> Markdown version of [/jobs/ext/2578324-security-engineer-grc](https://www.wearedevelopers.com/jobs/ext/2578324-security-engineer-grc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, GRC - **Company:** Palantir Technologies - **Location:** New York, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Spreadsheets, Cloud Computing Security, Databases, Continuous Integration, DevOps, Python (Programming Language), Parsing, Software Engineering, SQL Databases, TypeScript, Policy as Code, Google Cloud, Cloud Platform System, Git Flow, Kubernetes, Infrastructure Automation Frameworks, Api Design, Terraform, Api Management, Docker - **Published:** August 28, 2026 - **Apply:** https://www.dice.com/job-detail/4254d201-9cd7-4930-8f3b-868068f69fd7 ## About the Role * 3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRC. * Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databases. * Hands-on experience with at least one primary cloud platform, Google Cloud Platform Preferred and Infrastructure-as-Code tools such as Terraform * Deep familiarity with core frameworks such as * Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes)., * Certifications such as CISSP, CISA, CRISC, AWS Certified Security - Specialty, or CCSP. * Experience with Policy-as-Code engines * Background in software development, DevOps, or platform engineering. * Experience with modern continuous compliance platforms (e.g., Vanta, Drata, Anecdotes). ## Description In simple terms, healthcare in the U.S. has a massive, invisible problem behind the scenes: getting doctors paid by insurance companies is notoriously complicated. Insurance rules are constantly changing, and every bill (or "claim") requires mountains of paperwork. When mistakes happen, bills get rejected, patients end up with unexpected charges, and healthcare providers waste billions of dollars and countless hours on administrative bureaucracy instead of focusing on patient care., We are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots in spreadsheets; you will treat compliance as an engineering and data problem. You will build automated evidence pipelines, implement compliance-as-code, and establish continuous controls monitoring across our Google Cloud Platform infrastructure, identity systems, and CI/CD pipelines. You will turn point-in-time audits into a continuous compliance telemetry system that keeps our platform secure, resilient, and audit-ready at all times., 1) Compliance Automation & Engineering * Develop automated scripts and API integrations to collect compliance evidence directly from system sources instead of collecting manual screenshots. * Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically. * Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time. * Partnering with Legal on Medicare and Medicaid compliance * Partnering closely with legal and finance teams on future due diligence and compliance projects 2) Framework Mapping & Control Architecture * Convert regulatory, security, and industry standards (SOC 2, HiTrust, PCI, HIPAA) into clear, testable technical controls. * Map single technical controls across multiple overlapping frameworks to eliminate redundant work. * Work alongside DevOps and Software Engineering teams to build compliance controls directly into CI/CD pipelines without slowing down delivery. 3) Risk Management & Audits * Lead technical audit readiness and external audit engagements using programmatic evidence pipelines. * Automate vendor risk management workflows and API-driven vendor evaluations. * Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs rather than static quarterly surveys. ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers)