Senior GRC Engineer

Playlist
$150,000 - $170,000

About The Position

As a Senior GRC Engineer, you'll own the technical spine of how Playlist manages its control environment. That means designing the architecture that lets the team work across multiple compliance frameworks without duplicating effort at every audit, and making sure control design, evidence requirements, and implementation keep pace with regulatory change and business growth. You'll be expected to act as a technical leader who can help mature our governance, risk, compliance, in a way that is durable, measurable, and embedded into how our systems operate day to day. Your time will center on two related workstreams. The first is building and maintaining Playlist's Master Control List, a live control architecture mapped across PCI DSS, SOC 1 Type II, ISO 27001, HITRUST, and NIST CSF/800-53 that teams can use and navigate. The second is managing the full lifecycle of controls and evidence requirements as new standards are adopted, updated, or expanded to cover newly acquired brands.

Requirements

  • 6+ years of experience in security engineering, GRC, or compliance engineering, with direct hands-on work across multiple regulatory frameworks
  • Deep working knowledge of PCI DSS, SOC 1 or SOC 2, HITRUST, and at least one of ISO 27001 or NIST CSF/800-53
  • Experience designing or maintaining control frameworks, crosswalks, or unified control architectures across multiple compliance standards
  • Hands-on experience managing evidence requirements and control implementation, not just documentation
  • Proficiency with compliance automation tooling (Optro, Drata, Vanta, Hyperproof, Anecdotes, or similar)
  • Ability to translate technical control design into clear implementation guidance for engineering and product teams
  • Experience building or operating agentic AI workflows (LLM-based pipelines, multi-agent systems, RAG architectures) in a production or near-production context

Nice To Haves

  • Hands-on experience with AWS services (Lambda, Step Functions, EventBridge, S3, Aurora/RDS) for building and maintaining compliance automation infrastructure
  • Experience supporting external audits or assessments as a primary technical contact
  • Exposure to multi-brand or post-acquisition control harmonization
  • Certifications such as CISA, CISSP, ISO 27001 Lead Implementer, CCSFP (HITRUST), or PCI ISA
  • Experience in a SaaS or consumer marketplace environment

Responsibilities

  • Design and build framework crosswalks and control mappings across PCI DSS, SOC 1 Type II, ISO 27001, HITRUST, and NIST CSF/800-53, using languages such as OSCAL as the translation layer to preserve framework-specific requirements while reducing duplicate audit burden
  • Own the Master Control List end-to-end, including control nomenclature, relational database architecture, evidence linkages, and the operational model for ongoing maintenance across Playlist's multi-brand footprint
  • Manage the full lifecycle of controls, evidence requirements, and implementation as new standards are adopted, requirements change, or acquired entities are brought into scope
  • Drive evidence automation in GRC tooling, building collection workflows that scale without turning every audit season into a manual sprint
  • Partner with Security Engineering, Legal, and Finance to validate that control design reflects how the business operates, translating compliance requirements into implementation guidance that engineering teams can act on
  • Design, build and maintain AI-powered GRC tooling, multi-agent pipelines for risk quantification, evidence automation, vendor risk assessment, and compliance monitoring using cloud native tools and APIs, so the team's analytical and operational capacity scales without scaling headcount
  • Identify rationalization opportunities across frameworks, so adding a new standard to the portfolio means incremental work, not starting from scratch

Benefits

  • performance bonus
  • benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service