Talent.com
Governance, Risk & Compliance (GRC) Engineer
Governance, Risk & Compliance (GRC) EngineerSmarsh • Atlanta, GA, US
Governance, Risk & Compliance (GRC) Engineer

Governance, Risk & Compliance (GRC) Engineer

Smarsh • Atlanta, GA, US
7 days ago
Job type
  • Full-time
Job description

Job Description

Job Description

Who are we?

Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or headlines.  Relentless innovation has fueled our journey to consistent leadership recognition from analysts like Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008.

Summary

Smarsh is a global leader in digital communications capture, archiving, and oversight. Smarsh is committed to embedding security as a business enabler through governance process excellence and scalable control frameworks. As a GRC Engineer, you will play a critical role in advancing our governance, risk, and compliance programs. You’ll be responsible for defining, implementing, and optimizing security controls and risk processes that support operational alignment across the organization. This role requires an understanding of how governance can scale through automation, control validation workflows, and "Policy as Code" principles. You’ll collaborate closely with engineering, security, legal, and business teams to ensure our GRC practices mature in step with our growth.

How will you contribute?

  • ISMS Governance & Controls Assurance : Lead the ongoing maintenance and enhancement of Smarsh’s ISO 27001-aligned ISMS, ensuring policies, controls, and governance processes are clear, actionable, and aligned with business operations. Author and maintain security control narratives, working closely with technical teams to ensure controls are designed with enforceability and operational alignment in mind. Oversee the Control Assurance Program, ensuring effective evidence collection, control testing, and continuous monitoring practices. Coordinate internal and external audit readiness (SOC 2, ISO 27001, FedRAMP, customer audits) through structured governance workflows.
  • Risk Management & Governance : Manage the risk assessment lifecycle, ensuring comprehensive engagement across business, technical, and third-party risk domains. Facilitate risk acceptance workflows, maintaining governance rigor through well-defined documentation and approval processes. Ensure effective governance of risk treatment plans, enabling clear tracking and status reporting.
  • Regulatory, Contractual & Client Assurance : Translate emerging regulations (e.g., DORA, SEC Cyber Rules, UK AI Act) into internal governance requirements and operational processes. Manage customer security assessments and DDQs, utilizing standardized assurance artefacts to deliver efficient, high-quality responses. Ensure external assurance artefacts are maintained and accessible through the Smarsh Trust Center.
  • Third-Party & Supply Chain Risk : Lead third-party security reviews and ensure governance controls are extended across the vendor lifecycle. Partner with Procurement and Legal to align contractual security requirements and risk acceptance criteria.
  • Policy Lifecycle & Governance Metrics : Own the policy lifecycle process, ensuring policies are regularly reviewed, updated, and tracked for compliance. Develop governance reporting and dashboards that provide clear visibility into control effectiveness, risk posture, and audit readiness. Support governance forums and leadership committees with data-driven insights and structured governance reports.
  • GRC Operations & Enablement : Lead the continual refinement of GRC workflows, ensuring operational efficiency in documentation, evidence management, and status tracking. Collaborate with Engineering and Security teams to ensure controls are practically enforceable within operational workflows. Bring forward ideas and experience around scaling governance processes through automation and control validation techniques, supporting Smarsh’s long-term governance maturity.

What will you bring?

  • 2–5 years’ experience in information security, risk management, or compliance.
  • Working knowledge of security frameworks such as ISO 27001, SOC 2, GDPR, NIST CSF, or similar.
  • Familiarity with GRC platforms and evidence lifecycle management
  • Strong organizational skills with attention to detail in documentation and reporting.
  • Effective communication skills with both technical and non-technical stakeholders.
  • Curiosity and drive to grow into GRC Engineering with a focus on automation and scalability.
  • The above salary range represents Smarsh's good faith and reasonable estimate of the range of possible base compensation at the time of posting. Any applicable bonus programs will be discussed during the recruiting process.

    The salary for this role will be set based on a variety of factors, including but not limited to, internal equity, experience, education, location, specialty and training.

    Local cost of living assessments are done for each new hire at the time of offer.

    Don't meet every requirement? Apply anyway! We value diverse candidates and encourage applications, even if you don't perfectly match the job description. Studies have shown that some strong candidates may self-select out of the interview process prematurely, at Smarsh we encourage an inclusive, high-performing environment.

    Smarsh is an equal opportunity and affirmative action employer. Qualified applicants will receive consideration without regard to their race, colour, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Smarsh invites all qualified interested applicants to apply for career opportunities. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions. Including frequency of functions.

    About our culture

    Smarsh hires lifelong learners with a passion for innovating with purpose, humility and humor. Collaboration is at the heart of everything we do. We work closely with the most popular communications platforms and the world’s leading cloud infrastructure platforms. We use the latest in AI / ML technology to help our customers break new ground at scale. We are a global organization that values diversity, and we believe that providing opportunities for everyone to be their authentic self is key to our success. Smarsh leadership, culture, and commitment to developing our people have all garnered Comparably.com Best Places to Work Awards. Come join us and find out what the best work of your career looks like.

    Create a job alert for this search

    Governance Compliance • Atlanta, GA, US

    Related jobs
    FIPS Certified Security Engineer

    FIPS Certified Security Engineer

    VirtualVocations • Atlanta, Georgia, United States
    Full-time
    A company is looking for a Security Engineer, FIPS / CC (Mobile Devices).Key Responsibilities Lead the end-to-end validation process for IT products, including assessments, development of security ...Show more
    Last updated: 30+ days ago • Promoted
    Senior SOC Security Engineer

    Senior SOC Security Engineer

    VirtualVocations • Marietta, Georgia, United States
    Full-time
    A company is looking for a Senior SOC / Splunk Security Engineer.Key Responsibilities Monitor, detect, and respond to security incidents using SIEM and EDR tools Conduct deep-dive investigations i...Show more
    Last updated: 30+ days ago • Promoted
    Senior Directory Services Engineer

    Senior Directory Services Engineer

    VirtualVocations • Lawrenceville, Georgia, United States
    Full-time
    Lead Directory Services Engineer responsible for leading and advancing enterprise directory infrastructure across various environments. Key Responsibilities Design, secure, and maintain directory ...Show more
    Last updated: 2 days ago • Promoted
    Governance, Risk & Compliance (GRC) Engineer

    Governance, Risk & Compliance (GRC) Engineer

    Smarsh • Atlanta, GA, US
    Full-time
    Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications.Our growing community of over 6500 organizations in regulated industries counts on Smarsh every...Show more
    Last updated: 7 days ago • Promoted
    Consultant Engineer

    Consultant Engineer

    FM • STONE MOUNTAIN, Georgia, United States
    Full-time
    FM is one of the world’s largest risk management and industrial property insurance organizations.With 76 office locations in over 60 countries worldwide, FM provides specialized property protection...Show more
    Last updated: 11 days ago • Promoted
    GRC Analyst

    GRC Analyst

    VirtualVocations • Alpharetta, Georgia, United States
    Full-time
    A company is looking for a GRC Analyst to support IT risk management, compliance, and governance frameworks.Key Responsibilities Develop, evaluate, and implement governance, risk, and compliance ...Show more
    Last updated: 30+ days ago • Promoted
    GRC Engineering Manager

    GRC Engineering Manager

    VirtualVocations • Lawrenceville, Georgia, United States
    Full-time
    A company is looking for a Manager, GRC Engineering to oversee cybersecurity compliance programs.Key Responsibilities : Develop, write, and maintain policies and procedures for compliance with SOC...Show more
    Last updated: 11 hours ago • Promoted • New!
    Senior Director, Cyber Resilience

    Senior Director, Cyber Resilience

    VirtualVocations • Atlanta, Georgia, United States
    Full-time
    A company is looking for a Senior Director, Cyber & Technology Resilience to lead and enhance its technology resilience strategies. Key Responsibilities : Establish and lead a Technology Resilience...Show more
    Last updated: 1 day ago • Promoted
    Software Development Compliance Director

    Software Development Compliance Director

    VirtualVocations • Alpharetta, Georgia, United States
    Full-time
    A company is looking for an Associate Director of Software Development Compliance.Key Responsibilities Define and maintain a compliant software development lifecycle integrated with quality manag...Show more
    Last updated: 1 day ago • Promoted
    Lead Application Security Engineer - 19562

    Lead Application Security Engineer - 19562

    Cox Automotive • Redan, GA, US
    Full-time
    The Lead Application Security Engineer will partner with Security Engineering Enablement and Security Architecture to design and ship secure software : secure code reviews and help define requiremen...Show more
    Last updated: 2 days ago • Promoted
    Development Inspector

    Development Inspector

    Coweta County • Newnan, GA, US
    Full-time
    Announcement Open Until Filled.Dept / Div : Community Development / N / A .Performs intermediate skilled technical work inspecting development construction sites for compliance with Federal, State and l...Show more
    Last updated: 30+ days ago • Promoted
    Security Architect - AI Governance

    Security Architect - AI Governance

    VirtualVocations • Lawrenceville, Georgia, United States
    Full-time
    A company is looking for a Security Architect - AI Governance to lead the design and implementation of secure, ethical, and compliant AI systems. Key Responsibilities Identify and evaluate securit...Show more
    Last updated: 30+ days ago • Promoted
    Radiant Logic Engineer

    Radiant Logic Engineer

    VirtualVocations • Lawrenceville, Georgia, United States
    Full-time
    A company is looking for a Radiant Logic Engineer to support an enterprise identity management initiative.Key Responsibilities Deploy, reconfigure, and validate RadiantOne components including FI...Show more
    Last updated: 1 day ago • Promoted
    New Jersey Licensed Cybersecurity Engineer

    New Jersey Licensed Cybersecurity Engineer

    VirtualVocations • Marietta, Georgia, United States
    Full-time
    A company is looking for a Senior Lead, Cybersecurity Engineering.Key Responsibilities Administer and maintain logical security controls on z / OS systems Oversee incident response, vulnerability ...Show more
    Last updated: 10 hours ago • Promoted • New!
    Security Engineer

    Security Engineer

    VirtualVocations • Norcross, Georgia, United States
    Full-time
    A company is looking for a Security Engineer to handle digital security and incident response.Key Responsibilities : Act as a technical lead within the cyber security group, developing team object...Show more
    Last updated: 30+ days ago • Promoted
    GRC and Privacy Analyst

    GRC and Privacy Analyst

    VirtualVocations • Lawrenceville, Georgia, United States
    Full-time
    A company is looking for a GRC & Privacy Analyst to join their Compliance team.Key Responsibilities Manage and configure the data privacy platform to ensure compliance with global regulations Ov...Show more
    Last updated: 14 hours ago • Promoted • New!
    Senior Director - Head of Risk Practice VCA NA

    Senior Director - Head of Risk Practice VCA NA

    Visa • Atlanta, GA, United States
    Full-time
    Visa is a world leader in payments and technology, with over 259 billion payments transactions flowing safely between consumers, merchants, financial institutions, and government entities in more t...Show more
    Last updated: 30+ days ago • Promoted
    Principal Security Engineer

    Principal Security Engineer

    VirtualVocations • Lawrenceville, Georgia, United States
    Full-time
    A company is looking for a Principal Security Engineer to lead information security initiatives and collaborate with development and operational teams. Key Responsibilities Identify security threa...Show more
    Last updated: 30+ days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    VirtualVocations • Decatur, Georgia, United States
    Full-time
    A company is looking for a Senior Security Engineer to join their security team.Key Responsibilities Manage identity and access management, including Okta SSO and role-based access controls Driv...Show more
    Last updated: 30+ days ago • Promoted
    Senior Vulnerability Management Engineer

    Senior Vulnerability Management Engineer

    VirtualVocations • Marietta, Georgia, United States
    Full-time
    A company is looking for a Senior Vulnerability Management Engineer to lead the identification, assessment, and remediation of security vulnerabilities across enterprise systems.Key Responsibilitie...Show more
    Last updated: 30+ days ago • Promoted