Senior GRC Engineer

4 weeks ago
Full-time
Senior
Cybersecurity
Life360

Life360

Life360 is the top family location safety app, offering advanced safety features to connect and protect millions of families worldwide.

Family Services
251-1K
Founded 2008
$140M raised

Description

  • Own the governance framework for Life360's agentic systems and define the policies, control sets, and compliance posture that govern how agents are built and deployed.
  • Automate GRC work such as evidence collection, control narrative drafting, vendor questionnaire triage, and related workflows using AI and internal tooling.
  • Build policy-as-code processes, including version-controlled policies, peer review via pull requests, enforceable requirements, and automated compliance checks.
  • Lead SOC 2 Type 2, ISO 27001, and SOX ITGC compliance end to end as management owner, including evidence management, auditor coordination, and gap remediation.
  • Develop an operational risk function that uses live data sources, quantitative risk methods, and actionable risk scoring for stakeholders from service owners to executive leadership.
  • Mature the third-party risk management program through tiered reviews, automated evidence collection, and agent-based assessment workflows.
  • Serve as the primary management contact for auditors, owning scoping, walkthroughs, evidence delivery, management responses, and finding closure.
  • Build cross-functional partnerships with Engineering, Legal, Privacy, Internal Audit, and Procurement to make compliance a shared operational practice.
  • Maintain clear boundaries between management GRC responsibilities and Internal Audit's independent third-line assurance.

Requirements

  • 5+ years of experience in GRC, security engineering, or a hybrid role covering both policy/control ownership and technical implementation.
  • Hands-on experience using AI tools, LLMs, or agents for real work such as drafting, automation, investigation, or code.
  • Coding ability with Python or an equivalent language, including APIs, integrations, scheduled jobs, and working pipelines.
  • Ability to gather control evidence directly from cloud environments using APIs rather than screenshots or manual collection.
  • Experience implementing, integrating, or significantly extending a modern GRC platform.
  • Working knowledge of SOC 2, ISO 27001, and NIST AI RMF at the control level, including how they are evolving for AI and agentic systems.
  • Experience with SOX ITGC cycles at a public company, including evidence, walkthroughs, and auditor findings.
  • Experience building or scaling a TPRM program, including tiering, vendor pushback, and assessment automation.
  • Quantitative risk experience, ideally with FAIR or an equivalent methodology applied in practice.
  • Clear written communication for policies, control narratives, audit responses, and risk statements.
  • Bachelor's degree or equivalent.
  • Preferred: experience taking a company through SOC 2 Type 2 or ISO 27001 certification from scratch.
  • Preferred: privacy program experience with GDPR, CCPA, data mapping, or DPIAs.
  • Preferred: experience on the implementation side of security, such as engineering, operations, or incident response.
  • Preferred: experience building governance frameworks for AI systems, including model risk, ISO 42001, or controls for LLM and agent deployment.

Benefits

  • Competitive pay and benefits.
  • US base salary range of $115,500 to $213,000, with final pay based on background, experience, and location.
  • Medical, dental, vision, life, and disability insurance plans, with employee coverage paid 100%.
  • 401(k) plan with company matching.
  • Mental Wellness Program and Employee Assistance Program (EAP).
  • Flexible PTO plus 13 company-wide days off each year.
  • Winter and Summer weeklong synchronized company shutdowns.
  • Learning and development programs.
  • Equipment, tools, and reimbursement support for a productive remote setup.
  • Free Life360 Platinum Membership for your preferred circle.
  • Free Tile products.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

IT & Security Engineer (Contract)

Parachute Health 51-250 Health Care Providers & Services

Parachute Health is hiring a contractor for its IT & Security team to support secure, compliant, and efficient healthcare technology operations across identity, endpoint, network, and cloud security.

AWS Bash CrowdStrike DHCP DNS GCP Git GitHub HIPAA Linux macOS OAuth PostgreSQL PowerShell Python SAML Splunk SQL TLS
3 hours, 37 minutes ago

Sr. Solutions Architect (DevSecOps) II (6444)

MetroStar 251-1K IT Services

MetroStar is seeking a Sr. Solutions Architect (DevSecOps) II to lead secure platform and cloud solution efforts for containerized, microservices-based environments while ensuring compliance, continuous monitoring, and incident response readiness.

AWS CI/CD Cybersecurity DevSecOps Jenkins Kubernetes Microservices OpenShift SonarQube Splunk
5 hours, 2 minutes ago

Senior DevSecOps Consultant (Azure / Secrets Management)

Trility Consulting 51-250 Internet Software & Services

Trility Consulting is seeking a remote Senior DevSecOps Consultant to lead a short-term Azure security engagement focused on strengthening secrets management, application security, and repeatable DevSecOps standards across client environments.

Azure CI/CD DevSecOps GitHub .NET Python Secrets Management SQL Server
5 hours, 41 minutes ago

Lead Manager, IT Security Engineer

Make-A-Wish America 1K-5K Diversified Consumer Services

Make-A-Wish is hiring an Information Technology Security professional to help protect the organization’s information, infrastructure, and stakeholders through enterprise security design, operations, and incident support.

Azure Windows Server
6 hours, 7 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers