Back to Jobs
A-LIGN
Engineering & Architecture Just now

Senior GRC Engineer

A-LIGN
United StatesUnited States
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

CybersecurityISO 27001AI technical safeguardsGRCFedRAMP

Want to know if you're a match for this job?

Calculate My Match Score

The Senior GRC Engineer owns audit evidence collection and technical control maintenance across A-LIGN’s growing portfolio of compliance frameworks, including FedRAMP Moderate Equivalency, FedRAMP 20x, ISO 27001, ISO 42001, and SOC 2. This role bridges the GRC function and A-LIGN’s technical teams, working hands-on in GCP, GitHub, and Microsoft 365 to collect evidence, verify controls, and keep A-LIGN continuously audit-ready.

The Senior GRC Engineer works cross-functionally with every technical department in the company to reduce audit burden on engineering and IT while protecting the certifications that A-LIGN’s clients and platforms depend on. The role also supports broader information security activities, including risk assessments, threat modeling, security reviews, and AI technical safeguards.

Responsibilities

  • Own end-to-end audit evidence collection, validation, and organization across A-LIGN’s compliance frameworks, including FedRAMP (Moderate Equivalency and FedRAMP 20x), ISO 27001, ISO 42001, SOC 2, NIST 800-53, and NIST 800-171
  • Maintain and continuously verify technical controls across A-LIGN’s cloud and corporate environments, including Google Cloud Platform (GCP/GKE), GitHub, and Microsoft 365/Entra ID
  • Serve as the primary liaison between the GRC function and technical departments (IT, Engineering, DevOps) to gather evidence, validate control implementation, and reduce audit burden on those teams
  • Support FedRAMP continuous monitoring activities, including Key Security Indicator (KSI) evidence, vulnerability scan artifact collection, POA&M tracking, and assessor (3PAO) requests
  • Build and maintain evidence automation, including integrations between GRC tooling and source systems (identity provider, cloud platforms, code repositories, ticketing, endpoint management) to reduce manual collection effort
  • Support A-LIGN’s ISO 42001 Artificial Intelligence Management System (AIMS), including AI risk register evidence, AI control monitoring, and nonconformity remediation tracking
  • Prepare audit-ready evidence packages and coordinate directly with external assessors and certification bodies during assessment windows
  • Monitor control health between audit cycles, identify control drift or failures, and drive remediation with control owners before findings occur
  • Maintain compliance documentation, including control narratives, policies, and procedures
  • Support supplier and vendor security reviews with framework-specific evidence requirements
  • Track framework changes (FedRAMP 20x requirements, ISO standard revisions, SOC 2 criteria updates) and translate them into actionable control and evidence updates
  • Conduct security risk assessments and contribute to A-LIGN’s corporate risk management program and risk register
  • Participate in threat modeling for A-SCEND features, internal systems, and AI use cases, and translate findings into control improvements
  • Perform security reviews of new tools, vendors, and internal initiatives, including support for Vendor Review Board activities
  • Implement and validate AI technical controls and safeguards, including data loss prevention, AI connector and agent governance, and acceptable use enforcement, in support of A-LIGN’s AI Management System
  • Report compliance posture, evidence status, and audit readiness metrics to the CISO and GRC leadership

How would you rate this job post?

See what other professionals think about this role.

banner

A-LIGN is a premier, enterprise-grade security and compliance platform engineered to orchestrate massive-scale regulatory ecosystems and intelligent frictionless audit workflows. Operating as a highly integrated global cybersecurity hub, the company eliminates the operational friction of traditional localized compliance by seamlessly deploying advanced A-SCEND technology telemetry, rigorous multi-framework evidence architectures (covering SOC, ISO, HITRUST, and FedRAMP), and cohesive automated readiness frameworks. Moving beyond rigid legacy accounting firms, A-LIGN empowers global technology companies, high-growth SaaS providers, and government contractors to dynamically synchronize their risk mitigation pipelines with elite auditor-led execution. Under the hood, their sophisticated proprietary compliance infrastructure natively handles complex global security ingestion, instantaneous control-mapping routing across dozens of standards, and seamless GRC tool integration, ensuring frictionless audit readiness and uncompromising data integrity for over 6,000 global clients. What sets A-LIGN apart is its uncompromising dedication to frictionless security orchestration; by bridging the gap between rigorous regulatory requirements and accessible technology-fueled efficiency, the platform empowers organizations to radically accelerate their certification velocity, optimize compliance economics, and build an unassailable foundation for continuous commercial dominance in the modern digital risk landscape.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More