for improvements, automation opportunities, or remediation activities.
  • Develop and submit Standard Operating Procedures.
  • Analyze business-impacting events, conduct initial investigations, and evaluate control performance, exceptions, and risk indicators using continuous monitoring activities.
  • Investigate and analyze cyber incidents, control failures, and compliance exceptions, and assist in developing risk mitigation and remediation plans to support regulatory and internal compliance.
  • Lead implementation of global security initiatives, policies, compliance requirements, and continuous control monitoring practices; collect, validate, and report security metrics, control performance results, and remediation efforts.
  • Manage cyber security-related consulting, guidance, and support for customers and stakeholders.
  • Translate security principles to help configuration teams incorporate security and compliance requirements into build and configuration processes.
  • Monitor emerging IT/OT, cybersecurity, automation, and artificial intelligence technologies and assess their impact on the security, risk, and compliance landscape.

Required Qualifications

  • Bachelor’s Degree in Information Technology, related field, or equivalent experience.
  • 5+ years of relevant experience required.
  • Experience designing, implementing, and scaling GRC, CCM, or compliance automation solutions in a regulated environment required.
  • Experience with Python or comparable automation technologies, including developing, integrating, and supporting automated workflows and REST API-based data integrations across multiple enterprise systems required.
  • Hands-on experience integrating security-control data sources into a GRC/CCM evidence pipeline for continuous control testing required, including normalizing API, telemetry, configuration, vulnerability, identity, ticketing, and assessment data into control-level evidence, exception logic, ownership, frequency, and audit-ready records across at least three domains such as CNAPP/CSPM, SIEM/security data lake/XDR, CTEM/VM/ASPM, DSPM, ITSM, IAM, GRC/CCM, or AI/agent governance.

Preferred Qualifications

  • Experience building LLM-backed agentic workflows on Azure AI Foundry, GitHub, or open-source frameworks preferred.
  • Familiarity with NIST AI RMF, the OWASP LLM Top 10, or comparable AI risk frameworks preferred.

Technologies

  • Python, REST API
  • Azure AI Foundry, GitHub
  • NIST AI RMF, OWASP LLM Top 10
  • CNAPP, CSPM, SIEM, XDR
  • CTEM, VM, ASPM, DSPM, ITSM, IAM
  • AI/agent governance

Education

Bachelor’s Degree in Information Technology (or related field) or equivalent experience.

Minimum Qualifications

Bachelor’s Degree in Information Technology, related field, or equivalent experience. Professional certification (e.g., Security+, Network+, OSCP, GIAC, CEH) is preferred. 5+ years of relevant experience required.

Skills

  • Adaptability
  • AI Fundamentals
  • Change Management
  • Authentic Communicator
  • Cybersecurity Risk Management
  • General Programming
  • Intrusion Detection
  • Penetration Testing
  • Relationship Management
  • Security Controls
  • Security Governance
  • Security Information & Event Management (SIEM)
  • Security Policy Management
  • Threat Analysis
  • Threat Hunting
  • Vulnerability Management

Benefits

  • Health, vision, and dental insurance
  • Paid time off
  • 401k matching program
  • Paid parental leave
  • Educational reimbursement
  • Discretionary company-sponsored annual bonus program

Similar Jobs