GRC Engineer

ID.meMountain View, VA
5dOnsite

About The Position

ID.me is seeking a GRC Engineer to design, build, and operate AI agents that automate the compliance lifecycle across FedRAMP, ISO 27001, SOC 2, and Kantara accreditation programs. This role is a technologist that focuses on solving GRC domain problems with automation and AI.. You will write code and build tooling to scale GRC capabilities and reduce the compliance burden.. You will own engineering AI capabilities while also have the skillset to dive into compliance issues as another set up hands.. The primary initial challenge is automated evidence collection. You will develop programmatic methods to extract evidence from source systems, feed it into evaluation agents, and enable continuous monitoring to replace traditional annual snapshots with ongoing automated assurance. This role is based out of our Mountain View, CA or McLean, VA offices and requires full-time in-office attendance

Requirements

  • 5+ years of software engineering experience.
  • Experience building AI/ML-powered applications or agentic systems.
  • Proficiency in Python (or another language) an d experience with API integrations/data processing.
  • Familiarity with at least one compliance framework (FedRAMP, ISO 27001, SOC 2, or NIST).
  • Experience with Git, CI/CD, and deploying production-grade services.

Nice To Haves

  • Experience with the Anthropic Claude API, Model Context Protocol (MCP), or Claude Agent SDK.
  • Experience extracting data from cloud infrastructure (AWS, GCP) or security tooling (SIEM, vulnerability scanners).
  • Familiarity with GRC platforms (LogicGate, ServiceNow) or compliance data models.
  • Experience with OSCAL (Open Security Controls Assessment Language).
  • Background in highly regulated environments (FinTech, GovCloud, Healthcare).

Responsibilities

  • Own the full development lifecycle for AI agents designed to automate evidence collection, evaluation, and continuous monitoring.
  • Serve as the technical lead for LogicGate and our GRC SaaS integrations, ensuring the platform scales with our data needs.
  • Develop programmatic methods to extract evidence from source systems (AWS, GCP, GitHub) and feed it into evaluation agents to replace traditional annual audits.
  • Act as a high-bandwidth teammate capable of picking up slack in "traditional" GRC areas: policy authoring, change management, and manual controls enforcement.
  • Support the team's deep-dive efforts into FedRAMP, ISO 27001, and SOC 2, translating domain expertise into automated agent logic.
  • Build and maintain integration layers (MCP servers, APIs) that allow GRC tools to interact seamlessly with our internal ecosystem (Jira, BigQuery).
  • Contribute towards preparing compliance documentation, control evidence, and control owners for internal and external audits
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service