> Markdown version of [/jobs/ext/1248987-security-grc-specialist](https://www.wearedevelopers.com/jobs/ext/1248987-security-grc-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security GRC Specialist - **Company:** Modal Labs - **Location:** New York, NY, United States - **Experience:** Experienced - **Salary:** $150,000.0 - $270,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Engineering, DevOps - **Published:** July 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e67358971e3f71f1 ## About the Role * Core Experience + 3-7+ years in security GRC, compliance, or security engineering-adjacent roles + Hands-on experience with frameworks like SOC 2, ISO 27001, or similar + Experience supporting audits and customer-facing security conversations Technical Mindset (Important) + Comfortable working with engineers and understanding systems (cloud, infra, APIs, etc.) + Ability to translate between compliance language and technical implementation + Experience with modern cloud environments (AWS/GCP/Azure) is a strong plus Execution & Ownership + Proactive and hands-on-you drive changes, not just track them + Able to balance rigor with pragmatism in a fast-moving environment + Strong communication skills, especially with customers and cross-functional teams Bonus + Experience building or scaling a GRC program from early stages + Familiarity with automation in compliance workflows + Background in security engineering or DevOps ## Description We're looking for a hands-on Security GRC Specialist to own and scale our security and compliance programs while working closely with engineering and product teams. This role is central to building customer trust, enabling sales, and ensuring we meet evolving regulatory and security expectations without slowing down innovation. You won't just maintain compliance, you'll help shape how we build secure systems. What You'll Do: Compliance & Security Programs * Own and operate compliance frameworks (e.g., SOC 2, ISO 27001, GDPR, etc.) * Drive audits end-to-end: readiness, evidence collection, auditor coordination * Continuously improve controls and reduce compliance overhead through automation Customer Trust & Sales Enablement * Lead responses to customer security questionnaires, RFPs, and due diligence requests * Partner with Sales and Customer Success to unblock deals and build trust * Develop and maintain security documentation (trust center, whitepapers, FAQs) Engineering Collaboration * Work directly with engineering teams to design and implement practical security controls * Translate compliance requirements into technical, scalable solutions * Identify gaps and drive remediation projects (not just report them) Risk & Governance * Run risk assessments across systems, vendors, and processes * Maintain policies and standards, but keep them lightweight and actionable * Track and report on security posture and compliance status Process & Tooling * Improve how we manage compliance (evidence collection, control mapping, automation) * Evaluate and implement GRC/security tools where appropriate ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)