Compliance Engineer

GridwareSan Francisco, CA
10d$120,000 - $145,000

About The Position

We are building our information security compliance program and this role sits at the center of that effort. As our Compliance Engineer, you will work directly with the Head of Information Security to design, implement, and operationalize controls across multiple frameworks (SOC 2, ISO 27001, NIS 2, CIS IG3, NERC CIP, and NIST). You will also own customer-facing security assurance, including security questionnaires and audit evidence requests. This is a high-visibility role for someone energized by building structure in ambiguous environments and who understands that good compliance is good engineering.

Requirements

  • 2–4 years in information security compliance, GRC, or a related discipline.
  • Working knowledge of two or more: SOC 2, ISO 27001, NIST CSF/800-53, CIS Controls, NERC CIP.
  • Experience supporting or leading external audits, including evidence collection and auditor coordination.
  • Ability to perform cross-framework control mapping and identify gaps or conflicts.
  • Strong written communication skills across technical and non-technical audiences.

Nice To Haves

  • Hands-on experience with NERC CIP (CIP-002 through CIP-014) in an OT or critical infrastructure environment.
  • Familiarity with GRC platforms such as Vanta, Drata, OneTrust, or Archer.
  • Certifications: CISA, CRISC, ISO 27001 Lead Implementer/Auditor, or NERC CIP.

Responsibilities

  • Framework Implementation & Control Management
  • Design a unified control framework mapped across SOC 2, ISO 27001, CIS IG3, NERC CIP, and NIST (CSF/800-53), eliminating duplication and creating a single source of truth for compliance posture.
  • Develop and maintain a control library, policy inventory, and risk register.
  • Translate technical control requirements into actionable guidance for engineering, IT, and operations teams.
  • Audit Readiness & Evidence Collection
  • Build a structured, repeatable evidence collection process supporting concurrent audits across all frameworks.
  • Maintain a continuously updated evidence repository and coordinate with Engineering, DevOps, HR, and Legal to gather and validate artifacts.
  • Serve as primary liaison with external auditors; manage schedules, fieldwork, and findings remediation through to closure.
  • Customer Security Assurance
  • Own intake, triage, and completion of customer security questionnaires (SIG Lite, CAIQ, custom assessments).
  • Maintain a living questionnaire knowledge base and develop customer-facing security documentation, including trust portal content.
  • Program Development
  • Define compliance workflows, SOPs, tooling requirements, and automation opportunities as the program matures.
  • Monitor regulatory changes across NERC CIP, NIS 2, and NIST; proactively communicate impacts to the team.

Benefits

  • Health, Dental & Vision (Gold and Platinum with some providers plans fully covered)
  • Paid parental leave
  • Alternating day off (every other Monday)
  • “Off the Grid”, a two week per year paid break for all employees.
  • Commuter allowance
  • Company-paid training

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Education Level

No Education Listed

Number of Employees

11-50 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service