> Markdown version of [/jobs/ext/2293639-security-assurance-engineer](https://www.wearedevelopers.com/jobs/ext/2293639-security-assurance-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Assurance Engineer - **Company:** 6 Sense Insights, Inc. - **Location:** United States - **Experience:** Expert - **Salary:** $141,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Amazon S3, Automation of Tests, Software as a Service, Code Review, Continuous Integration, Data Normalization, Software Design Documents, DevOps, Identity and Access Management, Python (Programming Language), Automation of Marketing, PCI Data Security Standards, Runbook, Security Software, Security Information and Event Management, SQL Databases, Data Streaming, Policy as Code, Scripting, Cloud Platform System, Large Language Models, Git, Cloudformation, Production Code, Opsworks, Api Design, Cloudwatch, Terraform, Software Version Control, Security Orchestration, Automation & Response, Vulnerability Analysis, Programming Languages - **Published:** August 29, 2026 - **Apply:** https://boards.greenhouse.io/6sense/jobs/8139159?gh_jid=8139159 ## About the Role * 5+ years of experience being part of a GRC or similar team * 2+ years of hands-on experience building and maintaining automation, including proficiency in at least one scripting or programming language (Python preferred) and comfort working in Git, code review, and CI/CD * Demonstrated hands-on AWS experience relevant to control monitoring and evidence generation: Config, Security Hub, CloudTrail, IAM, Organizations and SCPs, Lambda, EventBridge, S3/Athena, CloudWatch * Experience retrieving, normalizing, and reconciling data across systems via APIs and SQL, and reasoning about the completeness and accuracy of that data * Practical experience applying LLMs or AI agents to real workflows, including prompt and workflow design, output evaluation, and appropriate human review and guardrails * Experience with security tools and cloud environments (e.g., GRC and compliance automation platforms, vulnerability scanners, SIEM, SOAR, AWS) * Experience with industry frameworks, regulations and standards, such as ISO 27001, SOC 2, GDPR, PCI, SOX, NIST, etc. * Ability to determine what constitutes sufficient audit evidence and to defend automated control testing and system-generated evidence to auditors Preferred Qualifications * Experience with infrastructure as code (Terraform, CloudFormation) and policy-as-code (OPA/Rego, AWS Config custom rules, cfn-guard, or similar) * Experience implementing or operating continuous control monitoring at scale in a SaaS or multi-account cloud environment * Experience integrating GRC or compliance automation platforms via API rather than through the UI * Experience building internal self-service tooling used by engineers or control owners * Big 4 (KPMG, Deloitte, PwC, EY) or similar experience * Bachelor's degree in a related field * Relevant industry certifications, such as CISSP, CISM, GIAC, AWS Certified Security - Specialty, or CCSK/CCSP, are highly desirable ## Description Build and own automated security control monitoring, continuous control monitoring, AWS evidence collection, control-failure workflows, and AI-native GRC processes. Integrate APIs and data systems, maintain cross-framework control libraries, support audits, validate remediation, administer GRC technology, and establish engineering standards for automation. Partner with Platform Engineering, DevOps, and IT to implement preventive guardrails, dashboards, self-service evidence, and measurable improvements in audit readiness and risk reduction., As members of 6sense's Security department, the Governance, Risk and Compliance (GRC) team aligns Security with business objectives while managing risks and meeting industry standards, regulations and contractual obligations. GRC enforces governance, implements risk management strategies, and ensures compliance through operating as the second line of defense., This role is the engineering capability behind that mission. Rather than testing controls after the fact, this engineer builds the systems that test them continuously. The expectation is that controls are monitored as code, technical evidence is produced automatically from AWS and other source systems, control owners can self-serve their own evidence without a GRC ticket, and AI is used as core infrastructure across GRC workflows rather than as an experiment. Audit readiness should be a byproduct of the running system, not a project. Job DescriptionResponsibilities & Accountabilities * All responsibilities of GRC Security Engineer III, and; * Design, build, and own automated security control monitoring; write production-quality code (e.g., Python) under version control, peer review, and CI/CD, and treat control logic as a maintained software asset rather than a documented procedure * Convert the control library from periodic, sample-based manual testing to continuous control monitoring (CCM): define the technical signal for each control, its test frequency, pass/fail thresholds, and alerting and escalation path * Engineer self-service technical evidence collection in AWS using native services (Config, Security Hub, CloudTrail, Organizations/SCPs, IAM Access Analyzer, Systems Manager, EventBridge, Lambda, Athena/S3, CloudWatch), so control owners and auditors retrieve current evidence on demand without GRC acting as an intermediary * Eliminate manual, screenshot-based, and ticket-driven evidence collection; retire manual test procedures as automated equivalents come online and document the transition so auditors can rely on it * Redesign GRC processes to be AI-native; apply LLMs and agentic workflows to evidence review, control mapping, gap analysis, security questionnaire and customer due diligence response, policy and procedure drafting, and risk assessment triage, with explicit human-in-the-loop review, guardrails, and output validation * Maintain a single normalized control library crosswalked across frameworks (ISO 27001, SOC 2, PCI DSS, SOX, GDPR, NIST) so that one automated test satisfies multiple obligations * Build the control-failure pipeline end to end: automated detection, enrichment, ticket creation, owner routing, SLA tracking, remediation verification, and closure, including exception and risk acceptance handling where remediation is not viable * Partner with Platform Engineering, DevOps, and IT to shift controls left into preventive guardrails: service control policies, AWS Config conformance packs, policy-as-code in CI/CD, and secure-by-default infrastructure patterns * Instrument control health reporting: automation coverage, evidence freshness, control failure rates, mean time to remediate, and audit-readiness posture, surfaced in dashboards consumable by Security leadership and control owners * Lead internal and external audit engagements with automated evidence as the primary artifact; defend automated test design, sampling logic, and the completeness and accuracy of system-generated evidence to auditors and assessors * Oversee and execute complex control tests and third-party and operational security risk assessments, using tooling and AI-assisted analysis to increase coverage and reduce cycle time, and communicate results across multiple audiences with varying levels of sensitivity * Develop issue and risk treatment plans with owners and validate remediation through automated re-testing rather than manual confirmation * Set the technical bar for the team: peer review other GRC Engineers' automation, queries, and test logic, and provide feedback, guidance, and enablement so automation ownership is distributed rather than siloed * Provide GRC technology administration, including integrations, API-based data flows, and user training and enablement * Mature security governance, training and awareness programs, using automation to target and measure them * Improve GRC handbook pages, procedures, playbooks, and technical design documentation, and maintain security program controlled documents * Execute on quarterly individual Key Results that support team Objectives (OKRs) Key Outcomes (First 12 Months) * A defined and measurable share of the control library operating under continuous monitoring, with a credible quarter-over-quarter plan to expand coverage * Technical evidence for in-scope AWS controls generated automatically and retrievable without GRC involvement * A documented reduction in audit preparation effort and evidence request turnaround time versus the prior audit cycle * At least one materially redesigned, AI-native GRC process replacing a previously manual workflow, with measured quality and throughput results * Control failures detected by the monitoring system rather than discovered during audit or assessment Performance Measurement * Increases the percentage of controls under automated, continuous monitoring and reduces the percentage tested manually * Increases the percentage of technical evidence collected without human intervention and maintains evidence freshness against defined SLAs * Reduces mean time to detect and mean time to remediate control failures * Reduces audit and assessment preparation hours and evidence request turnaround time * Ships maintainable, reviewed, version-controlled code and infrastructure with low operational failure and false-positive rates * Demonstrates measurable adoption of self-service evidence by control owners outside of GRC * Applies AI to GRC workflows with measured accuracy, appropriate review controls, and documented decisions on where AI is and is not relied upon * Maintains up-to-date knowledge of 6sense's product, environment, systems and architecture * Drives remediation of security risks and threats * Adheres to strict deadlines and SLAs * Participates in creation of, and executes on, milestones associated with major security projects * Develops and maintains up-to-date handbook pages, runbooks, workflows, dashboards, and technical design documentation for everything they own * Provides project status updates on a weekly basis * Actively prepares for weekly 1:1s with Manager and monthly skip levels * Administers GRC technology and its integrations, * Automation-first by default; treats a recurring manual GRC task as an engineering problem, not a staffing problem * Thinks like a builder and operates like an auditor: writes code that is maintainable and monitored, and control logic that is defensible and evidenced * Uses AI aggressively but skeptically; leans on it for leverage while validating output and being explicit about where human judgment is required * Designs for self-service so that GRC is not a bottleneck between control owners and their own evidence * Evangelizes security best practices * Works independently to maintain and improve overall company security posture * Collaborates with cross-functional teams, particularly engineering and platform teams, and earns credibility with them technically * Translates control intent and technical requirements into actionable, timebound, testable requests * Drives projects and tasks to completion by following up on questions, deadlines, and requests for input * Maintains accuracy of information * Proactive prioritization and escalation to management * Strong communication skills, including verbal, written, and presentation skills, and the ability to explain automated control design to both engineers and auditors ## Related Videos - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [3 Key Steps for Optimizing DevOps Workflows](https://www.wearedevelopers.com/videos/962-3-key-steps-for-optimizing-devops-workflows) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: 5 Security and Privacy Tools for Developers](https://www.wearedevelopers.com/magazine/710-the-overflow-5-security-and-privacy-tools-for-developers)