> Markdown version of [/jobs/ext/1452383-grc-engineer](https://www.wearedevelopers.com/jobs/ext/1452383-grc-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Engineer - **Company:** Legora, Inc. - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $188,000.0 - $221,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software as a Service, Continuous Integration, Human Resources Information System (HRIS), Information Technology Audit, Python (Programming Language), Software Product Management, Data Logging, Large Language Models, Core Api, Control Language, Terraform, Software Version Control - **Published:** July 26, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3b5448786fd9f591 ## About the Role * 5+ years spanning software or automation engineering and security compliance - an engineer who learned GRC, or a GRC operator who became a builder. * Production-grade scripting (Python or similar) against APIs - code you ship and own. * Hands-on experience building LLM/agent workflows and daily use of AI in your own work, with grounded judgment on what to delegate to agents, what needs a human, and how to evidence both to an auditor. * Enough GRC domain fluency to work inside SOC 2 / ISO 27001 control language and know what an auditor will accept as evidence. * Clear technical writing - your evidence and documentation will be read by auditors and customer security teams. NICE TO HAVE * Experience with compliance platform APIs and when to build past them. * OSCAL or other machine-readable control/catalog formats. * Infrastructure-as-code (Terraform or similar) and CI/CD pipeline engineering. * Prior work on AI product assurance: evals, red-teaming evidence, or model/agent documentation. ## Description You will build the platform Legora's assurance program runs on: pipelines that collect evidence continuously, checks that enforce policy in CI/CD, and agents that test controls and draft audit responses. The GRC Lead owns the program and the judgment calls; you own the machinery that turns certifications into an output of normal operations. You will sit in the Security organization and work daily with the GRC Lead, Engineering, and Corporate Security. This is an engineering seat with a compliance domain, and it exists because we sell AI agents to law firms: proving how our systems behave is part of the product., * Build the pipelines and integrations that aggregate control, asset, and identity data across our stack (cloud, IdP, HRIS, source control, CI/CD) and turn it into automated checks, live dashboards, and audit evidence. * Implement the unified controls library so one control satisfies many frameworks, with evidence collected once and mapped everywhere. * Ingest from what partners already own - Corporate Security's technical controls, the SaaS portfolio's system of record - rather than building parallel collectors; system owners keep their evidence, your platform makes it audit-ready. * Build the technical evidence base for our AI certifications (ISO/IEC 42001 and emerging AI-agent assurance standards): agent action logging, evaluation evidence, tool-call restrictions, and failure-mode documentation, working with Product and Engineering. Continuous assurance & agentic workflows * Translate written policies and regulatory requirements into enforceable rules: automated checks in CI/CD and infrastructure deployment, continuous controls monitoring, and drift alerts routed to owners. * Instrument control effectiveness so the GRC Lead reports risk posture from live data. * Design and run agentic workflows for evidence analysis, control testing, and audit response preparation, with a human in the loop where assurance demands it. Anything manual twice a quarter gets automated. ## Related Videos - [Insights from building the Canva Developers Platform to empower 185 million designers](https://www.wearedevelopers.com/videos/942-insights-from-building-the-canva-developers-platform-to-empower-185-million-designers) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [Why make use of an integration platform in today's software developments and infrastructure?](https://www.wearedevelopers.com/videos/758-why-make-use-of-an-integration-platform-in-today-s-software-developments-and-infrastructure) - [Building a Multi-Agent Orchestration Engine That Actually Follows the Rules](https://www.wearedevelopers.com/videos/100159-building-a-multi-agent-orchestration-engine-that-actually-follows-the-rules) ## Related Articles - [What Are Large Language Models?](https://www.wearedevelopers.com/magazine/304-what-are-large-language-models) - [What is Agentic Programming and Why Should Developers Care?](https://www.wearedevelopers.com/magazine/625-what-is-agentic-programming-and-why-should-developers-care) - [13 AI Tools You Have to Try](https://www.wearedevelopers.com/magazine/219-13-ai-tools-you-have-to-try) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Graph and AI Trends 2026: Why Is AI Running but Not Yet Delivering?](https://www.wearedevelopers.com/magazine/680-graph-and-ai-trends-2026-why-is-ai-running-but-not-yet-delivering) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)