2 hours ago
Base Salary
$141k - $180k/yr
Responsibilities
- Design, build, and own production-quality automated security control monitoring under version control, peer review, and CI/CD.
- Convert manual, periodic control testing into continuous control monitoring with defined signals, frequencies, thresholds, alerting, and escalation paths.
- Engineer self-service AWS evidence collection using native services so control owners and auditors can retrieve current evidence on demand.
- Build automated control-failure pipelines covering detection, enrichment, ticketing, routing, SLA tracking, remediation verification, closure, exceptions, and risk acceptance.
- Apply LLMs and agentic workflows to evidence review, control mapping, gap analysis, questionnaires, policy drafting, and risk triage with human-in-the-loop safeguards.
- Maintain a normalized control library mapped across ISO 27001, SOC 2, PCI DSS, SOX, GDPR, and NIST.
- Partner with Platform Engineering, DevOps, and IT to implement preventive guardrails, policy-as-code, and secure-by-default infrastructure patterns.
- Create dashboards for automation coverage, evidence freshness, control failures, remediation time, and audit readiness.
- Lead audit engagements and defend automated test design, sampling logic, and system-generated evidence to auditors and assessors.
- Execute control tests and third-party and operational security risk assessments, develop treatment plans, and validate remediation through automated retesting.
- Review and guide other GRC engineers' automation, queries, and test logic while distributing automation ownership across the team.
- Administer GRC technology and integrations, provide user enablement, and maintain documentation, playbooks, runbooks, dashboards, and controlled security program documents.
Requirements
- At least 5 years of experience as part of a GRC or similar team.
- At least 2 years of hands-on experience building and maintaining automation, including proficiency in a scripting or programming language, preferably Python.
- Experience working with Git, code review, and CI/CD.
- Hands-on AWS experience with services relevant to control monitoring and evidence generation, including Config, Security Hub, CloudTrail, IAM, Organizations, SCPs, Lambda, EventBridge, S3/Athena, and CloudWatch.
- Experience retrieving, normalizing, and reconciling data across systems through APIs and SQL while evaluating data completeness and accuracy.
- Practical experience applying LLMs or AI agents to real workflows, including prompt and workflow design, output evaluation, human review, and guardrails.
- Experience with security tools and cloud environments, such as GRC and compliance automation platforms, vulnerability scanners, SIEM, SOAR, and AWS.
- Knowledge of security frameworks, regulations, and standards including ISO 27001, SOC 2, GDPR, PCI, SOX, and NIST.
- Ability to determine sufficient audit evidence and defend automated control testing and system-generated evidence to auditors.
- Preferred experience with infrastructure as code using Terraform or CloudFormation and policy-as-code using OPA/Rego, AWS Config custom rules, cfn-guard, or similar tools.
- Preferred experience operating continuous control monitoring at scale, integrating GRC platforms through APIs, and building internal self-service tooling.
- Big Four or similar experience and a bachelor's degree in a related field are preferred.
- Relevant certifications such as CISSP, CISM, GIAC, AWS Certified Security – Specialty, CCSK, or CCSP are highly desirable.
- Strong communication, prioritization, independent execution, cross-functional collaboration, and security risk management skills are required.
Benefits
- Remote work is available, with equipment and support provided for working from home or an office.
- Full-time employees receive health coverage, life and disability insurance, paid parental leave, paid time off, paid holidays, quarterly self-care days, and a 401(k) employer match.
- Benefits may include stock options and access to learning and development initiatives including LinkedIn Learning.
- The company offers wellness education sessions, wellness days, and employee resource group events.
About 6sense
6sense is on a mission to revolutionize the way B2B organizations create revenue by predicting customers most likely to buy and recommending the best course of action to engage anonymous buying teams. 6sense Revenue AI is the only sales and marketing platform to unlock the ability to create, manage and convert high-quality pipeline to revenue. Customers report 2X increases in average contract value, 4X increases in win rate and 20-40% reduction in time to close deals. Know everything, do anything, with 6sense.