Back to all roles

Security Engineer – GRC, Governance, Risk & Compliance

Remote-first Full-time Now hiring

Job Description:

  • Configure, administer, and continuously improve Machinify’s Vanta GRC platform across all organizational entities
  • Build and maintain Vanta integrations with cloud environments (AWS, Azure), identity providers, endpoint management tools, HR systems, and other compliance-relevant data sources
  • Automate evidence collection workflows to reduce manual effort for HITRUST r2, SOC 2 Type II, and other certification cycles
  • Develop and maintain custom tests, policies, and controls within Vanta to reflect Machinify’s specific compliance requirements and risk posture
  • Monitor control health dashboards and manage remediation workflows for failing or at-risk controls
  • Manage the Vanta vendor risk module, including questionnaire automation and third-party assessment workflows
  • Support access review automation through Vanta, ensuring timely completion and accurate documentation
  • Maintain and improve GRC platform documentation including integration configurations, data flows, and control mapping
  • Evaluate and implement new Vanta capabilities as the platform evolves, including AI-assisted compliance features
  • Support HITRUST r2 and SOC 2 Type II audit activities through evidence preparation, auditor portal management, and issue tracking
  • Assist with customer security questionnaire responses by leveraging Vanta’s trust center and evidence library
  • Contribute to third-party risk assessments by coordinating vendor security reviews and maintaining assessment records
  • Help develop and maintain security policies and procedures aligned with HITRUST and SOC 2 requirements
  • Support the risk register by maintaining risk records, tracking remediation actions, and producing risk reporting
  • Participate in security awareness program activities including content development and training delivery tracking
  • Assist with regulatory documentation requirements including HIPAA privacy and security program documentation
  • Collaborate with the Security Engineering team to ensure technical controls are properly reflected in the GRC platform.

Requirements:

  • Bachelor’s degree in Information Security, Computer Science, Compliance, Risk Management, or related field, or equivalent work experience
  • 3+ years of experience in information security, GRC, or a technical compliance role
  • Hands-on experience with a GRC platform such as Vanta, Drata, Tugboat Logic, ServiceNow GRC, Archer or similar
  • Working knowledge of SOC 2 Trust Service Criteria and HITRUST CSF control requirements
  • Familiarity with cloud environments (AWS or Azure) sufficient to understand integration points and relevant compliance controls
  • Experience with API integrations, webhooks, or similar mechanisms for connecting systems to compliance platforms
  • Understanding of common compliance evidence types and audit workflows for security certifications
  • Familiarity with healthcare compliance requirements, particularly HIPAA Security Rule
  • Strong organizational skills for managing multiple compliance workstreams simultaneously
  • Clear written communication for policy documentation, control narratives, and cross-functional stakeholder engagement.

Benefits:

  • Work from anywhere in the US! Machinify is digital-first.
  • Top Medical/Dental/Vision offerings
  • FSA/HSA
  • Tuition reimbursement
  • Competitive salary, 401(k) with company match
  • Additional health and wellness benefits and perks
  • Flexible and trusting environment where you’ll feel empowered to do your best work

Apply tot his job Apply To this Job

More remote roles

GRC Risk Analyst

Remote-first Full-time

GRC Analyst - Public Sector

Remote-first Full-time

SAP GRC and Internal Control

Remote-first Full-time

SAP Security Engineer (GRC – Technical)

Remote-first Full-time

Director, Governance, Risk, and Compliance (GRC)

Remote-first Full-time

Open Source Investigations Analyst

Remote-first Full-time

SOC Analyst, Information Security Operations (Remote – United States)

Remote-first Full-time

Global Intelligence Analyst (Days/Hours TBD)

Remote-first Full-time

SOC Analyst

Remote-first Full-time

Environmental Health and Safety (EHS) Professional II-Remote (Oklahoma, OK, US,

Remote-first Full-time

Nurse Practitioner (PRN) - In-Home Health Assessments

Remote-first Full-time

[Remote] RCI-ABBV-33784 Bioinformatics Analyst (RNA-seq/CRISPR/NGS/HPC/Cloud Computing/Predictive Modeling/Transcriptomics/Genomics/Omics)

Remote-first Full-time

Experienced Part-Time Data Entry Remote Operator – Flexible Work from Home Opportunity at arenaflex

Remote-first Full-time

Your Words can Make You Up to $4500/Month! Freelance Academic Writers Wanted!

Remote-first Full-time

Cloud Infrastructure Engineer (GCP) @ Remote - PST or MST Zone Only

Remote-first Full-time

Experienced Remote Administrative Assistant/Customer Service Representative for arenaflex's Travel Division

Remote-first Full-time

Senior Manager, Project Management - Imaging

Remote-first Full-time

Provider Enrollment Specialist

Remote-first Full-time

Remote Part-Time Customer Service Agent & Product Eggspert – Animal Care Solutions Specialist for Backyard Flocks & Small Pets

Remote-first Full-time

Reservation Coordinator

Remote-first Full-time