×
Register Here to Apply for Jobs or Post Jobs. X

GRC Engineer

Job in New York, New York County, New York, 10261, USA
Listing for: RiverPark Ventures
Full Time position
Listed on 2026-07-30
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 130000 - 170000 USD Yearly USD 130000.00 170000.00 YEAR
Job Description & How to Apply Below
Location: New York

Our Mission

ButterflyMX is on a mission to empower people to open and manage doors & gates from a smartphone. Our products are installed in more than 20,000+ multifamily, commercial, gated communities, and student-housing properties worldwide, including properties developed, owned, and managed by the most trusted names in real estate. Our features are designed for developers, owners, property managers, and tenants and our products lower operating costs and improve tenant satisfaction.

Our

Solution

Developers and owners no longer need to run building wiring or install in-unit hardware. Property managers can grant building access, revoke permissions, and review entry logs from an online dashboard. Residents can open doors from their smartphones, issue visitor access, and see who is trying to enter the building.

Our Culture & Values

Fantastic people are the key to our success. As a distributed, primarily remote workforce, we’re looking for more intelligent, passionate, collaborative, ai-forward, and down-to-earth individuals to join our growing team. We’re driven by a shared commitment to excellence and innovation, grounded in our core values:
We delight our customers, We take ownership, We are a community of collaborators, We speak up, We think big and do small, and We are tenacious.

Role Overview

ButterflyMX is seeking a GRC Engineer who is equal parts practitioner and builder. You will own the governance, risk, and compliance program. But more importantly, you will re-engineer how that program operates: replacing manual, point-in-time processes with AI-assisted, automated, and agentic workflows wherever possible. From continuous controls monitoring to automated vendor risk intake to AI-accelerated policy drafting, you will design a GRC function built for scale.

This is a generalist role that spans the full GRC surface: compliance operations, risk management, audit management, trust and assurance, vendor/supply chain risk, and operational privacy support. You will own the day-to-day operations of our compliance posture: managing audit readiness, maintaining our risk register, driving policy development, coordinating vendor risk assessments, and building sustainable processes through engineering automations.

You are equally comfortable automating a controls evidence request (not just handing it to the control owner); conducting a supply chain risk analysis (software, firmware, hardware); and building automations and workflows to reduce compliance and documentation burdens. It is an individual contributor position reporting directly to the CISO to build and sustain our governance, risk, and compliance program.

Responsibilities
  • Own and continuously mature the company risk register; design a risk management workflow that uses AI tooling to surface, score, and route emerging risks with minimal manual intervention, ensuring the register reflects real-time posture, not a quarterly snapshot.
  • Lead external audit management (SOC 2 Type II); automate evidence collection pipelines in Vanta so that audit cycles are driven by continuous monitoring rather than evidence sprints, and begin scoping a readiness path for ISO 42001 (AI management systems).
  • Engineer the Trust and Assurance program for scale: build automated intake and triage workflows for security questionnaire requests, deploy AI-assisted response generation against a curated knowledge base, and expand the trust portal so that partner due diligence is largely self-service.
  • Build a vendor and supply chain risk program that goes beyond static spreadsheets. Design automated vendor intake, tiered risk scoring, and continuous monitoring triggers (news alerts, rating service integrations, release notes, expiration tracking) that surface risk without requiring manual sweeps.
  • Redesign and maintain security and privacy policies; use AI to draft, version, and track policy updates, and build a lightweight workflow for owner review, approval, and attestation that doesn’t require a ticketing system to chase people down.
  • Own common controls monitoring in Vanta. Configure and tune integrations, checks, and alerting so that control failures surface automatically to the…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary