Senior Security Engineer II
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are seeking a Senior Security Engineer to design and implement a scalable Governance, Risk, and Compliance (GRC) foundation across our cloud-based environment. This role will focus on standardizing controls, improving ownership visibility, and enabling automated evidence collection to support continuous compliance across SOC 2, ISO 27001, Cyber Essentials, and related frameworks. This is a transformation-focused role. The successful candidate will partner with compliance, security, and engineering teams to move the organization from a manual, audit-driven model to a structured, automation-enabled GRC program.
Responsibilities
GRC Platform Implementation & Automation
-
Lead implementation and administration of a GRC platform (e.g., Vanta)
-
Configure controls, evidence mapping, and integrations (AWS, identity systems, etc.)
-
Establish automated evidence collection and continuous monitoring
-
Reduce reliance on manual evidence gathering
Control Framework Development
-
Develop and maintain a unified control framework aligned to SOC 2, ISO 27001, and other standards
-
Define control statements, evidence requirements, and testing expectations
-
Map controls across frameworks to reduce duplication
-
Maintain traceability between controls and evidence
Ownership & System Mapping
-
Establish team-based ownership model for controls
-
Align systems and services to responsible teams
-
Maintain lightweight system inventory
-
Improve ownership visibility to reduce audit coordination overhead
Audit Enablement
-
Support audit readiness through well-defined and monitored controls
-
Partner with compliance team to streamline audits
-
Enable evidence reuse across frameworks
Process Standardization & Continuous Improvement
-
Standardized documentation and workflows
-
Improve efficiency and reduce audit fatigue
-
Support policy and standards development
-
Define and track compliance metrics, leveraging automation and data analytics to support continuous audit readiness and control effectiveness
-
All other duties as assigned
Requirements
-
Bachelor’s degree in Computer Science, Information Security, Information Systems, or a related technical field, or equivalent practical experience
-
5+ years of experience in security, compliance, or audit-focused roles
-
Proven experience leading ISO/IEC 27001 and SOC 2 audits end-to-end
-
Hands-on experience with a GRC platform (AuditBoard, Drata, Vanta, or similar) - required
-
Strong understanding and experience with control frameworks
-
Ability to translate technical implementations into audit-ready controls and documentation
-
Strong stakeholder management and auditor-facing communication skills
-
Experience in cloud-native or SaaS environments (AWS, Azure, or GCP preferred)
Preferred Qualifications
-
Experience with automation and continuous compliance
-
Certifications such as CISSP, CISA, CRISC, or ISO 27001 Lead Implementer/Auditor
-
Multi-framework experience
-
Experience scaling compliance programs in high-growth environments
About the company
LexisNexis, a part of RELX, is a leading global provider of legal, regulatory, and business information. We help customers increase productivity and improve decision-making and outcomes. Our 10,500 experts and innovative tools help us shape a better world for our customers and communities., LexisNexis Legal & Professional is proud to be an equal-opportunity employer. We are committed to equal opportunity employment regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. Together, we are building a diverse and inclusive workplace.
Working for you
We believe in a healthy work/life balance. We know that your well-being and happiness are key to a long and successful career. These are some of the benefits we are delighted to offer:
- Comprehensive, multi-carrier health plan benefits - Disability insurance - Dependent care and commuter spending accounts - Life and accident insurance - Retirement benefits (salary investment plan/employer stock purchase plan) - Modern family benefits, including adoption and surrogacy
About our Team
LexisNexis is a data and analytics company with 10,500 colleagues serving customers in more than 150 countries. We’re one of the largest information and analytics companies on the planet. We design solutions that help our customers increase productivity, improve decision-making and outcomes, and be more successful., RELX is a global provider of information-based analytics and decision tools for professional and business customers, enabling them to make better decisions, get better results and be more productive.
Our purpose is to benefit society by developing products that help researchers advance scientific knowledge; doctors and nurses improve the lives of patients; lawyers promote the rule of law and achieve justice and fair results for their clients; businesses and governments prevent fraud; consumers access financial services and get fair prices on insurance; and customers learn about markets and complete transactions.
Our purpose guides our actions beyond the products that we develop. It defines us as a company. Every day across RELX our employees are inspired to undertake initiatives that make unique contributions to society and the communities in which we operate.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.juju.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
What Are The Top Skills Required For Azure Developers?
What’s the Difference between a Junior, Mid, and Senior Developer?
Best Companies to work for in London: Top 25 Companies in 2023