SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Verkada is seeking a GRC (Governance, Risk, and Compliance) Engineer to build and lead the GRC function within the Security Team. This role is critical as Verkada scales globally with increasing enterprise customers who demand sophisticated security and compliance standards.
You will design and implement scalable, automated compliance programs that enable rapid business growth while maintaining customer trust. Key responsibilities include:
- Work cross-functionally with Security, IT, Engineering, Product, and Legal to guide security controls implementation, effectiveness, and automation across AWS, GitHub, and other platforms
- Build and maintain tooling for testing and continuous monitoring of security controls
- Develop and maintain the roadmap for continuous security compliance across Corporate, IT, and Product environments with focus on increasing automation
- Develop and maintain company-wide security policies, procedures, and plans; communicate best practices around applicable laws, regulations, and controls
- Create procedural documentation, training materials, and process documentation
- Perform annual security risk assessments and prepare risk treatment plans
- Conduct vendor security assessments to evaluate third-party security postures
- Manage the Security Exception Process to track exceptions, manage approvals, and improve automation
- Maintain customer-facing security documentation and FAQs
- Collaborate on Business Impact Assessments and annual BCP/DR activities
- Leverage AI and automation to scale GRC functions
- Work with internal and external auditors to achieve continuous compliance
You bring 7+ years of security/IT compliance experience, with demonstrated expertise in SOC 2, ISO 27001, and cloud software compliance. You have strong written and verbal communication skills, experience with AWS or similar cloud providers, and the ability to work autonomously across cross-functional teams in ambiguous situations. Scripting experience (Python, JSON) and prior experience automating audit evidence collection are bonuses. This is a full-time, onsite role requiring five days per week in San Mateo.