GRC Engineer

Remote Foster City, CA FullTime

Posted 2mo ago

Job Location

Foster City, CA

Tech Stack

Remote Work Policy

Fully remote

Employment Type

FullTime

Categories

Applied AI Engineer

About the job

Replit is seeking a GRC Engineer to be a key technical contributor to its compliance and risk management ecosystem. This role involves architecting systems and processes that automate trust, partnering across the organization to balance rigorous standards with the velocity of a high-growth startup. The ideal candidate will be a pragmatic operator who understands that GRC's purpose is to enable the business. You will drive quality, technical depth, and operational efficiency in security controls, owning the technical vision for Replit's GRC program and moving towards 'Compliance-as-Code' and automated evidence collection. You will also champion a culture of security and privacy, educating teams on the 'why' behind controls.

Responsibilities

  • Act as a technical subject matter expert for the GRC team, driving quality and efficiency in security controls.
  • Own the technical vision for Replit's GRC program, transitioning towards 'Compliance-as-Code' and automated evidence collection.
  • Champion security and privacy culture across the company.
  • Partner with Engineering and Architecture to integrate compliance requirements early in the design phase.
  • Collaborate with Legal Counsel to implement privacy and AI regulation requirements.
  • Manage the Customer Trust Center and handle security questionnaires to support the Sales team.
  • Serve as the primary contact for external auditors, bridging communication between auditors and internal teams.
  • Operate the Cybersecurity Risk Register, identifying, quantifying, and tracking risks.
  • Manage and evolve compliance posture across SOC 2, ISO 27001, and prepare for future certifications.
  • Apply judgment to prioritize real security or business risks over 'compliance theater'.
  • Drive automation of audit work and continuous monitoring for evidence collection.
  • Architect a scalable framework for assessing third-party vendors and AI model providers.

Requirements

  • 8+ years of experience in GRC or Information Security.
  • Technical fluency in engineering, cloud (GCP/AWS), and security architecture.
  • Deep experience with SOC 2, ISO 27001, PCI, HIPAA, and Privacy laws.
  • Strong ability to explain risk and tradeoffs to technical, legal, and commercial stakeholders.
  • Experience with GRC automation tools (e.g., Vanta, Drata) and a bias toward reducing manual toil.
  • Familiarity with FedRAMP, ITAR, or AI regulation is a strong plus.

Benefits

  • Competitive Salary & Equity
  • 401(k) Program with a 4% match (US Only)
  • Health, Dental, Vision and Life Insurance
  • Short Term and Long Term Disability
  • Paid Parental, Medical, Caregiver Leave
  • Flexible Time Off (FTO) + Holidays
  • Commuter Benefits (In-Office Only)
  • Monthly Wellness Stipend
  • Autonomous Work Environment
  • In Office Set-Up Reimbursement (In-Office Only)
  • Quarterly Team Gatherings
  • In Office Amenities (In-Office Only)

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.