or apply directly on A-LIGN External's site. We never take the application ourselves.
Is this posting real?
- This role has been open
- 8 days A-LIGN External's roles stay open a median of 39 days
- Reposted
- No
- Salary listed
- No 0% of A-LIGN External's roles list one
- Ghost-job risk at A-LIGN External
- high 11 stale, 0 reposted of 26 open
- Hiring momentum
- 38 roles opened in the last 90 days ↑ up vs. the prior 90 days
- Last confirmed on the employer's board
- 2026-09-17
Measured from postings appearing on and disappearing from A-LIGN External's own greenhouse board since 2026-08-03. Full hiring picture for A-LIGN External.
About this role
The Senior GRC Engineer at A-LIGN is responsible for managing audit evidence collection and maintaining technical controls across various compliance frameworks such as FedRAMP and ISO standards. This role involves hands-on work with GCP, GitHub, and Microsoft 365, collaborating with technical teams to ensure continuous audit readiness and support broader information security activities including risk assessments and security reviews. The position requires a proactive approach to monitoring compliance and implementing AI technical safeguards.
- benefits
- 5/5
- freshness
- 5/5
- career value
- 4/5
- role clarity
- 5/5
- pay transparency
- 0/5
Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of A-LIGN External as an employer.
What you need
- Bachelor's degree in information systems, cybersecurity, business, or equivalent combination of education and experience
- 5+ years of experience in information security, GRC, IT audit, or compliance engineering roles
- Hands-on experience with audit evidence collection and technical control validation for at least two of the following: FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171
- DevSecOps or cloud engineering experience sufficient to independently locate and extract evidence from GCP, GitHub, and Microsoft 365/Entra ID environments
- Experience with GRC platforms and evidence automation (AuditBoard, Vanta, Drata, or similar)
- Experience supporting external audits and assessor interactions, including 3PAO assessments
Nice to have
- Experience scripting or automating evidence collection (Python, PowerShell, or similar)
- Familiarity with risk assessment methodologies, threat modeling (e.g., STRIDE), and security review processes
- CISA, CISSP, CCSK/CCSP, ISO Lead Auditor/Implementer, or relevant certifications preferred but not required
- Proven experience utilizing AI tools to automate manual tasks, streamline workflows, and increase team efficiency
- Experience operating in PE-backed or high-growth environments preferred
What you get
- Employer Paid Life & Health Insurance
- Competitive Bonus Structure
- Home Office Reimbursement
- Technology Allowance
- Certification Reimbursement
- BeneficiaT Discount Loyalty Program
Worth weighing
- No salary listed
- The role requires strong collaboration across multiple technical departments, which may involve navigating complex team dynamics.
- The position is in-office hybrid, which may not suit all candidates' preferences.
Summarised from A-LIGN External's posting. Read the full original.
Listed by A-LIGN External on their greenhouse job board, last confirmed open on 2026-09-17. PitchMeAI is not the employer.
More roles at A-LIGN External
- IT Auditor - SOCGurgaon, India - In-Office Hybrid
- Business Development Representative InternTampa, United States
- Associate Director of Strategic ProgramsUnited States - Remote
- Account Executive, Expansion - Mid MarketUnited States – Remote
- Account Executive, Expansion - EnterpriseUnited States - Remote
- Senior IT Auditor - SOCGurgaon, India - In-Office Hybrid
- Senior GRC EngineerUnited States - Remote
- Senior IT EngineerUnited States – Remote