SlipstreamJobsFresh Startup & VC-Backed Jobs

Sr. GRC Engineer

Pendo - Raleigh, NC, United States - Hybrid - posted 2026-09-24

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 133,400 - 160,000 / annual

Pendo's Information Security team is seeking a Senior GRC Engineer to lead the evolution of governance, risk, and compliance programs. This role independently owns complex compliance, risk, and incident-response initiatives while identifying program maturity gaps, translating security risk into business terms, and contributing to security roadmap and investment decisions. Day-to-day responsibilities include: **AI-driven compliance acceleration**: Use AI tools to accelerate audit evidence preparation, policy documentation, control testing workflows, and regulatory research. Evaluate GRC platform automation capabilities and integrate AI tooling to reduce manual overhead, then document and share effective approaches with the team. **Security program strategy**: Identify maturity gaps across compliance and security operations, translate them into prioritized roadmap recommendations grounded in business risk, and contribute to security investment discussions. Clarify tradeoffs between coverage, cost, and risk, and anticipate emerging regulatory requirements. **Compliance program ownership**: Own one or more regulatory compliance programs end-to-end, including SOC 2 Type II, ISO 27001/42001, PCI-DSS, GovRAMP, or FedRAMP. Lead control design, evidence collection, auditor relationships, and remediation tracking. **Risk assessment and leadership**: Conduct organizational risk assessments and present findings to leadership with clear prioritization and investment-level recommendations. Translate technical exposure into business-risk language that enables informed decision-making. **Incident response leadership**: Lead incident response for complex, multi-system security events from investigation through resolution. Conduct root cause analysis, run post-incident reviews, and own resulting actions that turn findings into measurable program improvements. **Cross-functional partnership**: Work directly with engineering, product, and IT teams to deliver compliance requirements, validate implementations, and embed security into day-to-day operations. Pendo is a hybrid culture requiring in-office presence 3 days per week unless designated remote. The company was founded in 2013 and is backed by Battery Ventures, Salesforce Ventures, Spark Capital, and Meritech. **Requirements:** - 3 to 5 years of hands-on security experience with demonstrated ownership of compliance programs or security operations work - Deep working knowledge of at least two of: SOC 2, ISO 27001, PCI-DSS, FedRAMP, GovRAMP, or NIST 800-series - Demonstrated ability to independently own auditor relationships and manage an audit cycle end-to-end - Experience leading incident response investigations from triage through root cause analysis - Ability to translate security risk into business-risk language for leadership decision-making - Active, demonstrated use of AI tools to accelerate security workflows (evidence collection, policy drafting, regulatory research, detection analysis) - Strong written and verbal communication skills, tailored for engineering, auditor, and leadership audiences **Nice-to-haves:** - SIEM or EDR platform experience (Splunk, Elastic, CrowdStrike, SentinelOne) with independent detection rule writing - GRC platform administration (Vanta, Drata, Archer) with automation configuration and integrations - Threat intelligence operationalization or threat hunting using MITRE ATT&CK - Security certification (CISA, CISSP, CISM, Security+, or equivalent) - SaaS company experience with concurrent multi-framework compliance obligations

Similar roles