Source description
About the role
Control Engineering & Validation
Design and implement security controls as testable, system-aligned mechanisms across cloud and application environments
Translate regulatory and framework requirements into measurable control logic and validation checks
Build and operate control validation workflows, including continuous testing and monitoring
Identify and resolve gaps between documented controls and actual system behavior
GRC Automation & Tooling
Develop and improve GRC tooling integrations and platform capabilities
Automate evidence collection from cloud platforms, security tools, and internal systems
Design scalable workflows for continuous control monitoring and audit readiness
Improve data quality, structure, and traceability across GRC systems
Evidence & Audit Engineering
Design reusable, structured evidence models aligned to control requirements
Build automated evidence pipelines that support audit readiness
Ensure evidence is generated at the source and remains consistent over time
Maintain audit trails that demonstrate control effectiveness
Risk & Control Integration
Integrate control assurance outputs into risk management systems
Maintain clear linkage between controls, risks, and remediation activities
Improve visibility into control health and organizational risk posture
Support structured remediation workflows with clear ownership and tracking
Governance Systems & Process Design
Design and refine governance workflows that align with engineering practices
Contribute to Policy as Code and structured governance approaches
Standardize how policies and controls are implemented across systems
Improve consistency and repeatability across GRC operations
Regulatory & Compliance Engineering
Translate regulatory requirements into system-aligned control implementations
Ensure compliance obligations are implemented as measurable and testable mechanisms
Partner with Legal and Security to align regulatory interpretation with technical execution
Third-Party & External Assurance
Support third-party security assessments using scalable and repeatable evaluation approaches
Align vendor risk processes with internal control frameworks
Contribute to client assurance through standardized, automation-ready evidence
More at Smarsh
Related open roles
Java Developer
IL · Hybrid
Sr. Technical Product Manager
Remote · United States
Sr. Full-Stack Developer - AI-forward
Remote · United States
Technical Support Engineer I
United States · Hybrid
Sr. Security Operations Analyst
Bangalore · Hybrid
Lead Security Operations Analyst
Bangalore · Hybrid
