CrawlJobs Logo

Senior GRC Tools and Automation Engineer

https://www.atlassian.com Logo

Atlassian

Location Icon

Location:
United States , San Francisco

Category Icon

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

Not provided

Job Description:

We are looking for a skilled Senior GRC Tools and Automation Engineer to join our team. The ideal candidate will have a strong understanding of Governance, Risk, and Compliance (GRC) frameworks and will be adept at developing JIRA workflows. Experience in data analysis and reporting tools, API and data integration skills, and a good understanding of cloud, AI, and emerging technologies are essential. This role is crucial in enhancing our GRC capabilities through effective tool implementation and automation strategies.

Job Responsibility:

  • Lead the design, implementation, and maintenance of GRC tools to support compliance, risk management, and governance activities
  • Collaborate with cross-functional teams to gather requirements and ensure tools meet organizational needs
  • Design and develop custom JIRA workflows to streamline GRC processes
  • Ensure JIRA configurations align with best practices and organizational requirements
  • Utilize data analysis and reporting tools to generate insights and actionable reports for GRC activities
  • Create dashboards and visualizations to communicate risk and compliance metrics effectively to stakeholders
  • Develop and manage integrations between GRC tools and other enterprise systems using APIs
  • Ensure seamless data flow and integrity across platforms to enhance GRC operations
  • Stay informed about the latest developments in cloud computing, artificial intelligence, and emerging technologies
  • Assess the impact of these technologies on GRC practices and tools, and propose innovative solutions
  • Identify opportunities for automation within GRC processes to improve efficiency and reduce manual efforts
  • Implement automation solutions that enhance the accuracy and effectiveness of GRC operations

Requirements:

  • Bachelor's degree in Computer Science, Information Technology, or a related field
  • Advanced degree or relevant certifications (e.g., CRISC, CISSP, JIRA Certification) are a plus
  • A minimum of [X] years of experience in GRC tools implementation and automation
  • Strong expertise in developing JIRA workflows and configuring JIRA tools to meet organizational needs
  • Proficiency in data analysis and reporting tools, such as Power BI, Tableau, or similar platforms
  • Experience with API development and data integration techniques, ensuring seamless connectivity between systems
  • Solid understanding of cloud services (e.g., AWS, Azure, Google Cloud) and their implications for GRC
  • Familiarity with artificial intelligence and emerging technologies, with an ability to assess and integrate them into GRC processes
  • Excellent problem-solving skills, with a focus on innovation and process improvement
What we offer:
  • Health and wellbeing resources
  • Paid volunteer days

Additional Information:

Job Posted:
May 01, 2025

Employment Type:
Fulltime
Work Type:
Remote work
Job Link Share:

Looking for more opportunities? Search for other job offers that match your skills and interests.

Briefcase Icon

Similar Jobs for Senior GRC Tools and Automation Engineer

Senior Security GRC Engineer

The Senior Security GRC Engineer at Atlassian will be instrumental in implementi...
Location
Location
India , Bengaluru
Salary
Salary:
Not provided
https://www.atlassian.com Logo
Atlassian
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5-7+ years experience in a similar role, preferably in a large-scale SaaS/Product environment
  • Expertise and experience working in security-focused roles
  • Experience with application security, especially web applications
  • Experience in cloud security architecture and infrastructure
  • Experience providing SME knowledge and guidance to stakeholders and engineering functions
  • Experience working with internal/external audit and leadership teams
  • Solid knowledge of cybersecurity principles, risk management strategies, and IT governance frameworks
  • Strong communication and interpersonal skills, with the ability to interact with stakeholders at all levels and explain complex security concepts in an understandable way
  • Relevant certifications such as CISSP, CISM, or CRISC would be beneficial
  • Scripting experience to automate recurring tasks (JQL, SQL, Python, Go)
Job Responsibility
Job Responsibility
  • Deliver technical expertise and innovation, providing security guidance to teams and promoting the adoption of industry-leading methodologies to build secure products by default
  • Drive technical solutions in security and risk management
  • Leverage data analytics and visualization, deriving actionable insights from security governance, risk, and compliance data
  • Promote automation and tooling, encouraging the use of the latest security tools to enhance product security processes
  • Proactively identify and mitigate risks, recognizing potential security threats or compliance concerns specific to product security
  • Collaborate with product security teams, implementing security controls and best practices
  • Regularly evaluate and report, assessing the effectiveness of security controls
  • Influence and align stakeholders, working with security engineers and stakeholders to drive alignment on security initiatives
  • Stay informed on regulatory awareness and compliance, keeping up with the latest developments in legislative, regulatory, and industry security requirements
What we offer
What we offer
  • health coverage
  • paid volunteer days
  • wellness resources
  • Fulltime
Read More
Arrow Right
New

Staff Trust, Risk and Compliance Engineer

As a Staff Trust, Risk, and Compliance Engineer you will operate at the center o...
Location
Location
Czechia , Prague
Salary
Salary:
Not provided
rapid7.com Logo
Rapid7
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Extensive experience (typically 10+ years) building bridge-layers between complex business requirements and technical operations
  • Deep understanding of managing complex lifecycles—whether in Trust, Risk, and Compliance (NIST, ISO) or other highly regulated, high-scale technical fields
  • A proven track record of designing systems that don't just "work" but scale
  • A design-thinking–led microservices architecture that allows the TRC stack to adapt and evolve organically
  • Strong engineering mindset applied to governance, risk, and compliance challenges
  • Advanced technical fluency, including: Cloud environments (AWS)
  • APIs, automation, and scripting (e.g., Python)
  • Commercial GRC platforms and security tooling
  • Ability to influence direction, negotiate outcomes, and shape how peers and leaders approach problems
  • Strong judgment and communication skills
Job Responsibility
Job Responsibility
  • Design and drive end-to-end Trust, Risk, and Compliance programs across multiple complex regulatory and compliance regimes
  • Architect and evolve Rapid7’s TRC technology ecosystem, connecting applicability, assessment, implementation, operation, and meaningful reporting
  • Improve TRC maturity at scale, reducing uncertainty and friction while strengthening risk management outcomes
  • Operate autonomously across most situations, managing timelines, dependencies, and escalations without being chased
  • Run multiple complex initiatives in parallel with broad, cross-functional scope
  • Partner with senior leaders across Information Security, Engineering, Platform, IT, Enterprise Applications, and the business to shape direction and outcomes
  • Apply deep engineering judgment to navigate and integrate Rapid7’s technical stack, including AWS, Okta, commercial GRC platforms, Tableau, Terraform and Rapid7 products (such as InsightCloudSec, Surface Command, and InsightVM), and other security tooling
  • Leverage APIs, automation, scripting (e.g., Python), data, and AI-driven approaches to modernize how TRC operates
  • Integrate with productivity and collaboration tools (e.g., Slack, Google Workspace, Atlassian Portfolio) to deliver a seamless Trust, Risk, and Compliance experience
  • Influence how Rapid7 employees (“Moose”) think about security and compliance — shifting left, embedding controls early, and avoiding reactive cleanup
  • Fulltime
Read More
Arrow Right

Senior Manager of Crypto Operations, Risk

Join us in building the future of finance. Our mission is to democratize finance...
Location
Location
United Kingdom , London
Salary
Salary:
Not provided
robinhood.com Logo
Robinhood
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 7+ years of progressive experience in risk management within crypto, fintech, broker-dealer, payments, or adjacent financial services
  • 3+ years leading teams or owning risk programs
  • Deep understanding of crypto products and infrastructure (e.g., trading, custody, staking, on-chain transfers, wallets, keys, chain analytics) and associated operational, technology, market, liquidity, and financial crime risks
  • Demonstrated track record building and scaling risk management programs, KRIs/metrics, and governance in fast-paced, regulated environments
  • Hands-on experience with end-to-end risk assessment lifecycles, issue/incident management, and enterprise resilience (BIA/BCP/DRP)
  • Direct exposure to regulatory frameworks and expectations across multiple jurisdictions (e.g., NYDFS/BitLicense, state MSB oversight, OFAC/FinCEN, MiCA, DORA), and experience working with auditors/regulators
  • Comfortable engaging with data analytics and tools (e.g., Looker, Superset) to build dashboards and narratives
  • Exceptional communication, executive presence, and stakeholder management. Ability to influence decisions, communicate clearly, and drive outcomes across Product, Engineering, Compliance, Security, Legal, and Operations
  • Bachelor’s degree or equivalent experience required
Job Responsibility
Job Responsibility
  • Risk strategy and governance: Define and mature the crypto risk management strategy and operating model. Establish and refine risk policies, standards, and procedures. Run governance and committee reporting for risk management
  • Risk appetite and metrics: Own the Risk Appetite Statements for Crypto entities and implement a comprehensive KRI framework with thresholds, alerts, and escalation paths
  • Enterprise and product risk assessments: Lead RCSAs, Enterprise Risk Assessments, and Product/Change Risk Assessments (i.e. new feature launches like staking, and significant process/technology changes). Coordinate sufficient approvals and control implementation pre-launch
  • Issue, incident, and control management: Oversee issues and remediation plans end-to-end
  • run post-incident reviews with root-cause analysis and durable corrective actions
  • partner with first-line owners and Internal Audit on control design, testing, and continuous monitoring
  • Analytics and reporting: Build executive-ready dashboards and monthly/quarterly risk reports in collaboration with data teams (e.g., Superset, Looker)
  • deliver crisp insights, trends, and calls to action to crypto and enterprise leadership
  • prepare materials for Board/committee updates as needed
  • Regulatory and audit interface: Serve as a primary risk counterpart for regulatory examinations and supervisory touchpoints (e.g., NYDFS/BitLicense, state regulators, and MiCA/DORA)
Read More
Arrow Right

Senior Manager of Crypto Operations, Risk

Join us in building the future of finance. Our mission is to democratize finance...
Location
Location
United States , Menlo Park; New York
Salary
Salary:
183000.00 - 215000.00 USD / Year
robinhood.com Logo
Robinhood
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 7+ years of progressive experience in risk management within crypto, fintech, broker-dealer, payments, or adjacent financial services
  • 3+ years leading teams or owning risk programs
  • Deep understanding of crypto products and infrastructure (e.g., trading, custody, staking, on-chain transfers, wallets, keys, chain analytics) and associated operational, technology, market, liquidity, and financial crime risks
  • Demonstrated track record building and scaling risk management programs, KRIs/metrics, and governance in fast-paced, regulated environments
  • Hands-on experience with end-to-end risk assessment lifecycles, issue/incident management, and enterprise resilience (BIA/BCP/DRP)
  • Direct exposure to regulatory frameworks and expectations across multiple jurisdictions (e.g., NYDFS/BitLicense, state MSB oversight, OFAC/FinCEN, MiCA, DORA), and experience working with auditors/regulators
  • Comfortable engaging with data analytics and tools (e.g., Looker, Superset) to build dashboards and narratives
  • Exceptional communication, executive presence, and stakeholder management. Ability to influence decisions, communicate clearly, and drive outcomes across Product, Engineering, Compliance, Security, Legal, and Operations
  • Bachelor’s degree or equivalent experience required
Job Responsibility
Job Responsibility
  • Risk strategy and governance: Define and mature the crypto risk management strategy and operating model. Establish and refine risk policies, standards, and procedures. Run governance and committee reporting for risk management
  • Risk appetite and metrics: Own the Risk Appetite Statements for Crypto entities and implement a comprehensive KRI framework with thresholds, alerts, and escalation paths
  • Enterprise and product risk assessments: Lead RCSAs, Enterprise Risk Assessments, and Product/Change Risk Assessments (i.e. new feature launches like staking, and significant process/technology changes). Coordinate sufficient approvals and control implementation pre-launch
  • Issue, incident, and control management: Oversee issues and remediation plans end-to-end
  • run post-incident reviews with root-cause analysis and durable corrective actions
  • partner with first-line owners and Internal Audit on control design, testing, and continuous monitoring
  • Analytics and reporting: Build executive-ready dashboards and monthly/quarterly risk reports in collaboration with data teams (e.g., Superset, Looker)
  • deliver crisp insights, trends, and calls to action to crypto and enterprise leadership
  • prepare materials for Board/committee updates as needed
  • Regulatory and audit interface: Serve as a primary risk counterpart for regulatory examinations and supervisory touchpoints (e.g., NYDFS/BitLicense, state regulators, and MiCA/DORA)
What we offer
What we offer
  • Performance-driven compensation with multipliers for outsized impact, bonus programs, equity ownership, and 401(k) matching
  • 100% paid health insurance for employees with 90% coverage for dependents
  • Lifestyle wallet — a highly flexible benefits spending account for wellness, learning, and more
  • Employer-paid life & disability insurance, fertility benefits, and mental health benefits
  • Time off to recharge including company holidays, paid time off, sick time, parental leave, and more
  • Exceptional office experience with catered meals, events, and comfortable workspaces
  • Fulltime
Read More
Arrow Right
New

Senior Compliance Operations Engineer - Public Sector

The Corporate & Public Sector Strategy Team aims to accelerate Wiz’s growth by d...
Location
Location
United States
Salary
Salary:
151000.00 - 208000.00 USD / Year
wiz.io Logo
Wiz
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 7+ years of hands-on experience in cloud security engineering, compliance operations, or GRC roles
  • At least 4+ years directly supporting FedRAMP Moderate/High and DoD IL4/IL5 authorizations
  • In-depth expertise in NIST SP 800-53 Rev. 5, FedRAMP baselines (especially High), DoD Cloud SRG, and associated control overlays for IL5
  • Proven track record implementing and operating continuous monitoring in production FedRAMP and DoD IL4/IL5 environments
  • Experience with DoD-specific tools/processes (e.g., eMASS, ACAS, HBSS, STIGs)
  • Experience with DoD BCAP architecture and configuration
  • Strong experience with cloud platforms in government spaces (AWS GovCloud, Azure Government, Google Cloud for Government, or equivalent)
  • Proficiency in automation/scripting (Python, Bash, PowerShell) and Infrastructure as Code (Terraform, Ansible, Puppet/Chef preferred)
  • Familiarity with tools for compliance automation and scanning (e.g., Chef InSpec, OpenSCAP, Qualys, Tenable, AWS-native tools, Azure Security Center)
  • U.S. Citizenship required
Job Responsibility
Job Responsibility
  • Document security controls and architectures that satisfy FedRAMP High baseline requirements and DoD Cloud Computing Security Requirements Guide (SRG) overlays for Impact Level 5
  • Oversee continuous monitoring (ConMon) programs including vulnerability scanning, configuration monitoring, log aggregation/analysis, boundary protection validation, and monthly/ongoing reporting
  • Translate NIST 800-53 Rev. 5 controls and DoD-specific enhancements into operational requirements
  • partner with engineering, DevOps, and product teams to embed compliance into their processes
  • Lead preparation, evidence collection, and remediation for FedRAMP reassessments, 3PAO audits, DoD Provisional Authorizations, Significant Change Requests (SCRs), and contribute to Plan of Action & Milestones (POA&M) management
  • Automate compliance validation for control implementation verification and drift detection
  • Conduct technical risk assessments, root-cause analysis on compliance findings, and provide guidance for implementation of compensating controls or hardening measures in cloud environments
  • Support incident response and boundary protection activities in IL5 environments
  • Maintain and update compliance documentation including System Security Plans (SSP), control implementation descriptions, architectural diagrams, and boundary definitions
  • Collaborate cross-functionally with legal, product, engineering, and federal customer teams to scope new features/services while preserving authorization boundaries
What we offer
What we offer
  • Medical, dental and vision insurance
  • Home Office Setup reimbursement
  • Flexible Spending Accounts
  • Monthly Connectivity reimbursement
  • Employee Assistance Program (EAP)
  • Short- and Long-term Disability Insurance
  • Life & Accident Insurance
  • 401(k) Retirement Savings Plan (with employer match)
  • Flexible paid time off + 11 paid holidays
  • Paid leave programs, including parental, pregnancy health, medical and bereavement leave
  • Fulltime
Read More
Arrow Right

Senior Demo Engineer

We are seeking a hands-on, detail-oriented Demo Lab Architect to join our Soluti...
Location
Location
India , Chennai
Salary
Salary:
Not provided
workato.com Logo
Workato
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 3–5 years of experience in systems engineering, IT infrastructure, DevOps, or lab engineering roles
  • Experience with virtualization technologies (VMware vSphere, ESXi, or equivalent)
  • Strong understanding of Linux and Windows system administration
  • Familiarity with infrastructure automation tools (e.g., Ansible, Terraform, Packer)
  • Basic scripting skills in Python, PowerShell, or Bash
  • Experience managing cloud-based resources (e.g., AWS EC2, Azure VM)
  • Knowledge of networking concepts (VLANs, firewalls, routing, VPNs)
  • Strong problem-solving skills and the ability to work independently
  • Strong written and verbal communication skills to collaborate effectively across technical and non-technical teams
  • Able to translate technical requirements into actionable lab builds
Job Responsibility
Job Responsibility
  • Build and Maintain Demo Environments: Deploy, configure, and support virtual and physical lab infrastructure that mirrors real-world customer scenarios for technical demos, PoCs, and internal training
  • Automation and Scripting: Develop and maintain scripts (e.g., PowerShell, Python, Bash, Ansible, Terraform) to automate provisioning and configuration of lab environments. Build reusable components that accelerate demo deployments for field teams
  • Lab Infrastructure Management: Monitor performance, availability, and security of demo systems across hybrid cloud, on-premise, and virtualized environments (VMware, KVM, Hyper-V, AWS, Azure, GCP). Maintain up-to-date documentation and troubleshooting guides
  • Collaborate: Work closely with Solution Architects (SAs), Product Managers (PMs), and Field Engineering teams to ensure demo content stays aligned with product capabilities and best practices. Provide guidance and support to field teams on demo setup and usage
  • Security and Compliance: Implement and maintain lab security controls, manage access permissions, and ensure environments follow IT security and compliance guidelines. Collaborate with Business Technology (BT) and GRC teams to continuously audit demo environments
  • Version Control and Lab Updates: Maintain up-to-date snapshots and baselines of demo environments to reflect the latest product versions and configurations. Manage environment refresh cycles to ensure consistency and relevance
What we offer
What we offer
  • vibrant and dynamic work environment
  • multitude of benefits they can enjoy inside and outside of their work lives
Read More
Arrow Right

Security GRC Analyst

We’re looking for a Security GRC Analyst to help support and advance Intercom’s ...
Location
Location
Ireland , Dublin
Salary
Salary:
Not provided
intercom.com Logo
Intercom
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Experience building collaborative relationships with a diverse range of stakeholders, including executive leadership, management, Legal, Privacy, Engineering, and external auditors
  • Experience with cloud security practices, including tooling, strategy, and methodology
  • experience with AWS security is preferred
  • Knowledge of information security technologies, compliance and regulatory requirements, information governance, and privacy best practices
  • Knowledge of common information security management frameworks, such as ISO/IEC 27001, SOC 2, and HIPAA, as well as NIST frameworks including 800-53 and the NIST Cybersecurity Framework
  • Demonstrates a high level of personal integrity, with the ability to handle confidential information professionally and exercise sound judgment and maturity
  • Demonstrates the ability to scope, plan, and delegate work effectively
  • Demonstrates strong cross-functional communication skills, both written and verbal
  • Demonstrates a high degree of autonomy and ownership in their approach to work
Job Responsibility
Job Responsibility
  • Develop, enhance, and operationalise entity-level security and privacy policies, processes, and controls to mitigate risk and comply with applicable laws and regulations
  • Continuously monitor and assess Intercom’s security and privacy controls, working closely with teams such as Legal, Engineering, Sales, and Customer Support to refine and improve control design
  • Drive the implementation of security assurance strategies, including ownership of internal and external assurance resources and improvements to Intercom’s security assurance materials
  • Maintain and manage the enterprise security risk register, partnering with senior leaders to identify, assess, and reduce security risks
  • Improve operational efficiency through process improvements, technical solutions, and automation where possible
What we offer
What we offer
  • Competitive salary and equity in a fast-growing start-up
  • We serve lunch every weekday, plus a variety of snack foods and a fully stocked kitchen
  • Regular compensation reviews – we reward great work!
  • Pension scheme & match up to 4%
  • Peace of mind with life assurance, as well as comprehensive health and dental insurance for you and your dependents
  • Flexible paid time off policy
  • Paid maternity leave, as well as 6 weeks paternity leave for fathers, to let you spend valuable time with your loved ones
  • If you’re cycling, we’ve got you covered on the Cycle-to-Work Scheme, with secure bike storage too
  • MacBooks are our standard, but we also offer Windows for certain roles when needed
  • Fulltime
Read More
Arrow Right
New

Senior Technical IAM Analyst

We are seeking a Senior Technical IAM Analyst (L5) who operates with strong inde...
Location
Location
United Kingdom , London
Salary
Salary:
Not provided
deliveroo.co.uk Logo
DELIVER
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • High Ownership: Drives initiatives independently with minimal oversight
  • Risk-Oriented Thinking: Understands control design principles, not just process execution
  • Structured Problem Solver: Breaks complex systems into logical components and identifies root causes
  • Audit-Ready Mindset: Designs processes with evidence, traceability, and defensibility in mind
  • Influential Communicator: Engages engineering and business stakeholders confidently and credibly
  • Continuous Improver: Seeks efficiency, automation, and simplification at scale
  • Strong hands-on experience in IAM governance and administration in a complex environment
  • Deep understanding of: Joiners / Movers / Leavers lifecycle controls
  • User Access Reviews and certification models
  • Segregation of Duties (SoD)
Job Responsibility
Job Responsibility
  • IAM Governance & Control Ownership: Own and continuously improve Joiners/Movers/Leavers (JML) processes, ensuring completeness, accuracy, and timeliness of provisioning and deprovisioning
  • Lead and enhance User Access Reviews (UARs), ensuring SOX compliance, audit defensibility, and measurable control effectiveness
  • Identify control weaknesses, segregation of duties (SoD) conflicts, and systemic risk patterns - and implement corrective improvements
  • Act as a control owner or delegate for key IAM SOX controls, partnering with Internal Audit and GRC
  • Drive measurable reduction in manual intervention, control exceptions, and audit findings
  • Advanced Technical Execution: Design and implement IAM configurations across tools such as Okta, Azure AD, SailPoint, Conductor1, AWS IAM, or equivalent
  • Analyse and remediate complex access structures, including nested groups, 1-to-many mappings, and over-provisioned access
  • Interpret and influence infrastructure-as-code (Terraform, YAML, JSON) and workflow automations affecting identity governance
  • Collaborate with engineering teams to embed IAM controls into application architecture and CI/CD pipelines
  • Use data analytics to validate access models, detect anomalies, and assess risk exposure
What we offer
What we offer
  • Benefits differ by country, but we offer many benefits in areas including healthcare, well-being, parental leave, pensions, and generous annual leave allowances, including time off to support a charitable cause of your choice
  • A competitive and comprehensive compensation and benefits package
  • Up to 5% matched pension contributions
  • Some roles may be eligible for share awards
  • Free Deliveroo Plus: free delivery and access to special offers
  • Team lunches from the best local restaurants
  • 25 days annual leave plus bank holidays, increasing with length of time spent working at Deliveroo
  • One day of paid leave per year to volunteer with a registered charity
  • Funded single cover healthcare on our core plan, with the option to add family members at own cost
  • On-site gym (HQ), discounted external gym membership
  • Fulltime
Read More
Arrow Right