Security Engineer, GRC

Candid HealthSan Francisco, CA

About The Position

Candid Health is seeking a Security GRC Lead to establish its first in-house GRC program. This role will focus on treating compliance as an engineering and data problem, building automated evidence pipelines, implementing compliance-as-code, and establishing continuous controls monitoring across GCP infrastructure, identity systems, and CI/CD pipelines. The goal is to transform point-in-time audits into a continuous compliance telemetry system to ensure the platform remains secure, resilient, and audit-ready.

Requirements

  • 3+ years in a technical security role (Security Engineering, Cloud Security, or Technical GRC).
  • Proficiency in Python, TypeScript, SQL.
  • Hands-on experience interacting with APIs, parsing logs, and querying databases.
  • Hands-on experience with at least one primary cloud platform (GCP preferred).
  • Experience with Infrastructure-as-Code tools such as Terraform.
  • Deep familiarity with core frameworks such as SOC 2, HiTrust, PCI, HIPAA.
  • Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes).

Nice To Haves

  • Certifications such as CISSP, CISA, CRISC, AWS Certified Security – Specialty, or CCSP.
  • Experience with Policy-as-Code engines.
  • Background in software development, DevOps, or platform engineering.
  • Experience with modern continuous compliance platforms (e.g., Vanta, Drata, Anecdotes).

Responsibilities

  • Develop automated scripts and API integrations to collect compliance evidence directly from system sources.
  • Write and deploy infrastructure-as-code and policy enforcement rules to automatically enforce security baselines.
  • Maintain live compliance dashboards and alerts to flag configuration drift or policy violations in real time.
  • Partner with Legal on Medicare and Medicaid compliance.
  • Collaborate closely with legal and finance teams on future due diligence and compliance projects.
  • Convert regulatory, security, and industry standards (SOC 2, HiTrust, PCI, HIPAA) into clear, testable technical controls.
  • Map single technical controls across multiple overlapping frameworks to eliminate redundant work.
  • Work alongside DevOps and Software Engineering teams to integrate compliance controls directly into CI/CD pipelines without impacting delivery speed.
  • Lead technical audit readiness and external audit engagements using programmatic evidence pipelines.
  • Automate vendor risk management workflows and API-driven vendor evaluations.
  • Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service