SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 220,000 - 0 / annual
Turing is seeking a Staff GRC Engineer to bring an engineering mindset to governance, risk, and compliance. The company works with frontier AI labs and Fortune 500 enterprises to build high-quality datasets, reinforcement learning environments, and agentic AI systems. This is a senior, hands-on role focused on automating compliance rather than treating it as a manual spreadsheet exercise.
In this role, you will build and operate compliance automation systems including continuous controls monitoring, automated evidence collection, and control testing across cloud and corporate systems. You'll implement compliance-as-code and policy-as-code so controls are defined, versioned, tested, and enforced programmatically. You'll integrate GRC tooling with systems that hold evidence (cloud providers, identity providers, ticketing systems, CI/CD, HRIS) via APIs.
You'll create dashboards and reporting that provide real-time visibility into control health, drift, and audit readiness. A key responsibility is reducing audit burden by automating the collection and packaging of evidence for SOC 2, ISO 27001, and other frameworks. You'll partner with GRC analysts and risk owners to translate control requirements into technical checks and remediation workflows, and automate access reviews, risk assessments, and vendor risk workflows.
As a Staff engineer, you'll set the technical direction for how GRC operates at scale, mentor analysts and engineers on automation, and free up the organization from manual audit toil so it can focus on actual risk reduction. Your impact reaches beyond the automation you personally write—you'll identify where automation removes the most toil and risk, and make audit readiness a byproduct of how systems already run.
Requirements:
- Significant experience (typically 8+ years) spanning security/GRC and software engineering, with a strong hands-on engineering background
- Strong programming skills (Python, Go, or similar) and comfort building integrations against APIs
- Working knowledge of compliance frameworks (SOC 2, ISO 27001, and similar) and what evidence and control testing actually require
- Experience with cloud environments (AWS, GCP, or Azure) and infrastructure-as-code
- Familiarity with GRC/compliance automation platforms and continuous controls monitoring concepts
- Ability to lead cross-team initiatives and translate between compliance and engineering
Nice to have:
- Experience implementing compliance-as-code or building custom GRC tooling
- Familiarity with policy-as-code (e.g., OPA) and drift detection
- Prior experience surviving audits and knowing where the manual pain lives
- Relevant certifications (CISA, CISSP, or similar)