SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
ButterflyMX is seeking a GRC Engineer to own and modernize the company's governance, risk, and compliance program. This is a generalist role spanning compliance operations, risk management, audit management, trust and assurance, vendor/supply chain risk, and operational privacy support. You will report directly to the CISO and serve as both practitioner and builder, replacing manual, point-in-time processes with AI-assisted, automated, and agentic workflows.
Key responsibilities include: owning and maturing the company risk register with AI-driven risk surfacing and scoring; leading external audit management (SOC 2 Type II) and automating evidence collection pipelines in Vanta; engineering the Trust and Assurance program with automated intake workflows and AI-assisted response generation; building a vendor and supply chain risk program with automated intake, tiered risk scoring, and continuous monitoring triggers; redesigning security and privacy policies using AI for drafting and versioning; configuring common controls monitoring in Vanta with automated alerting; modernizing the security awareness and training program; designing an integrated compliance calendar with automated reminders; supporting operational privacy practices including cookie consent management and data subject requests; monitoring the regulatory and compliance landscape, particularly AI governance developments (EU AI Act, NIST AI RMF, ISO 42001); and leveraging AI tools across every GRC workflow to demonstrate measurable efficiency gains.
You should have 3+ years of GRC, information security compliance, or risk management experience with hands-on SOC 2 audit support or leadership. Familiarity with additional frameworks (CIS Controls v8, NIST CSF, NIST AI RMF, NIST Privacy Framework, ISO 42001, ISO 27001, OWASP Top 10 for Agentic Applications, MITRE frameworks) is a strong plus. Experience conducting rapid third-party/vendor risk assessments and managing supply chain risk programs is required. Strong organizational skills and the ability to balance strategic initiatives with operational execution are essential. This role emphasizes automation, AI integration, and building scalable processes rather than managing manual compliance workflows.