The Sr. Information Security GRC Engineer serves as the operational owner for the organization's regulatory compliance, which includes PCI, Information Technology Audit Management, Third-Party service provider oversight, and security-related data privacy programs. This role is responsible for ensuring the organization maintains a strong compliance posture, remains audit-ready, meets regulatory and contractual obligations, and effectively manages security risks through governance and oversight. As a senior individual contributor, this position drives outcomes through influence, collaboration, and accountability rather than direct authority. The role partners closely with Information Security, Technology, Legal, Privacy, Internal Audit, Procurement, HR, Marketing, and business stakeholders to coordinate assessments, manage audits, oversee remediation efforts, and strengthen the organization's overall security governance framework. Success in this role is measured by successful audit outcomes, reduction of repeat findings, timely remediation of identified risks, and the ability to make compliance processes efficient, predictable, and business enabling.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior