Security GRC Specialist

ONE STOP COLLECTIBLE CORP
New York, NY, United States
2 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$150,000.0 - $240,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Cloud Computing Cloud Engineering DevOps Identity and Access Management Data Streaming Workflow Management Systems

Job description

  • Own and operate our compliance frameworks: SOC 2, ISO 27001, GDPR, and others as we grow
  • Drive audits end to end: readiness, evidence collection, auditor coordination
  • Continuously improve controls and reduce compliance overhead through automation
  • Lead responses to enterprise security questionnaires, RFPs, and due diligence requests
  • Partner with Sales and Customer Success to unblock deals and build trust with security teams at Fortune 500 customers
  • Develop and maintain our trust center, security whitepapers, and customer-facing documentation
  • Work directly with engineering to design and implement practical security controls across our cloud infrastructure, data pipelines, and customer-facing surfaces
  • Partner on identity and access work (SSO, SAML, SCIM, IdP integrations) where security, compliance, and customer-facing requirements intersect
  • Translate compliance requirements into technical, scalable solutions
  • Identify gaps and drive remediation, not just report them
  • Run risk assessments across systems, vendors, and processes
  • Maintain policies and standards that are lightweight, current, and actually useful
  • Track and report on our security posture and compliance status to leadership
  • Improve how we manage compliance: evidence collection, control mapping, automation
  • Evaluate and implement GRC and security tooling where it earns its keep

Requirements

  • 3 to 7+ years in security GRC, compliance, or adjacent security engineering roles
  • Hands-on experience with SOC 2, ISO 27001, or similar frameworks
  • Experience supporting audits and leading customer-facing security conversations
  • Comfortable working with engineers and reasoning about cloud infrastructure, APIs, identity systems, and data flows
  • Able to translate between compliance language and engineering reality in both directions
  • Experience with modern cloud environments (AWS, GCP, or Azure) is a strong plus
  • Proactive and hands-on: you drive changes, you don’t just track them
  • Comfortable balancing rigor with pragmatism in a fast-moving environment
  • Strong written communication, especially with enterprise customers and cross-functional partners
  • Experience building or scaling a GRC program from early stages
  • Familiarity with automation in compliance workflows
  • Background in security engineering, DevOps, or identity and access management

Benefits & conditions

For this role, the expected base salary range is $150,000 to $240,000, depending on experience. Profound’s total compensation package includes base salary, equity, and a full range of benefits and perks. Final compensation will depend on factors such as your skills, experience, qualifications, and location, and will be determined during the interview process. Our recruiting team will share more details about the full compensation package and benefits as you move through hiring.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:50 min

Lowering pipeline latency with data streaming

Nathaniel Okenwa Nathaniel Okenwa · World Congress 2024

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · World Congress 2022

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all