Senior Security Engineer, GRC

1 month ago
Full-time
Senior
Cybersecurity
Temporal

Temporal

Temporal provides an open source durable execution platform that enables developers to create resilient applications capable of maintaining successful operations despite failures, network issues, and other disruptions.

Internet Software & Services
51-250
Founded 2019
$128M raised

Description

  • Own the intake, prioritization, and completion of customer security questionnaires, RFPs, and due diligence requests.
  • Serve as the primary customer-facing security and compliance representative for enterprise prospects and customers.
  • Build and maintain a reusable response library for common security and compliance questions.
  • Automate compliance posture validation across frameworks such as SOC 2 Type II, ISO 27001, and HIPAA.
  • Coordinate evidence collection, external auditor relationships, and readiness for annual compliance assessments.
  • Build dashboards and reporting pipelines that provide leadership visibility into compliance posture, risks, and program health.
  • Design and automate third-party risk assessment workflows, including vendor tiering and continuous monitoring.
  • Perform risk assessments, maintain the risk register, and escalate material findings with remediation recommendations.
  • Author, maintain, and operationalize security policies and procedures, including employee acknowledgments and exceptions.
  • Collaborate with Engineering, Legal, Product, Sales, and procurement stakeholders to resolve compliance gaps and support customer reviews.

Requirements

  • 8+ years of experience in GRC, information security compliance, or a closely related field.
  • Hands-on experience with at least two major compliance frameworks, such as SOC 2, ISO 27001, HIPAA, PCI-DSS, or FedRAMP.
  • Direct experience with audits and assessments.
  • Proven track record managing high volumes of security questionnaires and enterprise due diligence requests, including SIG and CAIQ formats.
  • Strong understanding of how security programs support company revenue and partnership with Go-to-Market teams.
  • Scripting and automation fluency in Python, Bash, or similar tools.
  • Experience building tools or automation, not just spreadsheets.
  • Strong customer-facing communication skills and the ability to present to executives, procurement teams, and technical stakeholders.
  • Solid understanding of risk management principles, including risk assessments and risk register maintenance.
  • Bachelor's degree in Information Security, Computer Science, Business, or a related field, or equivalent experience.
  • Security certifications such as CISSP, CISM, CRISC, CISA, or CCSP are preferred.
  • Experience with GRC platforms such as Vanta, Drata, Sprinto, or similar is preferred.
  • Familiarity with NIST CSF or NIST 800-53 is preferred.
  • Experience in SaaS, fintech, or healthcare environments with regulated data requirements is preferred.
  • Experience drafting or reviewing DPAs, BAAs, or security-related contract language is preferred.
  • Experience supporting FedRAMP authorization or state-level public sector compliance programs is preferred.

Benefits

  • Estimated salary range of $180,000 to $225,000, depending on qualifications and location.
  • Eligibility to մասնակցate in Temporal's equity plan.
  • Unlimited PTO plus 12 holidays and 2 floating holidays for U.S. employees.
  • 100% employer-paid medical, dental, and vision premiums for U.S. employees.
  • AD&D, short-term disability, long-term disability, and life insurance coverage, with standard and supplemental options.
  • 401(k) plan.
  • Learning and development support, professional memberships, and career enrichment funding.
  • Lifestyle spending account, in-home office setup support, work-from-home meals, internet reimbursement, and Calm app access for mental wellness.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

RASP Cyber Force | Професійна програма для ветеранів у сфері кібербезпеки

Raiffeisen Bank’s RASP Cyber Force is a six-month cybersecurity development program for veterans and service members, combining training and part-time work in one of the bank’s information security teams.

Cybersecurity Encryption Network Security Penetration Testing SOC
16 hours, 4 minutes ago

Senior Cryptocurrency Engineer

Lever 251-1K Professional Services

AnaVation is hiring a Senior Cryptocurrency Engineer to lead blockchain analysis and digital-asset investigations supporting federal cyber-enabled financial-crime and cryptocurrency cases.

Bitcoin Cybersecurity
16 hours, 19 minutes ago

Security Engineer

Worth AI Internet Software & Services

Worth AI is seeking a hands-on Security Engineer to strengthen vulnerability management, harden AWS environments, and embed application security into software delivery.

AWS Bash CI/CD JIRA Linear Python
16 hours, 34 minutes ago

Head of IT and Internal Security

Beyond is hiring a Head of IT & Internal Security to define and deliver its global internal technology and security strategy across a complex international organization.

GCP
16 hours, 34 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers