SlipstreamJobsFresh Startup & VC-Backed Jobs

Sr. Security Assurance Engineer

6sense - Remote - Remote - posted 2026-08-27

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

6sense is seeking a Senior Security Assurance Engineer to lead the engineering capability of its Governance, Risk and Compliance (GRC) team. This role focuses on building automated systems that continuously test and monitor security controls, rather than relying on periodic manual testing. Key responsibilities include: • Design and build automated security control monitoring systems using production-quality code (Python) with version control, peer review, and CI/CD pipelines. Treat control logic as maintained software assets rather than documented procedures. • Transform the control library from periodic, sample-based manual testing to continuous control monitoring (CCM). Define technical signals for each control, test frequency, pass/fail thresholds, alerting, and escalation paths. • Engineer self-service technical evidence collection in AWS using native services (Config, Security Hub, CloudTrail, Organizations/SCPs, IAM Access Analyzer, Systems Manager, EventBridge, Lambda, Athena/S3, CloudWatch) so control owners and auditors can retrieve current evidence on demand without GRC intermediation. • Eliminate manual, screenshot-based, and ticket-driven evidence collection by retiring manual test procedures as automated equivalents come online. • Redesign GRC processes to be AI-native, applying LLMs and agentic workflows to evidence review, control mapping, gap analysis, security questionnaires, customer due diligence responses, policy drafting, and risk assessment triage, with explicit human-in-the-loop review and guardrails. • Maintain a single normalized control library crosswalked across frameworks (ISO 27001, SOC 2, PCI DSS, SOX, GDPR, NIST) so one automated test satisfies multiple obligations. • Build the control-failure pipeline end-to-end: automated detection, enrichment, ticket creation, owner routing, SLA tracking, remediation verification, and closure, including exception and risk acceptance handling. • Partner with Platform Engineering, DevOps, and IT to shift controls left into preventive guardrails: service control policies, AWS Config conformance packs, policy-as-code in CI/CD, and secure-by-default infrastructure patterns. • Instrument control health reporting with dashboards showing automation coverage, evidence freshness, control failure rates, mean time to remediate, and audit-readiness posture. • Lead internal and external audit engagements using automated evidence as the primary artifact; defend automated test design and completeness to auditors and assessors. • Oversee complex control tests and third-party operational security risk assessments using tooling and AI-assisted analysis. • Set the technical bar for the team through peer review of other GRC Engineers' automation, queries, and test logic, enabling distributed automation ownership. • Provide GRC technology administration, including integrations, API-based data flows, user training, and enablement. Reports to Director, Security Assurance. This is a high-impact role combining security expertise with software engineering discipline to transform GRC from a compliance checkbox into a continuous, automated, AI-augmented capability.

Similar roles