All roles

Security Engineer – GRC, Governance, Risk & Compliance

Remote · USA Full-time New today

Job Description:

  • Configure, administer, and continuously improve Machinify’s Vanta GRC platform across all organizational entities
  • Build and maintain Vanta integrations with cloud environments (AWS, Azure), identity providers, endpoint management tools, HR systems, and other compliance-relevant data sources
  • Automate evidence collection workflows to reduce manual effort for HITRUST r2, SOC 2 Type II, and other certification cycles
  • Develop and maintain custom tests, policies, and controls within Vanta to reflect Machinify’s specific compliance requirements and risk posture
  • Monitor control health dashboards and manage remediation workflows for failing or at-risk controls
  • Manage the Vanta vendor risk module, including questionnaire automation and third-party assessment workflows
  • Support access review automation through Vanta, ensuring timely completion and accurate documentation
  • Maintain and improve GRC platform documentation including integration configurations, data flows, and control mapping
  • Evaluate and implement new Vanta capabilities as the platform evolves, including AI-assisted compliance features
  • Support HITRUST r2 and SOC 2 Type II audit activities through evidence preparation, auditor portal management, and issue tracking
  • Assist with customer security questionnaire responses by leveraging Vanta’s trust center and evidence library
  • Contribute to third-party risk assessments by coordinating vendor security reviews and maintaining assessment records
  • Help develop and maintain security policies and procedures aligned with HITRUST and SOC 2 requirements
  • Support the risk register by maintaining risk records, tracking remediation actions, and producing risk reporting
  • Participate in security awareness program activities including content development and training delivery tracking
  • Assist with regulatory documentation requirements including HIPAA privacy and security program documentation
  • Collaborate with the Security Engineering team to ensure technical controls are properly reflected in the GRC platform.

Requirements:

  • Bachelor’s degree in Information Security, Computer Science, Compliance, Risk Management, or related field, or equivalent work experience
  • 3+ years of experience in information security, GRC, or a technical compliance role
  • Hands-on experience with a GRC platform such as Vanta, Drata, Tugboat Logic, ServiceNow GRC, Archer or similar
  • Working knowledge of SOC 2 Trust Service Criteria and HITRUST CSF control requirements
  • Familiarity with cloud environments (AWS or Azure) sufficient to understand integration points and relevant compliance controls
  • Experience with API integrations, webhooks, or similar mechanisms for connecting systems to compliance platforms
  • Understanding of common compliance evidence types and audit workflows for security certifications
  • Familiarity with healthcare compliance requirements, particularly HIPAA Security Rule
  • Strong organizational skills for managing multiple compliance workstreams simultaneously
  • Clear written communication for policy documentation, control narratives, and cross-functional stakeholder engagement.

Benefits:

  • Work from anywhere in the US! Machinify is digital-first.
  • Top Medical/Dental/Vision offerings
  • FSA/HSA
  • Tuition reimbursement
  • Competitive salary, 401(k) with company match
  • Additional health and wellness benefits and perks
  • Flexible and trusting environment where you’ll feel empowered to do your best work

Apply tot his job Apply To this Job

Related roles

GRC Risk Analyst

Remote · USA Full-time

GRC Analyst - Public Sector

Remote · USA Full-time

SAP GRC and Internal Control

Remote · USA Full-time

SAP Security Engineer (GRC – Technical)

Remote · USA Full-time

Director, Governance, Risk, and Compliance (GRC)

Remote · USA Full-time

Open Source Investigations Analyst

Remote · USA Full-time

SOC Analyst, Information Security Operations (Remote – United States)

Remote · USA Full-time

Global Intelligence Analyst (Days/Hours TBD)

Remote · USA Full-time

SOC Analyst

Remote · USA Full-time

Environmental Health and Safety (EHS) Professional II-Remote (Oklahoma, OK, US,

Remote · USA Full-time

Job Title: Part-Time Remote Data Entry Specialist – E-Commerce Product Data Management (No Experience Required)

Remote · USA Full-time

DFM Engineer

Remote · USA Full-time

Customer Care Specialist I (Must live in Ohio)

Remote · USA Full-time

Experienced Live Chat Assistant – Customer Service Representative – Remote Work Opportunity

Remote · USA Full-time

Steuerfachkraft (m/w/d) in Mainz mindestens 52.000€ - 100% Remote möglich

Remote · USA Full-time

Territory Manager - Akron

Remote · USA Full-time

Experienced Jr Data Entry Clerk / Part Time (Remote) – Join arenaflex's Dynamic Team

Remote · USA Full-time

Remote Notary Services Provider Aldie, VA

Remote · USA Full-time

Experienced Travel Coordinator – Entry-Level Data Entry Assistant (Remote) at arenaflex

Remote · USA Full-time

Experienced Customer Service Representative – Work from Home Opportunity for Teens at arenaflex

Remote · USA Full-time