Senior GRC Engineer

1 week ago
Full-time
Senior
Cybersecurity
Life360

Life360

Life360 is the top family location safety app, offering advanced safety features to connect and protect millions of families worldwide.

Family Services
251-1K
Founded 2008
$140M raised

Description

  • Own the governance framework for Life360's agentic systems and define the policies, control sets, and compliance posture that govern how agents are built and deployed.
  • Automate GRC work such as evidence collection, control narrative drafting, vendor questionnaire triage, and related workflows using AI and internal tooling.
  • Build policy-as-code processes, including version-controlled policies, peer review via pull requests, enforceable requirements, and automated compliance checks.
  • Lead SOC 2 Type 2, ISO 27001, and SOX ITGC compliance end to end as management owner, including evidence management, auditor coordination, and gap remediation.
  • Develop an operational risk function that uses live data sources, quantitative risk methods, and actionable risk scoring for stakeholders from service owners to executive leadership.
  • Mature the third-party risk management program through tiered reviews, automated evidence collection, and agent-based assessment workflows.
  • Serve as the primary management contact for auditors, owning scoping, walkthroughs, evidence delivery, management responses, and finding closure.
  • Build cross-functional partnerships with Engineering, Legal, Privacy, Internal Audit, and Procurement to make compliance a shared operational practice.
  • Maintain clear boundaries between management GRC responsibilities and Internal Audit's independent third-line assurance.

Requirements

  • 5+ years of experience in GRC, security engineering, or a hybrid role covering both policy/control ownership and technical implementation.
  • Hands-on experience using AI tools, LLMs, or agents for real work such as drafting, automation, investigation, or code.
  • Coding ability with Python or an equivalent language, including APIs, integrations, scheduled jobs, and working pipelines.
  • Ability to gather control evidence directly from cloud environments using APIs rather than screenshots or manual collection.
  • Experience implementing, integrating, or significantly extending a modern GRC platform.
  • Working knowledge of SOC 2, ISO 27001, and NIST AI RMF at the control level, including how they are evolving for AI and agentic systems.
  • Experience with SOX ITGC cycles at a public company, including evidence, walkthroughs, and auditor findings.
  • Experience building or scaling a TPRM program, including tiering, vendor pushback, and assessment automation.
  • Quantitative risk experience, ideally with FAIR or an equivalent methodology applied in practice.
  • Clear written communication for policies, control narratives, audit responses, and risk statements.
  • Bachelor's degree or equivalent.
  • Preferred: experience taking a company through SOC 2 Type 2 or ISO 27001 certification from scratch.
  • Preferred: privacy program experience with GDPR, CCPA, data mapping, or DPIAs.
  • Preferred: experience on the implementation side of security, such as engineering, operations, or incident response.
  • Preferred: experience building governance frameworks for AI systems, including model risk, ISO 42001, or controls for LLM and agent deployment.

Benefits

  • Competitive pay and benefits.
  • US base salary range of $115,500 to $213,000, with final pay based on background, experience, and location.
  • Medical, dental, vision, life, and disability insurance plans, with employee coverage paid 100%.
  • 401(k) plan with company matching.
  • Mental Wellness Program and Employee Assistance Program (EAP).
  • Flexible PTO plus 13 company-wide days off each year.
  • Winter and Summer weeklong synchronized company shutdowns.
  • Learning and development programs.
  • Equipment, tools, and reimbursement support for a productive remote setup.
  • Free Life360 Platinum Membership for your preferred circle.
  • Free Tile products.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Automation Engineer (SOAR)

Nebius 51-250 Internet Software & Services

Nebius is hiring a Security Automation Engineer to build and scale SOC automation across security operations, integrating SIEM, EDR, and other platforms while shaping SOAR capabilities in a greenfield environment.

AWS Azure CrowdStrike GCP LLM Python REST API SIEM SOC Splunk
3 hours, 4 minutes ago

DevSecOps Engineer

INflow Federal 51-250 Aerospace & Defense

INflow Federal is seeking a fully remote DevSecOps Engineer to support an enterprise case management solution for Department of Defense mission partners by securing and automating cloud-based CI/CD and infrastructure operations in AWS GovCloud.

Agile AWS Bash CI/CD CloudFormation Docker ELK Stack Git GitLab CI Helm Jenkins Kubernetes PowerShell Prometheus Python Terraform
3 hours, 52 minutes ago

Cyber Security Architect

INflow Federal 51-250 Aerospace & Defense

INflow Federal is hiring a fully remote Cyber Security Architect to design and sustain secure enterprise architectures for a modernized Department of Defense information system supporting mission operations.

Agile DevSecOps ELK Stack OAuth Penetration Testing SAML Splunk
5 hours, 33 minutes ago

Principal Security Engineer, Product & AI

Marqeta 251-1K Diversified Financial Services

Marqeta is hiring a Principal Security Engineer to lead product security, AI security, and security architecture oversight for its payment platform and broader infrastructure.

AWS Generative AI Go Java Kubernetes LLM Machine Learning Network Security Python PyTorch SIEM TensorFlow Terraform
5 hours, 47 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers