GRC Engineer
Job description
About the role
This GRC Engineer position at Antithesis represents a foundational ownership role within a growing engineering organization. You will be responsible for establishing and maintaining the entire compliance program, ensuring it is robust enough to satisfy enterprise customers and auditors alike. The role demands a high degree of autonomy where you will own the end-to-end GRC lifecycle rather than operating as a passive support function. You will act as a critical bridge between technical teams and enterprise customers, translating complex security requirements into clear, auditable evidence. Because trust is our primary product, your work will directly enable sales cycles and protect our reputation in the market. This position is not advisory; you will be the day-to-day operator accountable for the health of our compliance posture. You will manage the systems, processes, and documentation necessary to prove that we do what we say.
Key facts
What you'll do
- Orchestrate the end-to-end SOC 2 audit lifecycle, transitioning the scope to a rolling twelve-month window while interfacing directly with external auditors.
- Serve as the single point of ownership for our Vanta instance, ensuring the system of record remains accurate, current, and reliable for all compliance evidence.
- Maintain and evolve the policy library, guaranteeing that documents are not only accurate and readable but also demonstrably followed across the organization.
- Run the GRC calendar by organizing tabletop exercises, preparing materials for security committee meetings, and administering security awareness training and annual reviews.
- Identify control gaps systematically across Engineering, IT, HR, and Operations, then drive remediation efforts to closure.
- Own the inbound security questionnaire queue, responding to enterprise prospects with speed and accuracy to unblock sales and accelerate deal closure.
- Act as the primary subject matter expert for enterprise buyers and external auditors, clearly articulating our security and compliance posture.
- Manage vendor security reviews, evaluating new vendors and participating in customer-side assessments to ensure third-party risk is controlled.
- Maintain the risk register and facilitate regular risk review cadences to identify, document, and escalate people, process, and infrastructure risks.
- Support penetration testing and vulnerability management initiatives by ensuring findings are tracked, reported, and remediated in a timely manner.
- Lay the groundwork for future frameworks such as ISO 27001, GDPR, and FedRAMP by designing scalable processes that can scale with the business.
- Collaborate with Legal and commercial teams on security-related clauses, data processing agreements, and other contractual security requirements.
- Partner with HR to develop and implement security-related employee policies, including acceptable use, onboarding, and offboarding procedures.
- Work closely with Engineering and Infrastructure leads to ensure that penetration testing and vulnerability management programs remain on track and that findings are addressed.
Requirements
- Possess three to five years of cumulative experience in GRC, compliance, or IT audit roles, with a preference for environments in SaaS or highly technical sectors.
- Demonstrate hands-on experience managing compliance programs, audit responses, and security questionnaires in a SaaS context.
- Show a proven ability to own and maintain complex policy libraries, ensuring that documents are current, accurate, and adhered to.
- Exhibit strong written and verbal communication skills, with the capability to translate technical security concepts for both technical and non-technical audiences.
- Have experience working with security governance tools, specifically including Vanta, to manage evidence, controls, and audit workflows.
- Display a meticulous attention to detail and the ability to manage multiple priorities in a fast-paced, deadline-driven environment.
- Bring a strong sense of ownership and accountability, with a track record of closing gaps and following through on remediation efforts.
- Understand the fundamentals of information security controls, risk management, and audit processes relevant to SaaS product delivery.
Nice to have
There are no preferred qualifications, skills, or experiences listed beyond the core requirements.
Practical notes
The role is full-time and based in Vienna, Virginia, USA. No specific working hours, travel requirements, visa sponsorship details, or application deadlines are provided in the source material.