> Markdown version of [/jobs/ext/3376753-security-grc-engineer-ai-automation](https://www.wearedevelopers.com/jobs/ext/3376753-security-grc-engineer-ai-automation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security GRC Engineer, AI & Automation - **Company:** Amex Gbt - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $104,000.0 - $194,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Business Systems, Software as a Service, Cyber Security, Information Systems, Computer Programming, Databases, Python (Programming Language), Machine Learning, PCI Data Security Standards, Data Streaming, Value Engineering, Workflow Management Systems, Scripting, Delivery Pipeline, Large Language Models, Information Technology, Data Analytics, RSA Archer Platform, Api Design - **Published:** September 26, 2026 - **Apply:** https://www.builtincolorado.com/job/senior-security-grc-engineer-ai-automation/11383663?handler=ApplyRedirect ## About the Role * Bachelor's degree in computer science, information security, information systems, or a related field (or equivalent experience). * 5+ years of experience in security engineering, GRC, or a related field, with demonstrated experience building automation or AI-enabled solutions. * Strong programming/scripting skills (e.g., Python, JavaScript, or similar) and experience working with APIs, databases, and workflow automation tools. * Hands-on experience applying AI or machine learning technologies (including LLMs and generative AI) to real-world business or security use cases. * Solid understanding of cybersecurity frameworks (NIST, ISO 27001, SOC 2) and regulatory compliance requirements (GDPR, PCI DSS). * Experience with GRC platforms such as Onspring, Archer, MetricStream, or similar tools, including configuration or integration work. * Familiarity with risk assessment methodologies, control frameworks, and audit evidence requirements. * Strong analytical and problem-solving skills, with the ability to translate complex, manual processes into automated solutions. * Excellent communication and reporting skills, with the ability to present technical solutions and their risk/compliance impact to both technical and non-technical stakeholders., Leads revenue recognition, billing, accounts receivable, collections, audit readiness, and financial control operations. Ensures ASC 606 and GAAP compliance, manages billing platforms and ERP integrations, drives automation and AI adoption, develops scalable processes, partners cross-functionally, reports financial metrics, and supervises accounting staff. Requires extensive revenue accounting and billing experience in SaaS or software, management expertise, and strong technical accounting knowledge. Top Skills: Ai-Enabled Accounting Automation ToolsBilling PlatformsErp SystemsExcelMicrosoft OutlookMicrosoft WordNetSuiteOracleSAP ## Description Design and scale automation and AI-driven solutions for security governance, risk, and compliance. Build pipelines to collect and validate evidence, integrate GRC platforms with security and IT systems, automate control monitoring and audit preparation, and deploy LLM-based workflows for testing, policy mapping, and risk reporting. Establish AI guardrails and quality controls while collaborating with security, engineering, data, and business teams to improve compliance and security posture. The summary above was generated by AI Amex GBT is a place where colleagues find inspiration in travel as a force for good and - through their work - can make an impact on our industry. We're here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued. AmexGBT's Security GRC team is looking for a talented Senior Security GRC Engineer to design, build, and scale automation and AI-driven solutions that modernize our governance, risk, and compliance program. This role sits at the intersection of security engineering and GRC, translating manual, evidence-heavy processes into automated, data-driven workflows. The ideal candidate combines hands-on engineering skills with a strong understanding of GRC principles, and is excited to apply AI and automation to reduce risk, improve control coverage, and free up the team to focus on higher-value analysis. What You'll Do * Design, build, and maintain automation pipelines that continuously collect, normalize, and validate compliance and control evidence across security and business systems. * Evaluate, prototype, and deploy AI and large language model (LLM)-based solutions to accelerate GRC workflows, including control testing, evidence review, policy mapping, and risk narrative generation. * Integrate GRC tooling (e.g., Onspring, Archer, MetricStream, or similar platforms) with security and IT systems via APIs to enable automated data flows, dashboards, and reporting. * Develop and maintain scripts, bots, and workflow tools that automate recurring GRC tasks such as evidence gathering, control monitoring, and audit preparation. * Partner with Security GRC analysts and program managers to identify manual, repetitive processes and re-engineer them into scalable, automated solutions. * Establish guardrails, testing, and quality controls to ensure AI-assisted outputs are accurate, explainable, and compliant with regulatory and audit requirements. * Monitor and report on the performance, reliability, and risk posture of automation and AI tools used within the GRC program. * Stay current with emerging AI, automation, and GRC technologies, and recommend adoption of new tools and techniques to continuously improve program maturity. * Collaborate with other AmexGBT teams (security, engineering, data, and business) to align automation initiatives with broader security posture and compliance goals., Leads complex, multi-workstream product initiatives as a principal Product Owner. Owns product vision, strategy, backlog integrity, prioritization, and Scrum team alignment. Coordinates Product, Engineering, Design, Delivery, and other stakeholders; improves execution discipline, transparency, and outcome tracking. Stabilizes programs with fragmented ownership or elevated delivery risk while ensuring customer and business requirements are addressed. Requires substantial Product Owner or Senior Product Manager experience, preferably in payments or financial services., Leads revenue recognition, billing, accounts receivable, collections, audit readiness, and financial controls. Owns ASC 606 compliance, billing systems, process automation, AI-enabled accounting improvements, reporting, and cross-functional alignment. Manages and mentors the accounting team while supporting scalable revenue operations and public-company readiness. Top Skills: Ai-Enabled Automation ToolsAsc 606GaapExcelMicrosoft OutlookMicrosoft WordNetSuiteOracleSAP What you need to know about the Colorado Tech Scene With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation. Key Facts About Colorado Tech * Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey) * Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3 * Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech * Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook) * Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures * Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute