Senior GRC Engineer
Life360Remote (USA)2mo ago
Engineeringremotecurated-jd
Job description
Senior GRC Engineer at Life360
About the role
Life360 is seeking a Senior GRC Engineer to build and evolve the company's governance, risk, and compliance programs. This role will focus on establishing technical foundations for modern GRC, including policy as code and continuous control testing, while also anticipating the evolving compliance landscape driven by AI and agentic systems.
Key facts
What you'll do
- Establish the governance framework for Life360's agentic systems, defining policies and controls ahead of regulatory changes.
- Automate GRC processes using AI and internal tools for tasks like evidence collection and vendor assessments.
- Develop policies as code, with requirements expressed as enforceable rules and automated checks.
- Manage SOC 2 Type 2, ISO 27001, and SOX ITGC audits end-to-end, ensuring continuous audit readiness.
- Build an operational risk function connected to live data sources for actionable risk assessment.
- Mature the Third-Party Risk Management (TPRM) program with tiered reviews and automated workflows.
- Serve as the primary management contact for auditors, managing scoping, evidence, and responses.
- Cultivate cross-functional relationships with Engineering, Legal, Privacy, Internal Audit, and Procurement.
- Maintain clear distinctions between GRC operations and independent assurance provided by Internal Audit.
Requirements
- A minimum of 5 years of experience in GRC, security engineering, or a combined role focusing on policy, controls, and technical implementation.
- Demonstrated experience using AI tools like LLMs and agents for practical work such as drafting, coding, automation, and investigations, with an understanding of AI's benefits and risks.
- Proficiency in coding, specifically Python or a similar language, to build integrations, schedule jobs, and deploy pipelines.
- Ability to gather evidence directly from cloud environments, including identity, audit logs, configuration, and secrets management, via APIs.
- Experience implementing, integrating, or significantly enhancing a modern GRC platform, understanding its capabilities and limitations.
- Familiarity with SOC 2, ISO 27001, and NIST AI RMF at a control level, including their evolution concerning AI and agentic systems.
- Experience managing SOX ITGC cycles at a public company, including evidence management, walkthroughs, and auditor interactions.
- Experience building or scaling a TPRM program, including designing tiering and automating assessment workflows.
- Experience with quantitative risk assessment, such as using the FAIR methodology, to inform risk registers and communicate risk to various stakeholders.
- Strong written communication skills for policies, control narratives, audit responses, and risk statements.
- A Bachelor's degree or equivalent.
Nice to have
- Experience leading a company through SOC 2 Type 2 or ISO 27001 certification from the ground up.
- Background in privacy programs, including GDPR, CCPA, data mapping, and DPIAs.
- Prior experience in security engineering, operations, or incident response.
- Experience developing governance frameworks for AI systems, including model risk or controls for LLM and agent deployment.
Skills & tools
- Python
- Cloud environments (AWS, Azure, GCP)
- GRC platforms
- AI tools (LLMs, agents)
- SOC 2
- ISO 27001
- SOX ITGC
- NIST AI RMF
- FAIR
Practical notes
The US-based salary range for this position is $115,500 to $213,000. Compensation will be determined by factors such as background, experience, geographic location, job-related knowledge, skills, and experience. The compensation package includes comprehensive medical, dental, vision, financial, and other benefits, along with equity.