> Markdown version of [/jobs/ext/1497930-cyber-security-grc-engineer](https://www.wearedevelopers.com/jobs/ext/1497930-cyber-security-grc-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security & GRC Engineer - **Company:** EMERGENT STAFFING, LLC - **Location:** Hartford, CT, United States - **Experience:** Expert - **Salary:** $150,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing Security, Cyber Security, Information Systems, Data Security, Identity and Access Management, Cloud Services, Phishing, Software Deployment, Systems Integration, Software Vulnerability Management, Data Logging, IT General Controls (ITGC), Information Technology, Data Management - **Published:** July 30, 2026 - **Apply:** https://jobs.emergentsoftware.net/o/senior-cyber-security-grc-engineer ## About the Role * Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent experience. * 7+ years of information security, cybersecurity, or risk management experience with progression into senior program ownership responsibilities. * Hands-on experience administering a GRC platform, preferably Vanta. * Experience implementing, operating, or auditing against NIST CSF, SOX ITGC, and GDPR requirements. * Demonstrated success developing and implementing security policies, controls, and governance programs. * One or more of the following certifications: CISSP, CISM, CRISC, or CISA. * Strong technical knowledge of cloud security, identity and access management, endpoint security, vulnerability management, logging, and security operations. * Excellent communication skills with the ability to engage technical teams, business leaders, auditors, and executives. * Proven ability to work independently, manage multiple priorities, and drive accountability across stakeholders. Nice to Have Experience * Direct Vanta administration experience. * Experience supporting a publicly traded company and SOX Section 404 compliance requirements. * Experience leading security programs across multiple organizations or business entities. * ISO 27001 Lead Implementer or Lead Auditor certification. * SANS/GIAC certifications. * Construction, engineering, energy, power generation, or EPC industry experience. * Familiarity with AI/ML governance, data security, and secure AI deployment practices. ## Description Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations. This is a senior-level, hands-on leadership role responsible for developing a unified security and compliance framework that supports NIST CSF 2.0, GDPR, and SOX IT General Controls requirements. The ideal candidate combines strategic leadership with technical expertise, comfortably engaging executive stakeholders and auditors while also administering security tools, managing risks, implementing controls, and driving compliance initiatives. This role will serve as the owner of the enterprise GRC platform, Vanta, ensuring continuous monitoring, audit readiness, and program maturity across all entities., * Own and mature the enterprise cybersecurity and risk management program across a multi-entity organization. * Design, implement, and maintain a harmonized control framework supporting NIST CSF 2.0, GDPR, and SOX ITGC requirements. * Lead enterprise governance activities, including risk reviews, KPI/KRI reporting, executive reporting, and steering committee meetings. * Serve as the primary liaison for auditors, assessors, clients, and internal stakeholders regarding security and compliance matters. * Administer and optimize Vanta as the enterprise GRC system of record. * Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit workflows within Vanta. * Develop, maintain, and manage enterprise security policies, standards, procedures, exceptions, and policy lifecycle processes. * Lead SOX ITGC readiness and compliance efforts. * Operationalize GDPR requirements, including records of processing, DPIAs, data subject rights management, vendor oversight, and breach response. * Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning. * Manage enterprise risk assessments, risk registers, third-party vendor risk programs, and remediation initiatives. * Oversee vulnerability management, patch coordination, access reviews, and technical security controls across cloud and on-premises environments. * Lead incident response activities, including preparation, detection, containment, recovery, and post-incident reviews. * Provide security architecture guidance for new systems, integrations, cloud solutions, and data platforms. * Build and manage security awareness, phishing simulation, and employee training programs. * Partner with business and project teams to ensure security and privacy requirements are incorporated into solution design., At Emergent Staffing, we work hard to find the best tech candidates capable of developing high quality results for our clients. If you think you're one of those, please understand that the effort put into this by people like yourself helps us be successful in surrounding you with other top-notch engineers. Here are the steps of our vetting process for this position: * Application (5 minutes) * Online Assessment (60 minutes) * Initial Phone Interview (30-45 minutes) * Virtual Interview with Hiring Manager (30 minutes) * Onsite Interview * Leadership Team Meeting (if needed) * Job Offer! ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)