> Markdown version of [/jobs/ext/208590-grc-engineer](https://www.wearedevelopers.com/jobs/ext/208590-grc-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Engineer - **Company:** Ouro Global, Inc. - **Location:** Austin, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Applications Architecture, Microsoft Azure, Software as a Service, Cloud Computing, Identity and Access Management, Python (Programming Language), Network Security, PCI Data Security Standards, Windows PowerShell, Cloud Services, Zero Trust Network Access, SQL Databases, Data Streaming, Data Logging, Google Cloud, Mitre Att&ck, Kubernetes, Integration Frameworks, Golang - **Published:** May 14, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9c407578c787ebb2 ## About the Role Do you have experience in System risk assessment (security system operation)?, The ideal candidate has significant experience in cloud and application architectures, strong knowledge of security controls and frameworks, and the ability to translate business requirements into actionable risk mitigation strategies. This role partners closely with Product Engineering, Cloud/Infrastructure, Security Engineering, and Audit/Compliance teams., * 5+ years of experience in GRC, security engineering, architecture review, or related technical security roles. * Strong understanding of cloud platforms (AWS, GCP, Azure) and their native security controls. * Hands-on experience reviewing architecture diagrams, data flows, and engineering design patterns. * Deep familiarity with security frameworks: NIST CSF, ISO 27001/27002//27017/27018/42001, PCI-DSS, CIS, SOC 2 Trust Principles, and MITRE ATLAS/ATT&CK. * Proven ability to conduct comprehensive technical risk assessments. * AI/ML architecture/governance over MCP, RAG, and agentic workflows * API integration and orchestration * Coding and scripting capabilities using Python, SQL, Go, and Powershell * Understanding of CI/CD pipelines, container orchestration (Kubernetes), IAM, network security, and logging pipelines. * Excellent communication skills and ability to translate complex technical risks to business stakeholders., * Certifications such as CISM, CRISC, CISSP, CCSP, AWS Security Specialty, or similar. * Experience with threat modeling methodologies. * Familiarity with security-as-code and risk automation tooling. * Previous work in a high-scale fintech, SaaS, or regulated environment ## Description Job Description: We are looking for a highly technical Governance, Risk, and Compliance (GRC) Engineer to strengthen our GRC function. This individual contributor role bridges traditional GRC responsibilities with hands-on technical expertise, ensuring that risk assessments, architecture reviews, and control validations are grounded in real-world engineering practices., Risk Assessments & Control Validation * Lead technical risk assessments across applications, cloud services, third-party integrations, and internal systems. * Assess control effectiveness against frameworks such as NIST CSF, ISO 27001, SOC 2, PCI-DSS, and internal policies. * Develop and maintain detailed risk registers and mitigation plans. * Validate logging coverage, access controls, encryption configurations, and identity/security controls across cloud and infrastructure environments. Policy, Standards & Compliance Engineering * Contribute to the development and maintenance of security policies, technical standards, and architecture principles. * Translate compliance requirements into technical control specifications. * Support engineering teams in interpreting and implementing controls correctly. * Collaborate with internal audit and external auditors to provide evidence and narrative explanations for control effectiveness. Security Program Enablement * Serve as a technical advisor to product and infrastructure teams during design, build, and release cycles. * Improve risk assessment methodologies and tooling, including automation where possible. * Provide GRC insights into threat modeling, vendor security reviews, and third-party due diligence. * Support continuous improvement initiatives across governance, compliance, and risk processes. Technical Architecture Governance * Review product, application, and cloud infrastructure architectures for security control gaps, misconfigurations, and design risks. * Evaluate engineering design documents, data flow diagrams, and deployment patterns to ensure alignment with security best practices (e.g., zero trust, least privilege, secure SDLC). * Provide actionable recommendations to engineering teams to address identified risks. * Participate in security design reviews for new and evolving technologies ## Related Videos - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) - [Retooling and refactoring - an investment in people.](https://www.wearedevelopers.com/videos/371-retooling-and-refactoring-an-investment-in-people) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)