or apply directly on A-LIGN External's site. We never take the application ourselves.
Is this posting real?
- This role has been open
- 8 days A-LIGN External's roles stay open a median of 39 days
- Reposted
- No
- Salary listed
- No 0% of A-LIGN External's roles list one
- Ghost-job risk at A-LIGN External
- high 11 stale, 0 reposted of 26 open
- Hiring momentum
- 38 roles opened in the last 90 days ↑ up vs. the prior 90 days
- Last confirmed on the employer's board
- 2026-09-17
Measured from postings appearing on and disappearing from A-LIGN External's own greenhouse board since 2026-08-03. Full hiring picture for A-LIGN External.
About this role
The Senior GRC Engineer at A-LIGN is responsible for managing audit evidence collection and maintaining technical controls across various compliance frameworks such as FedRAMP and ISO standards. This role involves hands-on work with tools like GCP, GitHub, and Microsoft 365, ensuring the organization remains audit-ready by collaborating with technical teams to streamline compliance processes. Additionally, the engineer will support risk assessments, threat modeling, and the implementation of AI safeguards.
- benefits
- 5/5
- freshness
- 5/5
- career value
- 4/5
- role clarity
- 5/5
- pay transparency
- 0/5
Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of A-LIGN External as an employer.
What you need
- Bachelor's degree in information systems, cybersecurity, business, or equivalent combination of education and experience
- 5+ years of experience in information security, GRC, IT audit, or compliance engineering roles
- Hands-on experience with audit evidence collection and technical control validation for at least two of the following: FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171
- DevSecOps or cloud engineering experience sufficient to independently locate and extract evidence from GCP, GitHub, and Microsoft 365/Entra ID environments
- Experience with GRC platforms and evidence automation
- Experience supporting external audits and assessor interactions, including 3PAO assessments
Nice to have
- Experience scripting or automating evidence collection (Python, PowerShell, or similar)
- Familiarity with risk assessment methodologies, threat modeling (e.g., STRIDE), and security review processes
- Certifications such as CISA, CISSP, CCSK/CCSP, ISO Lead Auditor/Implementer
- Experience operating in PE-backed or high-growth environments
What you get
- Healthcare, Dental, and Vision Benefits
- Employer Paid Life Insurance and Disability Insurance
- EAP - Employee Assistance Program
- Pet Insurance
- 401(k) Plan with Employer Matching
- Competitive Bonus Structure
Worth weighing
- No salary listed
- The role requires extensive hands-on technical experience and cross-functional collaboration, which may be challenging for candidates without strong technical backgrounds.
- The position involves managing multiple concurrent audit cycles, which could be demanding in terms of time and organization.
Summarised from A-LIGN External's posting. Read the full original.
Listed by A-LIGN External on their greenhouse job board, last confirmed open on 2026-09-17. PitchMeAI is not the employer.
More roles at A-LIGN External
- IT Auditor - SOCGurgaon, India - In-Office Hybrid
- Business Development Representative InternTampa, United States
- Associate Director of Strategic ProgramsUnited States - Remote
- Account Executive, Expansion - Mid MarketUnited States – Remote
- Account Executive, Expansion - EnterpriseUnited States - Remote
- Senior GRC EngineerPanama City, Panama - In-Office Hybrid
- Senior IT Auditor - SOCGurgaon, India - In-Office Hybrid
- Senior IT EngineerUnited States – Remote