SlipstreamJobsFresh Startup & VC-Backed Jobs

GRC Engineer

Forward Networks - Santa Clara, CA, United States - In-office - posted 2026-09-25

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 140,000 - 170,000 / annual

Forward Networks, founded in 2013 by Stanford Ph.D.s, is the industry leader in network digital twins—mathematically accurate models of production networks that enable autonomous networking and AI-driven change impact analysis. Trusted by Goldman Sachs, PayPal, S&P Global, IBM, Dell, and government agencies, Forward is backed by top-tier investors including Andreessen Horowitz and Goldman Sachs. Forward is hiring a GRC Engineer to pioneer a new discipline: moving beyond manual compliance spreadsheets and quarterly auditor chases to building automated, evidence-driven compliance systems. This role combines GRC engineering (compliance automation, audit management, control design and testing, risk management) with a growing Security Operations component (SIEM/SOAR administration, incident response, alert triage). For the first ~6 months, your focus is GRC Engineering: • Write, maintain, and drive review cycles for security policies and procedures • Build automated control tests that verify system configurations directly at the source (e.g., confirming MFA enforcement in identity providers) rather than relying on manual spreadsheets • Manage and extend GRC platforms (Vanta, Drata, etc.) using scripts and API integrations • Continuously monitor control drift between audits and drive remediation • Lead day-to-day SOC 2 Type II audits and lay groundwork for ISO 27001 and ISO 42001 • Maintain a prioritized risk register and run actionable risk assessments • Handle vendor security reviews and due diligence by pulling evidence from APIs and trust pages • Integrate compliance requirements directly into engineering workflows (CI/CD, access provisioning, change management) Once critical automations are in place, the role expands to include Security Operations: • Tune SIEM/SOAR detection rules, correlation logic, and response playbooks • Assist with EDR, DLP, and endpoint incident response • Participate in security alert triage and documentation • Jump into incident response investigations, containment, and post-mortem write-ups • Feed operational insights back into the GRC side to identify gaps between compliance platforms and actual operations This is a genuine split role for someone who can grow to handle both compliance engineering and security operations work. REQUIREMENTS: • 3+ years in GRC, compliance, security engineering, IT audit, or equivalent, with hands-on exposure to control design, risk assessment, and compliance frameworks • Experience writing policies and procedures with a focus on testable and verifiable outcomes • Demonstrated work in a GRC/compliance automation platform (Vanta, Drata, Thoropass, Anecdotes, or similar) • Solid working knowledge of SOC 2; ISO 27001 experience is a plus; curiosity about AI governance (ISO 42001) is important • Basic scripting ability: Python or Bash, SQL, and comfort pulling data from APIs, parsing log files, or automating manual tasks. You will not be a software engineer, but must be able to read, troubleshoot, and deliver working scripts • Some exposure to SIEM/SOAR tooling (Splunk, Chronicle, Panther, XSOAR, Tines, etc.) and basic understanding of how incident response operates • Ability to communicate effectively with both auditors and engineers in their respective languages • Tolerance for ambiguity; GRC Engineering is an evolving field and parts of this role will be figured out collaboratively • Experience with endpoint compliance in a Mac-centric environment Nice to have: • Comfort with Linux administration and scripting; experience with Terraform or policy-as-code • Security certifications (Security+, CISA, CISSP, ISO 27001 Lead Implementer/Auditor) • Real-world SIEM/SOAR tuning, migration, or incident response experience • Experience running tabletop exercises, post-mortems, and driving findings to completion with stakeholders

Similar roles