Overview
The Sr. GRC Engineer at Pendo is responsible for driving the evolution of the governance, risk, and compliance program. This role involves leading complex compliance, risk, and incident-response work while contributing to security roadmap and investment decisions.
Key Responsibilities
- Utilize AI to streamline audit evidence preparation, policy documentation, control testing workflows, and regulatory research.
- Identify maturity gaps across compliance and security operations and translate them into prioritized roadmap recommendations.
- Own regulatory compliance programs end-to-end, including SOC 2 Type II, ISO 27001/42001, PCI-DSS, GovRAMP, or FedRAMP.
- Conduct organizational risk assessments and present findings to leadership.
- Lead incident response for complex security events, conducting root cause analysis and post-incident reviews.
- Work with engineering, product, and IT teams to deliver compliance requirements.
Requirements
- 3 to 5 years of hands-on security experience with compliance programs or security operations.
- Working knowledge of at least two of the following frameworks: SOC 2, ISO 27001, PCI-DSS, FedRAMP, GovRAMP, or NIST 800-series.
- Experience managing an audit cycle end-to-end and owning auditor relationships.
- Experience leading incident response investigations from triage through documentation.
- Ability to translate security risk into business-risk language.
- Active use of AI tools to enhance security workflows.
- Strong written and verbal communication skills.
Benefits
- Highly competitive, employer-heavy coverage, including $0 premium options.
- Strong 401(k) match.
- Equity options.
- Flexible time off.
Location
This is a hybrid role based in Raleigh, NC, with an in-office requirement of 3 days a week unless designated remote.
How to Apply
To apply for this position, please submit your application through the Pendo careers page.
Deadline
No specific deadline mentioned.