> Markdown version of [/jobs/ext/2712777-security-grc-specialist](https://www.wearedevelopers.com/jobs/ext/2712777-security-grc-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security GRC Specialist - **Company:** ONE STOP COLLECTIBLE CORP - **Location:** New York, NY, United States - **Experience:** Experienced - **Salary:** $150,000.0 - $240,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Engineering, DevOps, Identity and Access Management, Data Streaming, Workflow Management Systems - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/security-grc-specialist-profound-8028650 ## About the Role * 3 to 7+ years in security GRC, compliance, or adjacent security engineering roles * Hands-on experience with SOC 2, ISO 27001, or similar frameworks * Experience supporting audits and leading customer-facing security conversations * Comfortable working with engineers and reasoning about cloud infrastructure, APIs, identity systems, and data flows * Able to translate between compliance language and engineering reality in both directions * Experience with modern cloud environments (AWS, GCP, or Azure) is a strong plus * Proactive and hands-on: you drive changes, you don't just track them * Comfortable balancing rigor with pragmatism in a fast-moving environment * Strong written communication, especially with enterprise customers and cross-functional partners * Experience building or scaling a GRC program from early stages * Familiarity with automation in compliance workflows * Background in security engineering, DevOps, or identity and access management ## Description * Own and operate our compliance frameworks: SOC 2, ISO 27001, GDPR, and others as we grow * Drive audits end to end: readiness, evidence collection, auditor coordination * Continuously improve controls and reduce compliance overhead through automation * Lead responses to enterprise security questionnaires, RFPs, and due diligence requests * Partner with Sales and Customer Success to unblock deals and build trust with security teams at Fortune 500 customers * Develop and maintain our trust center, security whitepapers, and customer-facing documentation * Work directly with engineering to design and implement practical security controls across our cloud infrastructure, data pipelines, and customer-facing surfaces * Partner on identity and access work (SSO, SAML, SCIM, IdP integrations) where security, compliance, and customer-facing requirements intersect * Translate compliance requirements into technical, scalable solutions * Identify gaps and drive remediation, not just report them * Run risk assessments across systems, vendors, and processes * Maintain policies and standards that are lightweight, current, and actually useful * Track and report on our security posture and compliance status to leadership * Improve how we manage compliance: evidence collection, control mapping, automation * Evaluate and implement GRC and security tooling where it earns its keep ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Python-Based Data Streaming Pipelines Within Minutes](https://www.wearedevelopers.com/videos/1233-python-based-data-streaming-pipelines-within-minutes) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)