FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Security Engineer – GRC Engineering
One Identity. Own continuous control monitoring end to end across identity providers, cloud control planes, code repositories, endpoint management, and ticketing .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in compliance program leadership and security engineering, with a strong focus on framework design, control mapping, and evidence automation. Proficient in Python and API integration, with hands-on experience in compliance automation platforms and cloud environments.
Highest-signal resume keywords
Compliance Program LeadershipFramework Design and Control MappingPython and API IntegrationISO 27001 and SOC 2 FluencyCompliance Automation Platform Experience
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Compliance EngineeringControl Validation as CodeAudit-Ready Evidence ProductionPolicy as Code FrameworksAutomated Asset PrioritizationControl TelemetryContinuous MonitoringFramework AssessmentAI IntegrationCloud Enforcement
Soft Skills
Communication with Auditors and EngineersStrategic ThinkingRelationship Management
Tools & Technologies
AzureAWSCompliance Automation Platforms
Certifications & Qualifications
FedRAMP CertificationISO 27001 Certification
Industry Keywords
GRC EngineeringNIS2DORAPCI DSSIRAP
Tech Stack
Tools & technologiesAWSAzureCloudPython
About the role
Key responsibilities & impact- Own continuous control monitoring end to end across identity providers, cloud control planes, code repositories, endpoint management, and ticketing
- Build alerting, escalation, and remediation confirmation for degraded controls
- Build a centralized common controls framework based on ISO 27001 and SOC 2
- Map additional frameworks to the common controls framework
- Capture, timestamp, index, and assemble audit-ready evidence on demand
- Ensure the evidence system operates within and logs its own controls
- Write control validation as code and produce auditor-accepted, engineer-actionable outputs
- Create pull-request-based corrections against pipelines, policies, or configurations
- Partner with infrastructure engineering on policy as code and evidence emission
- Define appropriate uses of agentic workflows for control mapping, evidence classification, and validation
- Own the compliance engineering program's direction, framework priorities, automation priorities, and engineering allocation
- Advance metrics covering control health, framework coverage, remediation velocity, and trends
- Integrate cyber risk management, risk registers, and exception handling with control telemetry
- Own automated asset prioritization to inform risk decisions, control coverage, and remediation order
- Lead the technical side of audits and explain control implementation and evidence production to assessors
Requirements
What you’ll need- Six or more years across compliance program leadership and security or compliance engineering, including experience on both the framework side and the build side; equivalent depth counts
- Experience leading a major framework through assessment from readiness through certification or authorization, such as FedRAMP or comparable, or owning GRC engineering end to end with control telemetry, continuous monitoring, and evidence automation
- Strategic framework design and control mapping across frameworks
- Recent hands-on Python and API integration experience
- Hands-on building with AI in the loop within the last six months, including verification of tooling output
- Framework fluency across ISO 27001 and SOC 2
- Familiarity with FedRAMP 20x, NIS2, DORA, and PCI DSS
- Knowledge of policy-as-code frameworks and cloud enforcement
- Sufficient Azure and AWS experience to identify where evidence resides
- Experience with a compliance automation platform
- Ability to run an audit calendar and assessor relationship
- Ability to write for both auditors and engineers
- Helpful: assessor-side experience; IRAP or another non-US regime; evidence work across hosted services and customer-deployed software; prior software or platform engineering experience
Benefits
Comp & perks- Health and wellness programs
- Career development opportunities
- Programs supporting employees in pursuing fulfilling careers
- Opportunities to learn and grow
- Equal employment opportunity and harassment-free work environment