Commercial GRC Engineer - Sr. Security Engineer I
Bellevue, United States · Hybrid · Full-time
- Posted 1w ago
- From Smartsheet’s careers page
- Location
- Bellevue, United States
- Work mode
- Hybrid
- Type
- Full-time
- Level
- Senior
- Experience
- 4+ years
- Department
- Other
Apply on Smartsheet’s site
Opens the listing on job-boards.greenhouse.io
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
You Will:
- Own control automation for SOC 2, ISO 27001/27017/27701, HIPAA, and related commercial frameworks: design and build automated evidence collection and continuous control monitoring across cloud, identity, endpoint, and SaaS systems.
- Express controls, control tests, and cross-framework mappings as version-controlled code so they are reviewable, testable, and reusable rather than locked in a single tool's configuration.
- Translate compliance requirements into technical control logic, workflows, and integrations, partnering with engineering, IT, and security teams to embed controls into existing systems and pipelines rather than bolting them on after the fact.
- Shift compliance left by participating in architecture and design reviews, defining control requirements as acceptance criteria for new systems, and helping teams build compliant-by-default infrastructure.
- Design the engineer-facing experience of compliance: self-service control status, guardrails and paved-road patterns, and compliance feedback delivered in the tools teams already use (CI/CD, Jira, Slack) rather than only in the GRC platform.
- Evaluate whether controls actually reduce relevant risk—not just whether they exist—and propose alternative controls when a framework default doesn't fit our threat model or workload architecture.
- Support full audit cycles end-to-end: coordinate evidence requests, populate and maintain the evidence library, respond to auditor follow-ups, and track remediation items through closure for SOC 2, ISO, and HIPAA assessments.
- Build and maintain dashboards and reporting that give GRC and security leadership real-time visibility into control health, evidence freshness, and audit readiness across frameworks.
- Identify and eliminate duplicate evidence-gathering effort across overlapping frameworks by mapping controls once and reusing that mapping across SOC 2, ISO, and HIPAA.
- Diagnose the root causes of recurring control failures or stale evidence and fix the underlying process, tooling, or ownership gap rather than the symptom.
- Partner with the GRC Team Lead and SATellite engineering to extend our internal GRC platform's control, evidence, and risk-lifecycle capabilities.
You Have:
- 4+ years of experience in GRC engineering, security engineering, compliance automation, or IT audit support, with hands-on ownership of at least one full certification cycle (SOC 2, ISO 27001, or similar).
- Practical, hands-on experience with GRC or compliance automation platforms (Vanta, Drata, Secureframe, or a homegrown equivalent), including configuring integrations and building evidence pipelines—not just reading dashboards.
- Experience with cloud security fundamentals (AWS/GCP/Azure IAM, logging, encryption) and how they map to control requirements.
- Solid working knowledge of SOC 2, ISO 27001 (and ideally 27017/27701), and HIPAA control requirements, and the ability to map controls across frameworks to avoid duplicated evidence work.
- Comfort with scripting or light development (Python, JavaScript, or similar) to build integrations, automate evidence pulls via API, or extend GRC tooling.
- Strong written communication; you can document a control, a gap, and a remediation plan clearly enough that an external auditor and an internal engineer both understand it.
- A stakeholder-centric mindset: you measure success by how easy it is for engineers to stay compliant, not just by how quickly GRC can produce evidence.
- Demonstrated ability to trace a control failure or audit finding back to its root cause and drive a durable fix across teams.
- Legally eligible to work in the U.S. on an ongoing basis.
Skills they ask for
Pick one to see other roles that ask for it.
About Smartsheet
Work management for teamsSmartsheet provides a work management platform with AI capabilities for connecting systems, running projects and helping teams act faster.
See all 45 roles at SmartsheetMore roles at Smartsheet
See all 45- Product Operations Manager (Remote Eligible)United States · RemoteProduct Management · RemoteUnited States1d
- Senior Product Manager – People SystemsUnited States · Senior · RemoteProduct Management · Senior · RemoteUnited States1d
- Enterprise Account Executive - State/Local Government (PNW)Boise · RemoteSales · RemoteBoise, United States2d
- Enterprise Account Executive - State/Local Government (PNW)San Francisco · Senior · RemoteSales · Senior · RemoteSan Francisco, United States2d
Share this role
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.