GRC Engineer

Security Engineer · Senior · Full Time

Foster City, CAUSD 210k – 320k3mo ago
Apply for this role

Opens Replit's application page

Role

What you'll do.

GRC Engineer at Replit is a technical leadership role responsible for architecting and automating the company's Governance, Risk, and Compliance program as the platform scales to millions of users. This position bridges security engineering and compliance operations, requiring deep technical fluency in cloud infrastructure (AWS/GCP), security architecture, and regulatory frameworks (SOC 2, ISO 27001, Privacy regulations) while driving the organization toward "Compliance-as-Code" automation. The ideal candidate combines 8+ years of GRC/InfoSec experience with pragmatic business acumen, capable of translating complex regulations into actionable technical controls and enabling enterprise sales through trusted security posture.

Responsibilities

  • Technical Architecture and GRC Program Leadership: Act as technical subject matter expert for the GRC team, owning the technical vision for Replit's compliance program. Drive the strategic shift from manual compliance workflows to Compliance-as-Code frameworks and automated evidence collection, ensuring technical depth and operational efficiency in security controls across the organization.
  • Governance Framework Management: Manage and evolve compliance posture across SOC 2 Type II and ISO 27001 certifications while preparing the organization for future compliance certifications including FedRAMP, ITAR, PCI DSS, and HIPAA. Operate with pragmatic judgment to distinguish between meaningful business risks and compliance theater while maintaining rigorous standards.
  • Cybersecurity Risk Register Operations: Own and operate the organization's Cybersecurity Risk Register, responsible for identifying, quantifying, and tracking technology and compliance-related risks. Communicate risk assessments and mitigation strategies to executive leadership and technical teams with clear business impact analysis.
  • Cross-Functional Engineering Collaboration: Partner with engineering architects and technical leads to embed compliance requirements into the design phase of new systems and features. Translate complex regulatory requirements and technical implementations into clear narratives that satisfy compliance frameworks without compromising development velocity or innovation.
  • Privacy and AI Regulation Implementation: Collaborate with Legal Counsel to interpret and implement requirements for privacy regulations including GDPR and CCPA, as well as emerging AI-specific regulations such as the EU AI Act. Develop guidance for engineering teams on privacy-by-design principles and AI governance frameworks.
  • Enterprise Sales Enablement and Customer Trust: Manage the Customer Trust Center and serve as subject matter expert on security questionnaires for enterprise prospects. Participate in complex customer security calls and demonstrations to build confidence in Replit's security and compliance posture, directly enabling the GTM strategy for enterprise market segment.
  • External Audit and Auditor Relationship Management: Serve as primary point of contact and relationship owner for external audit firms (SOC 2, ISO 27001, and others). Bridge communication between auditors and internal technical teams, ensuring requests are reasonable, technically sound, and aligned with Replit's technology infrastructure.
  • Control Automation and Third-Party Risk Management: Drive initiatives to automate security control monitoring and evidence collection, identifying opportunities to shift from manual audit work to continuous monitoring. Architect scalable frameworks for assessing third-party vendors and AI model providers, ensuring supply chain security without creating administrative bottlenecks.
  • Security Culture and Thought Leadership: Champion a culture of security and privacy across the company through education and engagement initiatives. Lead training and awareness programs that explain the business rationale and risk implications behind security controls, empowering engineering and product teams to make security-conscious decisions.

Qualifications

What we look for.

Technical

  • Cloud Infrastructure and Security Architecture Fluency

    Strong technical fluency with AWS and GCP cloud platforms, understanding infrastructure-as-code, network architecture, and cloud security best practices. Ability to anticipate how architectural decisions impact risk posture and compliance requirements.

  • Compliance Framework Expertise

    Deep hands-on experience implementing and maintaining SOC 2 Type II, ISO 27001 certification programs. Demonstrated understanding of PCI DSS, HIPAA, and Privacy regulations (GDPR, CCPA). Knowledge of emerging frameworks such as FedRAMP and ITAR is highly valuable.

  • GRC Automation and Tooling

    Practical experience with GRC automation platforms such as Vanta, Drata, or similar solutions. Ability to architect automated control validation, evidence collection, and reporting systems. Strong bias toward reducing manual compliance toil through technology and process automation.

  • Security Monitoring and Control Design

    Experience designing and implementing security controls, continuous monitoring systems, and evidence collection mechanisms. Understanding of control testing methodologies, audit evidence standards, and control optimization for scalability.

  • AI Governance and Emerging Regulations

    Familiarity with AI-specific governance requirements and emerging regulations including the EU AI Act. Understanding of compliance considerations for AI/ML systems, data governance, and responsible AI frameworks.

Education

  • Computer Science, Information Security, or Related Degree

    Bachelor's degree in Computer Science, Cybersecurity, Information Security, Business Administration, or related technical field is preferred. Relevant professional certifications can partially substitute for formal education.

  • Professional Security and Compliance Certifications

    Industry-recognized certifications such as CISSP, CCSK, ISO 27001 Lead Auditor, or SOC 2 certification are valuable. These certifications demonstrate commitment to the field and depth of compliance and security knowledge.

Experience

  • Minimum 8 Years GRC or Information Security Experience

    Extensive background in Governance, Risk, and Compliance or Information Security roles, with demonstrated progression in responsibility and complexity. Experience should include direct involvement in compliance certifications, audit management, and risk management programs at scale.

  • Enterprise Security Program Experience

    Background working with enterprise organizations on compliance and security programs, including experience managing audits, certifications, and security assessments. Understanding of enterprise security requirements and procurement processes.

  • Cross-Functional Stakeholder Engagement

    Proven ability to work effectively across diverse organizational functions including Engineering, Legal, Product, and Sales. Experience translating security requirements for technical and non-technical audiences with varying priorities and risk tolerances.

  • Risk Quantification and Risk Management

    Demonstrated experience identifying, analyzing, and quantifying business and technical risks. Background in risk register operations, risk-based prioritization, and communicating risk to executive leadership with clear business impact.

Skills

Required

  • Technical Communication and Translation

    Exceptional ability to explain complex security and regulatory concepts to diverse audiences including engineers, legal counsel, executives, and auditors. Skill in translating regulation language into specific, actionable technical requirements without over-simplifying.

  • Pragmatic Risk Judgment

    Strong discernment between theoretical compliance gaps and meaningful business risks. Ability to prioritize issues based on actual security impact rather than perceived audit preferences, with sound judgment in navigating gray areas appropriately.

  • Process Design and Automation

    Capability to design efficient compliance processes and identify automation opportunities. Experience implementing workflow improvements that reduce manual effort while improving evidence quality and audit readiness.

  • Relationship and Stakeholder Management

    Strong interpersonal and emotional intelligence skills for managing complex relationships with auditors, legal teams, and engineering leaders. Ability to influence without direct authority and build consensus across competing priorities.

  • Strategic and Systems Thinking

    Ability to think strategically about compliance program evolution and architecture. Understanding of how individual controls interconnect to form a comprehensive security program and how business growth impacts compliance needs.

Preferred

  • Compliance Automation Platform Implementation

    Nice to have

    Hands-on experience implementing and optimizing GRC automation platforms such as Vanta, Drata, Secureframe, or comparable solutions. Understanding of continuous control monitoring and automated attestation frameworks.

  • FedRAMP and Government Compliance

    Nice to have

    Practical experience with FedRAMP compliance programs, ITAR requirements, or other government/regulated industry compliance frameworks. Knowledge of differences between commercial and government security standards.

  • Third-Party Risk and Vendor Management

    Nice to have

    Background designing and implementing third-party security assessment frameworks, vendor risk management programs, and supply chain security initiatives at scale.

  • Startup and High-Growth Company Experience

    Nice to have

    Background in scaling compliance and security programs from early-stage to mature organizations. Understanding of the balance between security rigor and operational agility required in fast-growing companies.

  • AI and Machine Learning Governance

    Nice to have

    Experience with AI/ML governance frameworks, responsible AI principles, and emerging regulations around artificial intelligence systems. Understanding of data governance and algorithmic risk management.

  • Security Engineering Background

    Nice to have

    Prior experience as a Security Engineer or Information Security Engineer, providing deep technical understanding of infrastructure security, application security, and security architecture.

Tech stack

Languages

PythonSQLYAML/JSON

Frameworks

SOC 2 Type II FrameworkISO 27001:2022 Information Security ManagementGDPR and Privacy by DesignRisk Management Framework (NIST CSF/RMF)

Databases

PostgreSQL/MySQLData Warehousing Solutions (BigQuery/Snowflake)

Tools

Vanta or Drata GRC PlatformAWS and GCP Security ToolsJIRA or Asana Project ManagementSlack or Enterprise Communication PlatformsGoogle Workspace or Microsoft 365

Other

Infrastructure-as-Code (Terraform/CloudFormation)API Integration and AutomationAudit and Risk Analysis Methodologies

Compensation

Pay and benefits.

Base·USD 210,000 – 320,000

Full posting

Original listing.

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

About the role

Replit is the agentic software creation platform that enables anyone to build applications using natural language. As we scale to support millions of developers and enterprise organizations, maintaining a robust, transparent, and technically sound Governance, Risk, and Compliance (GRC) program is critical.

We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust, partnering deeply across the organization. We need a pragmatic operator who understands that GRC exists to enable the business—balancing rigorous standards with the velocity of a high-growth startup.

 

What You'll Do

Technical Excellence & Architecture

  • Technical Depth: Act as a technical subject matter expert for the GRC team. You will drive quality, technical depth, and operational efficiency in our security controls.

  • Program Architecture: Own the technical vision for Replit’s GRC program, moving the team from manual workflows toward "Compliance-as-Code" and automated evidence collection.

  • Thought Leadership: Champion a culture of security and privacy across the company, educating teams on why controls exist rather than just enforcing them.

Cross-Functional Collaboration

  • Engineering & Architecture: Partner with Architects and Engineering Leads to "bake in" compliance requirements early in the design phase. You will translate complex technical implementations into narratives that satisfy frameworks without slowing down development.

  • Legal & Privacy: Work closely with Legal Counsel to interpret and implement requirements for Privacy (GDPR, CCPA) and emerging AI-specific regulations (e.g., EU AI Act).

  • Sales & GTM: Enable the Sales team by managing the Customer Trust Center and handling complex security questionnaires. You will serve as a subject matter expert in customer calls to build confidence with enterprise prospects.

  • Auditor Relationships: Own and cultivate the primary relationship with external auditors. You will serve as the bridge between auditors and internal teams, ensuring requests are reasonable, clear, and relevant to our tech stack.

Risk Management & Strategic Compliance

  • Risk Register Operator: You will operate the Cybersecurity Risk Register. You will be responsible for identifying, quantifying, and tracking risks, distinguishing between theoretical compliance gaps and meaningful business risks.

  • Framework Evolution: Manage and evolve our compliance posture across SOC 2, ISO 27001, and prepare the organization for future certifications in regulated markets (e.g., FedRAMP, ITAR, PCI, HIPAA).

  • Pragmatic Governance: Apply judgment to operate in "gray areas" when appropriate. You will prioritize issues that represent real security or business risk over "compliance theater."

Automation & Efficiency

  • Control Automation: Drive the shift from manual evidence collection to continuous monitoring. You will identify opportunities to automate audit work, ensuring GRC scales with the business.

  • Third-Party Risk: Architect a scalable framework for assessing third-party vendors and AI model providers, ensuring our supply chain remains secure without creating administrative bottlenecks.

Required Skills & Experience

  • 8+ years of experience in GRC or Information Security

  • Technical Fluency: Ability to speak the language of engineering, cloud (GCP/AWS), and security architecture. You can anticipate how architectural decisions impact risk and compliance.

  • Regulatory Breadth: Deep experience with SOC 2, ISO 27001, PCI, HIPPA, and Privacy laws.

  • Collaborative Communication: Strong ability to explain risk and tradeoffs to technical (Engineers), legal, and commercial (Sales/Execs) stakeholders.

  • Automation Mindset: Experience with GRC automation tools (e.g., Vanta, Drata) and a bias toward reducing manual toil.

Bonus Qualifications

  • Familiarity with FedRAMP, ITAR, or AI regulation is a strong plus.

 

What We Value

  • Pragmatism: You distinguish between "checking a box" and reducing risk. You focus on outcomes over optics.

  • Business Enablement: You understand that your role is to help Replit sell to the enterprise safely, supporting innovation through technical trust.

  • Solutions-Oriented: You are collaborative and low-ego. You prefer fixing root causes and empowering teams through automation over manual bureaucracy.

  • Clarity: You can take a complex regulation and explain exactly what it means for a specific engineering team in plain English.

This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.

Full-Time Employee Benefits Include:

💰 Competitive Salary & Equity

💹 401(k) Program with a 4% match (US Only)

⚕️ Health, Dental, Vision and Life Insurance

🩼 Short Term and Long Term Disability

🚼 Paid Parental, Medical, Caregiver Leave

🏝 Flexible Time Off (FTO) + Holidays

🚗 Commuter Benefits (In-Office Only)

📱 Monthly Wellness Stipend

🧑‍💻 Autonomous Work Environment

🖥 In Office Set-Up Reimbursement (In-Office Only)

🚀 Quarterly Team Gatherings

☕ In Office Amenities (In-Office Only)

Want to learn more about what we are up to?

Interviewing + Culture at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Redirects to Replit's application page.

Other roles

More at Replit.

View all 29 roles