
Security Engineer (GRC)
Candid Health
Job description
-
We are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won’t just write policies or collect manual screenshots in spreadsheets; you will treat compliance as an engineering and data problem
-
You will build automated evidence pipelines, implement compliance-as-code, and establish continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines. You will turn point-in-time audits into a continuous compliance telemetry system that keeps our platform secure, resilient, and audit-ready at all times
-
- Compliance Automation & Engineering
-
Develop automated scripts and API integrations to collect compliance evidence directly from system sources instead of collecting manual screenshots
-
Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically
-
Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time
-
Partnering with Legal on Medicare and Medicaid compliance
-
Partnering closely with legal and finance teams on future due diligence and compliance projects
-
- Framework Mapping & Control Architecture
-
Convert regulatory, security, and industry standards (SOC 2, HiTrust, PCI, HIPAA) into clear, testable technical controls
-
Map single technical controls across multiple overlapping frameworks to eliminate redundant work
-
Work alongside DevOps and Software Engineering teams to build compliance controls directly into CI/CD pipelines without slowing down delivery
-
- Risk Management & Audits
-
Lead technical audit readiness and external audit engagements using programmatic evidence pipelines
-
Automate vendor risk management workflows and API-driven vendor evaluations
-
Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs rather than static quarterly surveys- 3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRC
-
Deep familiarity with core frameworks such as
-
Hands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as Terraform
-
Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes)
-
Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databases
-
Experience with modern continuous compliance platforms (e.g., Vanta, Drata, Anecdotes)
-
Background in software development, DevOps, or platform engineering
-
Experience with Policy-as-Code engines
-
Certifications such as CISSP, CISA, CRISC, AWS Certified Security – Specialty, or CCSP