Aegis Ai logo
Posted 1h ago•United States

GRC Engineer

MiddleUnited StatesSalary undisclosed
Required Skills
PythonNext.js
Job Description

Overview

We're a team of ex-Google engineers who built some of the largest defensive platforms on the planet — Safe Browsing and reCAPTCHA. Now, we're striking out on our own to tackle an even bigger challenge: stopping the new wave of adversarial AI attacks already hitting organizations today.

We're going after a $5B+ market, ripe for disruption. Traditional detection methods are too slow to keep up. Adversaries are using AI to craft customized, high-evasion attacks — and old-school rules-based systems don't stand a chance.

The Role

We're looking for a GRC Engineer to advance AegisAI's security program. We sell to security teams, which means our buyers grade us the way we grade our own vendors: audits, frameworks, questionnaires, policies, proof. Your job is to own that proof: keep it current, airtight, and fast to produce.

The title says engineer on purpose. We run compliance the way we run infrastructure: controls mapped once across frameworks, evidence collected automatically through APIs instead of screenshots, and an audit that falls out of how we operate every day rather than a yearly scramble. You'll own our SOC 2 end to end, keep our policies current as we scale, advance the business continuity and incident response muscle behind our customer commitments, and answer the security reviews that gate our biggest deals.

You'll work directly with the head of security, our engineers, and the customers who ask the hard questions. What you build here becomes the reason deals close faster.

What You'll Do

Own Compliance end to end: Keep the program audit-ready year round and run the auditor relationship.

Pave the road to what's next: Keep us ahead of what our customers ask for, so when the business needs its next certification or framework, we're already on track.

Run our risk management program: Maintain the risk register, keep treatments moving, and ensure we have an accurate picture of risk at all times.

Own the policy suite: Keep our policies, standards and procedures current as we grow, aligned with how we operate, and clear to the customers who read them.

Own BC/DR and incident response: Maintain and exercise our plans and playbooks, own the customer notification commitments behind them, and make sure everyone knows their part before it's needed.

Answer the questions that gate deals: Own customer security questionnaires and TPRM reviews end to end, grow the answer library so answers stay accurate and consistent, and keep turnaround fast.

Run vendor and subprocessor risk: Review the vendors we depend on, keep DPAs and the subprocessor list current, scale third-party risk management as our vendor footprint grows, and handle customer data requests end to end.

Map controls across frameworks: Maintain our control set against the industry frameworks we build on, audit against it, and make one piece of evidence count everywhere it can.

Expand evidence automation: Pull more proof straight from systems through APIs and scripts, so audits and questionnaires draw from live data.

Who You Are

  • 4+ years in GRC, security compliance or audit at a SaaS company, and you've run a SOC 2 Type II end to end at least once.

  • You've answered enterprise security questionnaires and you write clearly enough that your answers close the thread.

  • Technical enough to read an architecture diagram, question an engineer's answer, and tell the difference between a control that exists and one that's written down.

  • You script. Python or similar, comfortable with APIs, and allergic to collecting the same evidence twice.

  • Working knowledge of the major privacy regimes and what they mean for a data processor.

  • Organized, self-directed, and honest about what you don't know yet.

Bonus points:

  • You've implemented ISO 27001, or carried a company through certification.

  • Compliance automation platform experience, especially custom tests and the API side of one.

  • AI governance exposure: ISO 42001, NIST AI RMF, or building an AI policy from scratch.

  • You've built or tested BC/DR for a production SaaS.

  • Privacy certifications (CIPP or similar).

  • You've worked at a security vendor and know the standard your answers get held to.

Our Culture

  • Flat, flexible, and fast.

  • You'll own your decisions.

  • You'll have clear KPIs for success — but how you get there is up to you.

  • If you want compliance work that protects our customers and wins deals instead of filling binders, and want to work with a team that moves at the speed of the real world, join us.

Similar Openings in Other

View all in category➔