> Markdown version of [/jobs/ext/3115351-senior-security-grc-engineer-ai-automation](https://www.wearedevelopers.com/jobs/ext/3115351-senior-security-grc-engineer-ai-automation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security GRC Engineer, AI & Automation - **Company:** Global Business Travel Group, Inc. - **Location:** Cheyenne, WY, United States - **Experience:** Expert - **Salary:** $104,300.0 - $193,700.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Business Systems, Cyber Security, Information Systems, Computer Programming, Databases, Python (Programming Language), Machine Learning, PCI Data Security Standards, Data Streaming, Value Engineering, Workflow Management Systems, Scripting, Delivery Pipeline, Large Language Models, Information Technology, Data Analytics, RSA Archer Platform, Api Design - **Published:** September 27, 2026 - **Apply:** https://dejobs.org/x/x/8755A933D1B64BC086EE990A204A61D7/job/ ## About the Role AmexGBT's Security GRC team is looking for a talented Senior Security GRC Engineer to design, build, and scale automation and AI-driven solutions that modernize our governance, risk, and compliance program. This role sits at the intersection of security engineering and GRC, translating manual, evidence-heavy processes into automated, data-driven workflows. The ideal candidate combines hands-on engineering skills with a strong understanding of GRC principles, and is excited to apply AI and automation to reduce risk, improve control coverage, and free up the team to focus on higher-value analysis., * Bachelor's degree in computer science, information security, information systems, or a related field (or equivalent experience). * 5+ years of experience in security engineering, GRC, or a related field, with demonstrated experience building automation or AI-enabled solutions. * Strong programming/scripting skills (e.g., Python, JavaScript, or similar) and experience working with APIs, databases, and workflow automation tools. * Hands-on experience applying AI or machine learning technologies (including LLMs and generative AI) to real-world business or security use cases. * Solid understanding of cybersecurity frameworks (NIST, ISO 27001, SOC 2) and regulatory compliance requirements (GDPR, PCI DSS). * Experience with GRC platforms such as Onspring, Archer, MetricStream, or similar tools, including configuration or integration work. * Familiarity with risk assessment methodologies, control frameworks, and audit evidence requirements. * Strong analytical and problem-solving skills, with the ability to translate complex, manual processes into automated solutions. * Excellent communication and reporting skills, with the ability to present technical solutions and their risk/compliance impact to both technical and non-technical stakeholders. ## Description * Design, build, and maintain automation pipelines that continuously collect, normalize, and validate compliance and control evidence across security and business systems. * Evaluate, prototype, and deploy AI and large language model (LLM)-based solutions to accelerate GRC workflows, including control testing, evidence review, policy mapping, and risk narrative generation. * Integrate GRC tooling (e.g., Onspring, Archer, MetricStream, or similar platforms) with security and IT systems via APIs to enable automated data flows, dashboards, and reporting. * Develop and maintain scripts, bots, and workflow tools that automate recurring GRC tasks such as evidence gathering, control monitoring, and audit preparation. * Partner with Security GRC analysts and program managers to identify manual, repetitive processes and re-engineer them into scalable, automated solutions. * Establish guardrails, testing, and quality controls to ensure AI-assisted outputs are accurate, explainable, and compliant with regulatory and audit requirements. * Monitor and report on the performance, reliability, and risk posture of automation and AI tools used within the GRC program. * Stay current with emerging AI, automation, and GRC technologies, and recommend adoption of new tools and techniques to continuously improve program maturity. * Collaborate with other AmexGBT teams (security, engineering, data, and business) to align automation initiatives with broader security posture and compliance goals., * Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family. * Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals. * Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first. * We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action. * And much more! All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law. Click Here (https://explorer.amexglobalbusinesstravel.com/rs/346-POJ-129/images/Additional%20Disclosures%20in%20Accordance%20with%20the%20LA%20County%20Fair%20Chance%20Ordinance.pdf?version=2) for Additional Disclosures in Accordance with the LA County Fair Chance Ordinance. ## Related Videos - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [API Design - Getting Started](https://www.wearedevelopers.com/videos/33-api-design-getting-started) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)