Job details
Job description, work day and responsibilities
What you'll do: We're looking for a mid-level GRC Engineer to help us scale our compliance program through automation and run audits across SOC 2, ISO 27001, and SOX. This is a hands-on, technical role where you'll spend as much time writing code and integrating systems as you do reviewing controls. You'll serve as the bridge between Security, Engineering, and the business by transforming manual, evidence-heavy compliance work into automated, repeatable processes while helping leadership understand and prioritize risk.
This role is ideal for someone with GRC or security experience who wants to move beyond spreadsheets and checklists into building the tooling that makes a compliance program efficient, scalable, and audit-ready year-round.
In this role you will: Automation & Tooling Build and maintain automation for continuous control monitoring, evidence collection, and audit readiness through scripts, APIs, and GRC platform integrations
Integrate compliance workflows with cloud providers, identity systems, ticketing platforms, and CI/CD pipelines to automatically collect control data and evidence
Reduce manual compliance work by codifying control checks and pulling evidence directly from source systems
Develop dashboards and reporting that provide stakeholders with real-time visibility into control health and audit readiness
Audits & Frameworks Run and coordinate audits for SOC 2 (Type I and Type II), ISO 27001, and SOX, including scoping, evidence collection, control walkthroughs, and auditor coordination
Map controls across multiple compliance frameworks to reduce duplication and maintain a unified control library
Track audit findings and control gaps through remediation and closure with business and technical stakeholders
Maintain audit-ready documentation including policies, procedures, control narratives, and evidence repositories
Risk Management Identify, assess, and document organizational risks while maintaining the enterprise risk register
Support risk assessments, including likelihood and impact scoring, treatment planning, and remediation tracking
Partner with Engineering and IT to evaluate the control impact of new systems, vendors, and architectural changes
Contribute to the third-party risk management program
Cross-Functional Partnership Partner with control owners to ensure controls are operating effectively and generating appropriate evidence
Translate compliance requirements into practical, engineering-focused guidance
Support customer security questionnaires, trust requests, and due diligence activities
What you'll need:
NinjaTrader is hiring for this role on CareerPlace.
Apply on the company website through NinjaTrader.
Imported from employer careers page. Source ref: 0f604642f2e9.

