433,960open jobs
15,178companies
61,739added this week
Browse all
Salary
$82k – $181k per year (Estimated)
Location
Remote/Hybrid (Panama, Panama)
Seniority
Senior · 5+ years exp
Overview
Company
Impact
Profile match
A-LIGN is a cybersecurity compliance and audit firm headquartered in Tampa, Florida, and founded in 2009. The company performs SOC 2, ISO 27001, HITRUST, PCI DSS, FedRAMP, and other assessments, and sells A-SCEND, a platform that manages evidence collection across multiple frameworks. It is a licensed CPA firm and accredited certification body serving technology and cloud service providers preparing for enterprise and government audits.

About the Role 

The Senior GRC Engineer owns audit evidence collection and technical control maintenance across A-LIGN's growing portfolio of compliance frameworks, including FedRAMP Moderate Equivalency, FedRAMP 20x, ISO 27001, ISO 42001, and SOC 2. This role bridges the GRC function and A-LIGN's technical teams, working hands-on in GCP, GitHub, and Microsoft 365 to collect evidence, verify controls, and keep A-LIGN continuously audit-ready. The Senior GRC Engineer works cross-functionally with every technical department in the company to reduce audit burden on engineering and IT while protecting the certifications that A-LIGN's clients and platforms depend on. The role also supports broader information security activities, including risk assessments, threat modeling, security reviews, and AI technical safeguards.

Reports to

Chief Information Security Officer

Pay Classification

Full-Time 

Responsibilities 

  • Own end-to-end audit evidence collection, validation, and organization across A-LIGN's compliance frameworks, including FedRAMP (Moderate Equivalency and FedRAMP 20x), ISO 27001, ISO 42001, SOC 2, NIST 800-53, and NIST 800-171
  • Maintain and continuously verify technical controls across A-LIGN's cloud and corporate environments, including Google Cloud Platform (GCP/GKE), GitHub, and Microsoft 365/Entra ID
  • Serve as the primary liaison between the GRC function and technical departments (IT, Engineering, DevOps) to gather evidence, validate control implementation, and reduce audit burden on those teams
  • Support FedRAMP continuous monitoring activities, including Key Security Indicator (KSI) evidence, vulnerability scan artifact collection, POA&M tracking, and assessor (3PAO) requests
  • Build and maintain evidence automation, including integrations between GRC tooling and source systems (identity provider, cloud platforms, code repositories, ticketing, endpoint management) to reduce manual collection effort
  • Support A-LIGN's ISO 42001 Artificial Intelligence Management System (AIMS), including AI risk register evidence, AI control monitoring, and nonconformity remediation tracking
  • Prepare audit-ready evidence packages and coordinate directly with external assessors and certification bodies during assessment windows
  • Monitor control health between audit cycles, identify control drift or failures, and drive remediation with control owners before findings occur
  • Maintain compliance documentation, including control narratives, policies, and procedures
  • Support supplier and vendor security reviews with framework-specific evidence requirements
  • Track framework changes (FedRAMP 20x requirements, ISO standard revisions, SOC 2 criteria updates) and translate them into actionable control and evidence updates
  • Conduct security risk assessments and contribute to A-LIGN's corporate risk management program and risk register
  • Participate in threat modeling for A-SCEND features, internal systems, and AI use cases, and translate findings into control improvements
  • Perform security reviews of new tools, vendors, and internal initiatives, including support for Vendor Review Board activities
  • Implement and validate AI technical controls and safeguards, including data loss prevention, AI connector and agent governance, and acceptable use enforcement, in support of A-LIGN's AI Management System
  • Report compliance posture, evidence status, and audit readiness metrics to the CISO and GRC leadership

Minimum Qualifications 

EDUCATION 

  • Bachelor's degree in information systems, cybersecurity, business, or equivalent combination of education and experience

EXPERIENCE 

  • 5+ years of experience in information security, GRC, IT audit, or compliance engineering roles
  • Hands-on experience with audit evidence collection and technical control validation for at least two of the following: FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171
  • DevSecOps or cloud engineering experience sufficient to independently locate and extract evidence from GCP, GitHub, and Microsoft 365/Entra ID environments
  • Experience with GRC platforms and evidence automation (AuditBoard, Vanta, Drata, or similar)
  • Experience supporting external audits and assessor interactions, including 3PAO assessments
  • Working knowledge of vulnerability management, CI/CD pipelines, infrastructure-as-code, and identity and access management concepts
  • Experience scripting or automating evidence collection (Python, PowerShell, or similar) preferred
  • Familiarity with risk assessment methodologies, threat modeling (e.g., STRIDE), and security review processes preferred

CERTIFICATIONS  

  • CISA, CISSP, CCSK/CCSP, ISO Lead Auditor/Implementer, or relevant certifications preferred but not required

SKILLS 

  • Strong cross-functional collaboration and project management skills
  • Ability to translate framework requirements into clear, actionable requests for technical teams
  • Highly organized with the ability to manage evidence deadlines across multiple concurrent audit cycles
  • Excellent written communication for control narratives, evidence descriptions, and assessor responses
  • Self-directed with strong follow-through in a fast-paced, deadline-driven environment
  • Proven experience utilizing AI tools to automate manual tasks, streamline workflows, and increase team efficiency
  • Experience operating in PE-backed or high-growth environments preferred

Benefits 

  • Employer Paid Life & Health Insurance 
  • Competitive Bonus Structure 
  • Home Office Reimbursement 
  • Technology Allowance 
  • Certification Reimbursement 
  • BeneficiaT Discount Loyalty Program 
  • Personalized Career Coaching 
  • Generous Paid Time Off 
  • Paid Office Closure December 25-January 1 
  • Summer Hours 

About A-LIGN 

A-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor. To learn more, visit a-lign.com. 

Come Work for A-LIGN! 

Apply online today at A-LIGN.com and learn about life at A-LIGN by following us on LinkedIn.  

A-LIGN is an Equal Opportunity Employer.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
433,960 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Panama
Research Nurse 1 day ago
$44k – $99k per year (Estimated) • In office • 2+ years exp • Bachelor's Degree • Madison
DevOps
GCP
Apply
$61k – $157k per year (Estimated) • In office • Internship • Bachelor's Degree • Schaumburg
Python
Verilog
VHDL
Apply
$100k – $237k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Pittsburgh • Raleigh • Dallas
SQL
DevOps
CI/CD
QA
Selenium
Apply
$22k – $45k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Hyderabad
Python
SQL
SAS
Apply
$48k – $94k per year (Estimated) • In office • Full-Time • 2+ years exp • Bachelor's Degree • Toronto
Python
SQL
AI/ML
Prompt Engineering
AI Agents
RAG
DevOps
AWS
Analytics
Tableau
Power BI
Informatica
Management
Confluence
Apply
$80k – $160k per year (Estimated) • Remote/Hybrid • 5+ years exp • Bachelor's Degree • Tampa
Cybersecurity
ISO 27001
SOC 2
FedRAMP
Apply
Remote/Hybrid • Bachelor's Degree • Sofia
Cybersecurity
ISO 27001
SOC 2
FedRAMP
Marketing
LinkedIn
Apply
Senior IT Engineer 2 days ago
$91k – $180k per year (Estimated) • Remote/Hybrid • 4+ years exp • Bachelor's Degree • Panama
PowerShell
AI/ML
Copilot
Cybersecurity
ISO 27001
SOC 2
NIST 800-53
FedRAMP
Microsoft Entra ID
Management
Power Automate
Apply
Senior Accountant 2 days ago
$86k – $172k per year (Estimated) • Remote/Hybrid • 3+ years exp • Bachelor's Degree • Tampa
Cybersecurity
ISO 27001
SOC 2
FedRAMP
Apply
$111k – $242k per year (Estimated) • Remote/Hybrid • 8+ years exp • Bachelor's Degree • Panama
Cybersecurity
ISO 27001
SOC 2
FedRAMP
Apply
$66k – $111k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Panama
Apply
Aviation Mechanic 1 day ago
$41k – $86k per year (Estimated) • In office • Secret • 3+ years exp • High School Diploma • Panama
Apply
Remote • Part-Time • Panama
Python
Cybersecurity
MITRE ATT&CK
Management
Miro
Discord
Apply
$84k – $189k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Guaynabo • San Jose • Panama • Mexico City
Analytics
Power BI
Microsoft Excel
Apply
$60k – $159k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Panama
Apply
See all jobs
This is one of many
433,960 more open roles from verified company boards, updated every day.