> Markdown version of [/jobs/ext/1153278-security-engineer-grc](https://www.wearedevelopers.com/jobs/ext/1153278-security-engineer-grc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, GRC - **Company:** Ivy Rehab Network - **Location:** Philadelphia, PA, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Information Systems, Information Leak Prevention, Information Systems Security Architecture Professional, Smartsuite, Phishing, Security Information and Event Management, Scripting, Data Classification, Information Technology, No-code Tools, Low-code, RSA Archer Platform, Servicenow - **Published:** July 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=594f32d719d752a7 ## About the Role * Minimum 3-5 years of experience in Cybersecurity, with a focus on GRC or third-party risk management. * Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field. * Excellent communication, collaboration, and problem-solving skills * Relevant security certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM). + GIAC certifications, Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) are a plus. * Former NOC/SOC experience is highly desired. * Deep understanding of security frameworks and standards such as NIST CSF, HIPAA, HITRUST. * Proven ability to analyze vendor security documentation (SOC 2 Type II, SIG questionnaires, penetration test reports). * Experience utilizing GRC platforms (e.g., SmartSuite, Archer, ServiceNow GRC, or similar), low-code/no-code platforms, or scripting to automate security processes and compliance mapping. * Excellent communication and collaboration abilities - able to explain complex risk concepts to non-technical stakeholders and work cross-functionally to drive security initiatives. ## Description The Security Engineer will manage, scale, and automate our Governance, Risk, and Compliance (GRC) program supporting an organization of 7,500+ teammates across 750+ locations. This role focuses on building security policies, automating compliance workflows, and conducting third-party vendor risk assessments. Additionally, you will provide secondary engineering and analytical support to optimize our MSSP relationship, triage alerts, and refine SOC use cases. This role is primarily remote, with occasional travel required for projects, collaboration, and team building., * Lead the design, rollout, and continuous improvement of the internal GRC framework and security architecture. * Author, maintain, and help enforce information security policies, procedures, and control frameworks across the business. * Identify opportunities to automate compliance tracking, evidence collection, and risk reporting workflows to eliminate manual processes. * Ensure organizational alignment with industry standards (e.g., NIST CSF, HIPAA, HITRUST) and facilitate internal or external security assessments. * Own the end-to-end third-party risk assessment process; evaluate vendor security postures, SOC 2 reports, and risk profiles prior to onboarding. * Partner with legal, procurement, and business stakeholders to communicate vendor risks and negotiate necessary security safeguards. * Manage and monitor the Data Loss Prevention (DLP) solution; triage data exfiltration alerts and partner with business units to implement, enforce, and refine data classification schemas * Drive the security awareness training strategy; oversee automated phishing campaigns, measure program effectiveness, and deliver tailored education to mitigate human risk. * Provide secondary support to SOC operations by validating alert triage and improving detection logic * Collaborate to improve SIEM/SOC use cases, detection logic, and incident response workflows. ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Reimagining app development with Low-code and AI](https://www.wearedevelopers.com/videos/1651-reimagining-app-development-with-low-code-and-ai) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)