Security Engineer, GRC
$180k - $258kCandid Health
About Candid HealthIn simple terms, healthcare in the U.S. has a massive, invisible problem behind the scenes: getting doctors paid by insurance companies is notoriously complicated. Insurance rules are constantly changing, and every bill (or "claim") requires mountains of paperwork. When mistakes happen, bills get rejected, patients end up with unexpected charges, and healthcare providers waste billions of dollars and countless hours on administrative bureaucracy instead of focusing on patient care. That is where Candid Health steps in. Founded by former Palantir leaders who experienced these pain points firsthand, we are building the modern financial backbone for American healthcare. Instead of relying on decades-old legacy software or attempting to patch broken systems with superficial tools, we've rebuilt the underlying infrastructure from the ground up.Our core product is an autonomous Revenue Cycle Management (RCM) platform. Powered by AI agents and a configurable rules engine, the platform unifies clinical, billing, and insurance data into a single smart system. It acts like an intelligent, automated back-office that handles complex medical claims from start to finish—submitting them accurately on the first pass, cutting down administrative costs, and dramatically increasing cash flow for healthcare providers.Today, we are trusted by over 200 fast-growing healthcare organizations—from digital health innovators to large enterprise medical groups—processing billions in claims annually. Backed by top investors like Sixth Street Growth, Oak HC/FT, 8VC, and Y Combinator, Candid Health recently raised a $120 million Series D to fuel the AI-driven transformation of healthcare payments and eliminate administrative friction for good.Role OverviewWe are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots in spreadsheets; you will treat compliance as an engineering and data problem.You will build automated evidence pipelines, implement compliance-as-code, and establish continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines. You will turn point-in-time audits into a continuous compliance telemetry system that keeps our platform secure, resilient, and audit-ready at all times.Key Responsibilities1) Compliance Automation & EngineeringDevelop automated scripts and API integrations to collect compliance evidence directly from system sources instead of collecting manual screenshots.Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically.Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time.Partnering with Legal on Medicare and Medicaid compliancePartnering closely with legal and finance teams on future due diligence and compliance projects2) Framework Mapping & Control ArchitectureConvert regulatory, security, and industry standards (SOC 2, HiTrust, PCI, HIPAA) into clear, testable technical controls.Map single technical controls across multiple overlapping frameworks to eliminate redundant work.Work alongside DevOps and Software Engineering teams to build compliance controls directly into CI/CD pipelines without slowing down delivery.3) Risk Management & AuditsLead technical audit readiness and external audit engagements using programmatic evidence pipelines.Automate vendor risk management workflows and API-driven vendor evaluations.Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs rather than static quarterly surveys.Required Qualifications3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRC.Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databases.Hands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as TerraformDeep familiarity with core frameworks such asUnderstanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes).Preferred QualificationsCertifications such as CISSP, CISA, CRISC, AWS Certified Security – Specialty, or CCSP.Experience with Policy-as-Code enginesBackground in software development, DevOps, or platform engineering.Experience with modern continuous compliance platforms (e.g., Vanta, Drata, Anecdotes).Our valuesWe spend at least as much time with our coworkers as we do with our closest friends + family - if we intend to do the most important + challenging work of our lives, it’s important that these folks energize us, support us, inspire us, and push us to do our best work. This is what you can expect of your teammates at Candid (in no particular order):We put our customers firstWe take care of each other and ourselvesWe anchor on outcomes and work relentlessly and creatively to achieve themWe collectively prioritize building a diverse and inclusive workspaceWe believe humility is our greatest strengthWe are candid, kind, and committedWe strive to be the most prepared person in the roomWe are truth seekersPay TransparencyThe estimated starting annual salary range for this position is $180,000 - 258,000 USD. The listed range is a guideline fromPave data, and the actual base salary may be modified based on factors including job-related skills, experience/qualifications, interview performance, market data, etc. Total compensation for this position may also include equity, sales incentives (for sales roles), and employee benefits. Given Candid Health’s funding and size, we heavily value the potential upside from equity in our compensation package. Further note that Candid Health has minimal hierarchy and titles, but has broad ranges of experience represented within roles.LocationSan Francisco; Denver; New York CityEmployment TypeFull timeLocation TypeHybridDepartmentEngineering
- ...New York, Washington D.C., London and Amsterdam.The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused... ...with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance...SuggestedWork experience placementWork at officeLocal areaShift work
$200k - $220k
...they rely on every day.We are looking for a hands-on Corporate Security Engineer to own and improve the technical controls that keep our... ...easier to use. You'll partner closely with IT, Infrastructure, GRC, and Detection & Response to improve the security foundations...SuggestedWork at officeLocal area$208k - $312k
...move from idea to production with speed, security, and exceptional developer experience.Now... ...About the Role:We are looking for a Security Engineer to join our Detection Response team. In... ...and collaborating with Engineering, GRC and the broader Security Division.Proactively...SuggestedWork at officeRemote workWork from homeWorldwideMonday to FridayFlexible hoursShift work$200k - $330k
...and design teams for Google Workspace. What you'll doLead Security for Our Platform. Take charge of application, cloud,... ...Collaborate with Cross-Functional Teams. Partner closely with engineering, product, and GRC to embed security throughout the software development...SuggestedFull timeFlexible hours- Brex is seeking a Senior GRC Engineer to bridge governance, risk, and compliance with security engineering. You will automate controls, build integrations between security tools and GRC platforms, and scale our trust program as Brex expands into new markets. Based in San...Suggested
- ...privacy by design and customer trust. You will implement frameworks like SOC 2, ISO 27001 and HIPAA, ensure GDPR/CCPA/CPRA compliance, design scalable audit processes and a robust GRC platform, and help lead regulatory strategy for AI safety. #J-18808-Ljbffr Perplexity
$134k - $205k
...best work of your career.We’re looking for a Senior Corporate Security Engineer to help secure the systems, identities, devices, and collaboration... ...guardrails.Partnering closely with IT, DRE, People, Legal, GRC, Procurement, and engineering teams to implement controls that...Remote workWork from homeFlexible hours$130k
About the roleWe are looking for a versatile Security Software Engineer to join our team and operate across product security, application security... ...)Pen testing or bug bounty experienceFamiliarity with GRC tools and frameworks#LI-Hybrid #LI-JL1A little about usAt Chime...Full timeWork at officeLocal areaRemote work- ...Principal GRC, Cyber Security Data Architect SAN FRANCISCO, CA Purpose Lead the delivery of a NIST CSF 2.0 cybersecurity gap and maturity assessment for a global enterprise program, covering assessment planning, stakeholder engagement, evidence review, maturity...
$275k - $300k
...at Postman.About the TeamThe Information Security organization at Postman operates across three... ...pillars: Governance Risk & Compliance (GRC), Product Security, and Security... ...looking for a Principal Offensive Security Engineer who is as much a strategist as they are a...Work at officeFlexible hours3 days per week$134k - $184.8k
Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential of AI... ...and Intelligence (TDI) organization is the engine that powers Okta's global workforce,... ...the organization.Partner with Security and GRC to communicate our risk posture and remediation...Local areaWorldwideFlexible hoursShift work$232k - $310k
...join us, and build real world value.THE WORK:As a Senior Staff Security Engineer, you will be one of Ripple's most senior technical security... ...infrastructure standards as Treasury integrates.Partner with GRC to ensure Treasury meets its compliance obligations across SOC...Full timeWork at officeLocal area$192k - $240k
...and support you need to grow your career.Engineering at BrexEngineering at Brex is about... ...intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy... ...Application Security, Corporate Engineering, GRC and IT and to improve security...Work at officeRemote workWork from home$165k - $242k
...March 2025. Learn more at What You’ll Do: The Enterprise Security team at CoreWeave is responsible for securing how our people... ...team to join. About the Role: As a Senior Security Engineer, Enterprise Security , you’ll design and ship the security controls...Permanent employmentFull timeTemporary workFor contractorsCasual workWork at officeRemote workFlexible hours$237.6k - $297k
We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the...Full time$146.3k - $257.7k
...scalers to join us on our journey to create a better future of work with AI. About the roleThis is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems...Full timeWork at officeLocal area$234.4k - $385k
...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are... ...engaging a robust security culture. About the RoleAs a Security Engineer, Application Security you will be responsible for identifying and...Work at officeRemote workRelocation packageFlexible hours$155k - $400k
...team is building its AI-native future. About The Role The Security Team is responsible for securing all things Sentry: our... ...autonomy to tackle hard security problems with creativity and an engineering mindset. We work at a company with a strong developer culture,...Hourly payFull time$146.3k - $257.7k
...scalers to join us on our journey to create a better future of work with AI. About the roleJoin WRITER's security team as a staff detection and response engineer and help protect the AI infrastructure that's transforming how the world works. You'll build sophisticated...Full timeWork at officeLocal area$160k - $185k
...year on administration instead of care. If you want to help change that, apply below. About the role We are looking for a Security Engineer to help build and strengthen security foundations from the ground up in a fast-moving startup environment, with a primary...Full timeWork at officeImmediate startRemote workFlexible hoursShift work$122.5k - $165k
...everyone is a stakeholder.What you’ll be responsible for:The Circle Security Team works to protect Circle; our customers, clients, and... ...:2+ years of experience in detection, response, or security engineering.Experience working security incidents, especially those involving...Work experience placementFlexible hoursShift workNight shift$180k - $258k
...today!Curious to learn more about our story? Check out this blog post written by our founders. The RoleWe're looking for a Senior Security Engineer who is ready to elevate the safety and security of our systems and networks. You will serve as our guardian, ensuring our...Flexible hours$237.6k - $297k
We are seeking a Senior Security Engineer with a specialty in Detection and Incident Response to join our Security Engineering team. This role sits at the intersection of security operations and software engineering — you won't just investigate incidents, you'll build the...Full time$165k - $200k
...single API, Merge Agent Handler, which empowers AI agents with secure access to thousands of third-party tools, and Merge Gateway,... ...product development, unblock sales, reduce customer churn, and save engineering resources—allowing them to focus on their core product.Merge...Full timeWork at officeHome office$155k - $400k
...team is building its AI-native future. About The Role The Security Team is responsible for securing all things Sentry: our... ...autonomy to tackle hard security problems with creativity and an engineering mindset. We work at a company with a strong developer culture,...Hourly payFull time$293k - $385k
...that artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products. We are... ...engaging a robust security culture.About the RoleAs a Security Engineer on Detection & Response, you’ll help protect OpenAI’s most...Work at officeLocal areaRemote workFlexible hours$153k - $376k
...together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us!As a Security Engineer you will identify and drive impactful projects to improve the security of Figma’s product, platform, and IT systems. We are...Minimum wageFull timeLocal areaRemote workFlexible hours- ...Modernisation, and Industry-Specific Software Solutions, DXC modernises, secures, and operates some of the world’s most complex technology... ...and New Zealand market, we are enhancing the Security Engineering Team who work within the Secured Infrastructure capacity to deliver...Full timeLocal area
- ...rely on our best-in-class platform.Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought... ...welcome; join us and let’s build what’s next - together!As a Security Engineer III embedded within the Security Operations team, you...Work at office
$347k
...that artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products. We are... ...culture.About the RoleOpenAI is seeking a Principal Security Engineer to join our Infrastructure Security (InfraSec) team. InfraSec...Work at officeLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer, GRC. Be the first to apply!
- security engineering manager San Francisco, CA
- application security engineer San Francisco, CA
- sr information security engineer San Francisco, CA
- sr security engineer San Francisco, CA
- entry level security engineer San Francisco, CA
- senior application security engineer San Francisco, CA
- staff security engineer San Francisco, CA
- security solutions engineer San Francisco, CA
- principal security engineer San Francisco, CA
- physical security engineer San Francisco, CA

