FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

GRC Engineer
Aegis AI Security. Own the compliance program end to end and keep it audit-ready year-round .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in managing compliance programs, including SOC 2 Type II, and possesses strong technical skills in scripting and API integration. Proficient in risk management, incident response, and maintaining compliance with major privacy regimes.
Highest-signal resume keywords
SOC 2 Type II ManagementRisk ManagementCompliance AutomationScripting in PythonISO 27001 Implementation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
GRCSecurity ComplianceAuditRisk Register MaintenanceBusiness Continuity PlanningDisaster RecoveryIncident ResponseTechnical Architecture EvaluationPrivacy Regime KnowledgeCustomer Security Questionnaires
Soft Skills
Clear Written CommunicationOrganizedSelf-DirectedHonest About Knowledge Gaps
Tools & Technologies
Compliance Automation PlatformsAPIsScripts
Certifications & Qualifications
ISO 27001CIPP
Industry Keywords
AI GovernanceNIST AI RMFThird-Party Risk ManagementData Processor ComplianceVendor Management
Tech Stack
Tools & technologiesPython
About the role
Key responsibilities & impact- Own the compliance program end to end and keep it audit-ready year-round
- Run the auditor relationship
- Prepare the company for future customer-requested certifications and frameworks
- Maintain the risk register, advance risk treatments, and keep the risk picture accurate
- Maintain policies, standards, and procedures as the company scales
- Maintain and exercise business continuity, disaster recovery, and incident response plans and playbooks
- Own customer notification commitments and ensure stakeholders understand their roles
- Manage customer security questionnaires and third-party risk management reviews end to end
- Expand the answer library for accurate, consistent, and fast responses
- Review vendors, maintain DPAs and the subprocessor list, scale third-party risk management, and handle customer data requests
- Map controls across industry frameworks and maximize reuse of evidence
- Automate evidence collection through APIs and scripts
- Work directly with the head of security, engineers, and customers
- Advance AegisAI's security program for its AI-attack defense business
Requirements
What you’ll need- 4+ years in GRC, security compliance, or audit at a SaaS company
- Must have run a SOC 2 Type II end to end at least once
- Experience answering enterprise security questionnaires
- Clear written communication sufficient to close security-review threads
- Technical ability to read architecture diagrams and evaluate whether controls exist in practice
- Scripting experience in Python or similar
- Comfortable working with APIs
- Working knowledge of major privacy regimes and their implications for a data processor
- Organized, self-directed, and honest about knowledge gaps
- ISO 27001 implementation or certification experience preferred as a bonus
- Compliance automation platform experience, especially custom tests and APIs, preferred as a bonus
- AI governance exposure, including ISO 42001 or NIST AI RMF, preferred as a bonus
- Experience building or testing BC/DR for a production SaaS preferred as a bonus
- Privacy certification such as CIPP preferred as a bonus
- Experience working at a security vendor preferred as a bonus
Benefits
Comp & perks- Flat, flexible, and fast culture
- Clear KPIs for success with autonomy over how to achieve them