Logo for Glow

GRC Engineer

Role overview

Qualifications

  • Experience in GRC, security assurance, customer trust, compliance, security engineering, or a related field
  • Strong written and verbal communication skills
  • Experience managing or supporting frameworks such as SOC 2, ISO 27001, NIST CSF, NIST 800-53
  • Automation mindset with interest in reducing manual work

Responsibilities

  • Build the process to own and complete customer security questionnaires, assessments, and due-diligence requests
  • Join customer and prospect calls to explain security posture and risk-management practices
  • Manage compliance programs and audits from readiness through ongoing monitoring
  • Partner with various teams to address security and compliance requirements

Key facts

Hard skills

Other skills

  • Communication
  • Curiosity
  • Decisiveness

About the company

Glow logo

Glow

Cybersecurity

Glow is the Endpoint AI company. AI has changed how people work, creating a new generation of risks that traditional reactive tools can’t keep up with. We're rethinking endpoint security from the ground up: an AI-powered operating model built on prevention, not reaction, that fixes the foundation so organizations can adopt new software and AI on solid ground. Learn more at glow.io.

Company details

IndustryCybersecurity
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About Glow

Glow is on a mission to transform how enterprises proactively protect the modern endpoint with an agentic-first approach. Our platform gives security teams the visibility, context, and autonomous remediation they've never had before — across every endpoint, application, and AI tool in the environment. We move fast, we build things that matter, and we believe security should be a force multiplier for the business, not a bottleneck. Let's Glow.

About the role ...

At Glow - we’re looking for a pragmatic, technically curious GRC Engineer to help customers trust our company and products.

You’ll own customer-facing security assurance work, including security questionnaires, diligence requests, and customer calls. You’ll also manage and automate our compliance programs, improve the systems we use to collect evidence and monitor controls, and partner with Product and Engineering to design effective controls as the product evolves.

This role is ideal for someone who enjoys translating between customers, auditors, security teams, and product builders—and who believes compliance should enable the business rather than create unnecessary bureaucracy.

What you'll do ...

  • Build the process to own and complete customer security questionnaires, assessments, and due-diligence requests accurately and efficiently.

  • Join customer and prospect calls to explain our security posture, controls, architecture, and risk-management practices.

  • Build and maintain reusable trust materials, including standard responses, evidence packages, security documentation, and trust-center content.

  • Manage compliance programs and audits, such as SOC 2 and ISO 27001, from readiness through evidence collection, testing, remediation, and ongoing monitoring.

  • Automate evidence collection, control monitoring, questionnaire responses, and other repetitive GRC workflows.

  • Automate and own the process for maintaining policies, risk registers, control mappings, vendor reviews, and remediation plans.

  • Partner with Product, Engineering, IT, Legal, Sales, and Customer Success to address security and compliance requirements.

  • Help Product and Engineering teams translate regulatory, contractual, and customer requirements into practical product and operational controls.

  • Participate in product design and roadmap discussions, identifying control requirements early and recommending solutions that are secure, scalable, and usable.

  • Track emerging customer expectations and compliance requirements, then help prioritize improvements to our security program.

  • Define metrics that show the effectiveness, efficiency, and business impact of the GRC and customer-trust program.

What you'll bring ...

  • Experience in GRC, security assurance, customer trust, compliance, security engineering, or a related field.

  • A love of building from the ground up.

  • Hands-on experience completing customer security questionnaires and supporting customer security reviews.

  • Strong written and verbal communication skills, including the ability to explain technical and compliance topics clearly to both technical and non-technical audiences.

  • Experience managing or supporting frameworks such as SOC 2, ISO 27001, NIST CSF, NIST 800-53, or similar standards.

  • Working knowledge of common SaaS and cloud security controls, including identity and access management, encryption, logging, vulnerability management, secure development, incident response, business continuity, and vendor risk.

  • Ability to evaluate evidence critically rather than treating compliance as a checklist.

  • Strong project-management skills and comfort coordinating work across multiple teams.

  • An automation mindset, with an interest in using APIs, scripts, integrations, AI, or GRC platforms to reduce manual work.

  • Curiosity about how products are designed and a desire to help teams build controls into systems from the beginning.

  • Sound judgment when balancing security, customer commitments, usability, and business needs.

You might also bring ...

  • Experience at startups, B2B SaaS, cloud, infrastructure, fintech, healthcare, or other security-conscious technology company.

  • Familiarity with privacy and regulatory requirements such as GDPR, CCPA/CPRA, HIPAA, PCI DSS, or FedRAMP.

  • Experience with GRC automation, trust-center, or questionnaire-management platforms.

  • Ability to read technical architecture diagrams, audit logs, configurations, and code well enough to validate control design and evidence.

  • Experience designing product-level controls, such as audit logging, role-based access, data retention, tenant isolation, or administrative safeguards.

  • Relevant certifications such as CISSP, CISA, CISM, CRISC, CCSK, or ISO 27001 Lead Implementer/Auditor. Certifications are helpful but not required.

At Glow, we believe our greatest strength is our people. We're committed to building an inclusive workplace where every team member feels welcomed, respected, and empowered to do their best work. We know that diverse backgrounds, experiences, and perspectives make us stronger as a company and better partners to our customers.

Glow is proud to be an equal opportunity employer. We celebrate diversity and are committed to creating an environment free from discrimination and harassment. We make all employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, genetic information, or any other characteristic protected by applicable law.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Other jobs at Glow

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.