Senior GRC Engineer
Job Description
<h4><strong>About the Role </strong></h4> <p>The Senior GRC Engineer owns audit evidence collection and technical control maintenance across A-LIGN's growing portfolio of compliance frameworks, including FedRAMP Moderate Equivalency, FedRAMP 20x, ISO 27001, ISO 42001, and SOC 2. This role bridges the GRC function and A-LIGN's technical teams, working hands-on in GCP, GitHub, and Microsoft 365 to collect evidence, verify controls, and keep A-LIGN continuously audit-ready. The Senior GRC Engineer works cross-functionally with every technical department in the company to reduce audit burden on engineering and IT while protecting the certifications that A-LIGN's clients and platforms depend on. The role also supports broader information security activities, including risk assessments, threat modeling, security reviews, and AI technical safeguards.</p> <h4><strong>Reports to</strong></h4> <p>Chief Information Security Officer</p> <h4><strong>Pay Classification</strong></h4> <p>Full-Time </p> <h4><strong>Responsibilities </strong></h4> <ul> <li>Own end-to-end audit evidence collection, validation, and organization across A-LIGN's compliance frameworks, including FedRAMP (Moderate Equivalency and FedRAMP 20x), ISO 27001, ISO 42001, SOC 2, NIST 800-53, and NIST 800-171</li> <li>Maintain and continuously verify technical controls across A-LIGN's cloud and corporate environments, including Google Cloud Platform (GCP/GKE), GitHub, and Microsoft 365/Entra ID</li> <li>Serve as the primary liaison between the GRC function and technical departments (IT, Engineering, DevOps) to gather evidence, validate control implementation, and reduce audit burden on those teams</li> <li>Support FedRAMP continuous monitoring activities, including Key Security Indicator (KSI) evidence, vulnerability scan artifact collection, POA&M tracking, and assessor (3PAO) requests</li> <li>Build and maintain evidence automation, including integrations between GRC tooling and source systems (identity provider, cloud platforms, code repositories, ticketing, endpoint management) to reduce manual collection effort</li> <li>Support A-LIGN's ISO 42001 Artificial Intelligence Management System (AIMS), including AI risk register evidence, AI control monitoring, and nonconformity remediation tracking</li> <li>Prepare audit-ready evidence packages and coordinate directly with external assessors and certification bodies during assessment windows</li> <li>Monitor control health between audit cycles, identify control drift or failures, and drive remediation with control owners before findings occur</li> <li>Maintain compliance documentation, including control narratives, policies, and procedures</li> <li>Support supplier and vendor security reviews with framework-specific evidence requirements</li> <li>Track framework changes (FedRAMP 20x requirements, ISO standard revisions, SOC 2 criteria updates) and translate them into actionable control and evidence updates</li> <li>Conduct security risk assessments and contribute to A-LIGN's corporate risk management program and risk register</li> <li>Participate in threat modeling for A-SCEND features, internal systems, and AI use cases, and translate findings into control improvements</li> <li>Perform security reviews of new tools, vendors, and internal initiatives, including support for Vendor Review Board activities</li> <li>Implement and validate AI technical controls and safeguards, including data loss prevention, AI connector and agent governance, and acceptable use enforcement, in support of A-LIGN's AI Management System</li> <li>Report compliance posture, evidence status, and audit readiness metri