SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Clerk is a developer infrastructure company providing authentication and identity management for modern web applications. They are seeking a Senior GRC Engineer to own and build their governance, risk, and compliance program.
You will be a hands-on engineer responsible for the entire compliance and security review program that customers rely on before integrating Clerk into their authentication flows. Your primary focus will be automating and streamlining compliance evidence gathering, control enforcement, and audit readiness.
Key responsibilities include:
- Own SOC 2 Type II and HIPAA compliance end-to-end: scoping, control design, evidence collection, auditor walkthroughs, and remediation
- Scope and lead the next compliance framework (ISO 27001 is the likely candidate) based on customer requirements
- Build and maintain integrations that feed the GRC platform from cloud providers, SaaS tools, and internal systems
- Convert controls into continuous automated checks using policy-as-code, configuration drift detection, and control-failure pipelines
- Run the vendor security review program, including intake and periodic re-review cycles
- Own the security questionnaire and trust center workflow
- Maintain the risk register and conduct risk assessments with documented decisions
- Embed compliance requirements into the software development lifecycle and change management through tooling
- Reduce manual effort required to pass audits by automating repetitive tasks
You will work as part of a small security team in a globally distributed company, requiring you to scope, prioritize, and ship with minimal process overhead.
REQUIREMENTS:
- 5+ years in security with demonstrated experience building automation for GRC or compliance programs
- Technical ownership of at least one SOC 2 Type II or ISO 27001 audit with ability to articulate lessons learned
- Proficiency writing code and using LLMs to increase productivity without compromising quality
- Hands-on experience with GRC platform APIs (not just dashboards)
- Cloud IAM and configuration expertise on at least one provider (GCP preferred)
- Ability to determine sufficient evidence standards and defend automated tests to auditors
- Comfortable operating in a lean security team environment with self-directed scope and prioritization
- Strong written communication skills for policies, control narratives, and customer-facing questionnaire responses
NICE-TO-HAVES:
- Experience at an all-remote company
- Production experience shipping LLM or agentic workflows for compliance work
- Background at a developer-tools company
About Clerk
SaaS / Enterprise Software — user authentication and identity management for modern web apps.