×
Register Here to Apply for Jobs or Post Jobs. X

Senior GRC Engineer

Job in Dallas, Dallas County, Texas, 75215, USA
Listing for: Jobtailor
Full Time position
Listed on 2026-07-20
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, Data Security
Salary/Wage Range or Industry Benchmark: 120000 - 180000 USD Yearly USD 120000.00 180000.00 YEAR
Job Description & How to Apply Below

Responsibilities

  • Write scripts (Python, SQL, APIs) to pull evidence directly from source systems (AWS, Azure, IAM platforms, endpoint agents, CI/CD pipelines), eliminating manual evidence collection
  • Build and maintain continuous control monitoring workflows integrated into engineering pipelines, not just GRC platforms
  • Design compliance-as-code and policy-as-code approaches; own the technical architecture of how controls are tested automatically
  • Operate and extend the GRC platform (Service Now GRC, Drata, One Trust, or equivalent) as an engineer, not just a user, including building integrations and automating evidence routing
  • Build and maintain Lantern’s AI risk register and AI systems inventory, including pre‑deployment risk assessments for new AI use cases across our benefits platform in partnership with Engineering and Product
  • Implement AI governance controls aligned to the NIST AI RMF, covering model risk, bias, transparency, and accountability, with a bias toward automated monitoring over manual review
  • Monitor HHS AI policy, EU AI Act, and state‑level regulation; translate emerging requirements into actionable, automatable controls
  • Govern AI systems used within the GRC function itself, including any LLM‑powered evidence analysis or control monitoring tools
  • Own the HIPAA Privacy and Security compliance program: risk assessments, remediation tracking, workforce training coordination, and ongoing monitoring
  • Support HITRUST CSF certification and SOC 2 Type II audit cycles as a technical contributor, building automated evidence pipelines rather than collecting evidence manually
  • Map the control environment against NIST CSF; identify gaps and build a prioritized, automatable remediation roadmap
  • Build and maintain the enterprise risk register with automated KRI tracking and outcome‑based reporting for leadership
  • Run the third‑party risk management (TPRM) program with a continuous monitoring posture: automated vendor monitoring rather than point‑in‑time assessments
  • Conduct vendor risk assessments with emphasis on cloud vendors handling PHI and AI/ML vendors embedding models into products we purchase
Requirements
  • 5+ years in GRC, information security, or compliance engineering, with at least 3 years in healthcare or health‑tech
  • Demonstrated ability to write code that extracts evidence directly from systems (Azure, IAM, endpoints, APIs), not just configure workflow tools
  • Has built something using an LLM or AI framework: a working tool, even a prototype
  • Thinks like an engineer first: sees a manual compliance process and asks how to eliminate it, not how to document it better
#J-18808-Ljbffr
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary