The Sr. Engineer, Governance, Risk & Compliance (Audit & Compliance) is responsible for leading the organization’s audit and compliance programs, ensuring continuous alignment with regulatory, contractual, and security framework requirements. This role owns the end-to-end audit lifecycle, including planning, readiness, evidence management, auditor coordination, and remediation tracking across frameworks such as SOC 2, HITRUST, PCI DSS, HIPAA, and NIST CSF. The individual will act as the primary liaison between internal stakeholders and external auditors, ensuring audit readiness and sustained compliance posture. This position operates as a senior individual contributor responsible for driving compliance execution, maintaining control frameworks, and leveraging GRC tools to enable scalable and efficient compliance operations. Leverage tools and technology to support Information Security audit, compliance, and GRC initiatives across the Information Security Program Act as system administrator for certain security or GRC tools such as phishing and training platforms, GRC/IT Risk Management tools, Third Party Risk Management (TPRM) platforms, Risk Register, privacy management, etc. Integrate related tools and workflows with other systems as needed. Engage with internal stakeholders and security vendors on design sessions, and help configure and optimize GRC solutions and compliance workflows. Work with IT partners in Application Security, Security Engineering and Operations, Enterprise Applications, Desktop Support, Help Desk, Networking and Infrastructure Operations, to get data and information needed to support GRC work and audit & compliance activities. Collaborate with IT teams and Information Security teams to obtain security and operational data needed to support audit, compliance, and risk assessment activities. Work with IT teams and partners to align GRC objectives with enterprise security controls and operational processes including cybersecurity / technology solutions such as IAM, PAM, MFA, RBAC, SSO, DLP, IDS/IPS, XDR, MDM, SIEM, etc. Support data analysis, metrics, dashboards and reporting activities by pulling data from source systems. Stay current with evolving regulatory requirements, compliance frameworks, industry trends, threat intelligence and make recommendations for process and control improvements. Participate in security incidents and support related audit, compliance and remediation activities as needed. Support security assessment requests for customers, HITRUST, SOC 2, etc. by pulling appropriate data as needed. Work with IT partners to align GRC requirements with operational processes such as secure software development life cycle, software engineering, infrastructure, network, etc. Maximize the utilization of GRC tools and technology to improve program efficiency and audit readiness Assist with the development and maintenance of policies, procedures and compliance documentation. Stay current with changes in information security and cybersecurity regulations, industry frameworks, and best practices, and apply them to existing NextGen GRC solutions and processes. Use GRC and security engineering skills to help streamline or automate NextGen methodology for maintaining accreditations or certifications (e.g., SOC 2, HITRUST, etc.). Use GRC and security engineering skills to help streamline or automate NextGen methodology for responding to customer security assessments or questionnaires.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior