Sr. Security Assurance Engineer
$141.23k - $180.14k6sense
Our Mission:
6sense's mission is to multiply what matters: growth, retention, and efficiency. We envision a future where companies, teams and people reach their full potential.
Our People:
People are the heart and soul of 6sense. We serve with passion and purpose. We live by our Being 6sense values of Win as One Team, Stay Curious, Do The Right Thing, Own the Outcome, and Create Belonging. Every 6sensor plays a part in defining the future of our industry-leading technology. 6sense is a place where difference-makers roll up their sleeves, take risks, act with integrity, and measure success by the value we create for our customers. We want 6sense to be the best chapter of your career.
Job Title:
Senior Security Engineer, GRC (Governance, Risk and Compliance)
Organizational Reporting:
Director, Security Assurance
Function/Dept:
Business Technology / Security
Purpose of the Job
As members of 6sense's Security department, the Governance, Risk and Compliance (GRC) team aligns Security with business objectives while managing risks and meeting industry standards, regulations and contractual obligations. GRC enforces governance, implements risk management strategies, and ensures compliance through operating as the second line of defense.
This role is the engineering capability behind that mission. Rather than testing controls after the fact, this engineer builds the systems that test them continuously. The expectation is that controls are monitored as code, technical evidence is produced automatically from AWS and other source systems, control owners can self-serve their own evidence without a GRC ticket, and AI is used as core infrastructure across GRC workflows rather than as an experiment. Audit readiness should be a byproduct of the running system, not a project.
Job Description
Responsibilities & Accountabilities
- All responsibilities of GRC Security Engineer III, and;
- Design, build, and own automated security control monitoring; write production-quality code (e.g., Python) under version control, peer review, and CI/CD, and treat control logic as a maintained software asset rather than a documented procedure
- Convert the control library from periodic, sample-based manual testing to continuous control monitoring (CCM): define the technical signal for each control, its test frequency, pass/fail thresholds, and alerting and escalation path
- Engineer self-service technical evidence collection in AWS using native services (Config, Security Hub, CloudTrail, Organizations/SCPs, IAM Access Analyzer, Systems Manager, EventBridge, Lambda, Athena/S3, CloudWatch), so control owners and auditors retrieve current evidence on demand without GRC acting as an intermediary
- Eliminate manual, screenshot-based, and ticket-driven evidence collection; retire manual test procedures as automated equivalents come online and document the transition so auditors can rely on it
- Redesign GRC processes to be AI-native; apply LLMs and agentic workflows to evidence review, control mapping, gap analysis, security questionnaire and customer due diligence response, policy and procedure drafting, and risk assessment triage, with explicit human-in-the-loop review, guardrails, and output validation
- Maintain a single normalized control library crosswalked across frameworks (ISO 27001, SOC 2, PCI DSS, SOX, GDPR, NIST) so that one automated test satisfies multiple obligations
- Build the control-failure pipeline end to end: automated detection, enrichment, ticket creation, owner routing, SLA tracking, remediation verification, and closure, including exception and risk acceptance handling where remediation is not viable
- Partner with Platform Engineering, DevOps, and IT to shift controls left into preventive guardrails: service control policies, AWS Config conformance packs, policy-as-code in CI/CD, and secure-by-default infrastructure patterns
- Instrument control health reporting: automation coverage, evidence freshness, control failure rates, mean time to remediate, and audit-readiness posture, surfaced in dashboards consumable by Security leadership and control owners
- Lead internal and external audit engagements with automated evidence as the primary artifact; defend automated test design, sampling logic, and the completeness and accuracy of system-generated evidence to auditors and assessors
- Oversee and execute complex control tests and third-party and operational security risk assessments, using tooling and AI-assisted analysis to increase coverage and reduce cycle time, and communicate results across multiple audiences with varying levels of sensitivity
- Develop issue and risk treatment plans with owners and validate remediation through automated re-testing rather than manual confirmation
- Set the technical bar for the team: peer review other GRC Engineers' automation, queries, and test logic, and provide feedback, guidance, and enablement so automation ownership is distributed rather than siloed
- Provide GRC technology administration, including integrations, API-based data flows, and user training and enablement
- Mature security governance, training and awareness programs, using automation to target and measure them
- Improve GRC handbook pages, procedures, playbooks, and technical design documentation, and maintain security program controlled documents
- Execute on quarterly individual Key Results that support team Objectives (OKRs)
Key Outcomes (First 12 Months)
- A defined and measurable share of the control library operating under continuous monitoring, with a credible quarter-over-quarter plan to expand coverage
- Technical evidence for in-scope AWS controls generated automatically and retrievable without GRC involvement
- A documented reduction in audit preparation effort and evidence request turnaround time versus the prior audit cycle
- At least one materially redesigned, AI-native GRC process replacing a previously manual workflow, with measured quality and throughput results
- Control failures detected by the monitoring system rather than discovered during audit or assessment
Performance Measurement
- Increases the percentage of controls under automated, continuous monitoring and reduces the percentage tested manually
- Increases the percentage of technical evidence collected without human intervention and maintains evidence freshness against defined SLAs
- Reduces mean time to detect and mean time to remediate control failures
- Reduces audit and assessment preparation hours and evidence request turnaround time
- Ships maintainable, reviewed, version-controlled code and infrastructure with low operational failure and false-positive rates
- Demonstrates measurable adoption of self-service evidence by control owners outside of GRC
- Applies AI to GRC workflows with measured accuracy, appropriate review controls, and documented decisions on where AI is and is not relied upon
- Maintains up-to-date knowledge of 6sense's product, environment, systems and architecture
- Drives remediation of security risks and threats
- Adheres to strict deadlines and SLAs
- Participates in creation of, and executes on, milestones associated with major security projects
- Develops and maintains up-to-date handbook pages, runbooks, workflows, dashboards, and technical design documentation for everything they own
- Provides project status updates on a weekly basis
- Actively prepares for weekly 1:1s with Manager and monthly skip levels
- Administers GRC technology and its integrations
Person Specification
Educational and Experience Requirements
- 5+ years of experience being part of a GRC or similar team
- 2+ years of hands-on experience building and maintaining automation, including proficiency in at least one scripting or programming language (Python preferred) and comfort working in Git, code review, and CI/CD
- Demonstrated hands-on AWS experience relevant to control monitoring and evidence generation: Config, Security Hub, CloudTrail, IAM, Organizations and SCPs, Lambda, EventBridge, S3/Athena, CloudWatch
- Experience retrieving, normalizing, and reconciling data across systems via APIs and SQL, and reasoning about the completeness and accuracy of that data
- Practical experience applying LLMs or AI agents to real workflows, including prompt and workflow design, output evaluation, and appropriate human review and guardrails
- Experience with security tools and cloud environments (e.g., GRC and compliance automation platforms, vulnerability scanners, SIEM, SOAR, AWS)
- Experience with industry frameworks, regulations and standards, such as ISO 27001, SOC 2, GDPR, PCI, SOX, NIST, etc.
- Ability to determine what constitutes sufficient audit evidence and to defend automated control testing and system-generated evidence to auditors
Preferred Qualifications
- Experience with infrastructure as code (Terraform, CloudFormation) and policy-as-code (OPA/Rego, AWS Config custom rules, cfn-guard, or similar)
- Experience implementing or operating continuous control monitoring at scale in a SaaS or multi-account cloud environment
- Experience integrating GRC or compliance automation platforms via API rather than through the UI
- Experience building internal self-service tooling used by engineers or control owners
- Big 4 (KPMG, Deloitte, PwC, EY) or similar experience
- Bachelor's degree in a related field
- Relevant industry certifications, such as CISSP, CISM, GIAC, AWS Certified Security – Specialty, or CCSK/CCSP, are highly desirable
Competencies and Behaviors
- Automation-first by default; treats a recurring manual GRC task as an engineering problem, not a staffing problem
- Thinks like a builder and operates like an auditor: writes code that is maintainable and monitored, and control logic that is defensible and evidenced
- Uses AI aggressively but skeptically; leans on it for leverage while validating output and being explicit about where human judgment is required
- Designs for self-service so that GRC is not a bottleneck between control owners and their own evidence
- Evangelizes security best practices
- Works independently to maintain and improve overall company security posture
- Collaborates with cross-functional teams, particularly engineering and platform teams, and earns credibility with them technically
- Translates control intent and technical requirements into actionable, timebound, testable requests
- Drives projects and tasks to completion by following up on questions, deadlines, and requests for input
- Maintains accuracy of information
- Proactive prioritization and escalation to management
- Strong communication skills, including verbal, written, and presentation skills, and the ability to explain automated control design to both engineers and auditors
Base Salary Range: $141,230.25 - $180,137.70. The base salary range represents the anticipated low and high end of the base salary range for this position. Actual salaries may vary and may be above or below the range based on various factors, including but not limited to work location and experience. The base salary is one component of 6sense’s total compensation package for this position. Other compensation may include a bonus program or commission plan, and stock options if approved by 6sense’s board. In addition, 6sense provides a variety of benefits, including generous health insurance coverage, life, and disability insurance, a 401K employer matching program, paid holidays, self-care days, and paid time off (PTO). #Li-remote
Notice of Collection and Use of Personal Information for California Residents: California Recruitment Privacy Notice and Policy
Our Benefits:
Full-time employees can take advantage of health coverage, paid parental leave, generous paid time-off and holidays, quarterly self-care days off, and stock options. We’ll make sure you have the equipment and support you need to work and connect with your teams, at home or in one of our offices.
We have a growth mindset culture that is represented in all that we do, from onboarding through to numerous learning and development initiatives including access to our LinkedIn Learning platform. Employee well-being is also top of mind for us. We host quarterly wellness education sessions to encourage self care and personal growth. From wellness days to ERG-hosted events, we celebrate and energize all 6sense employees and their backgrounds.
Equal Opportunity Employer:
6sense is an Equal Employment Opportunity and Affirmative Action Employers. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to View email address on aiapply.co.
We are aware of recruiting impersonation attempts that are not affiliated with 6sense in any way. All email communications from 6sense will originate from the @6sense.com domain. We will not initially contact you via text message and will never request payments. If you are uncertain whether you have been contacted by an official 6sense employee, reach out to View email address on aiapply.co
- ...Responsibilities Design, build, and own production-quality automated security control monitoring under version control, peer review, and CI/... ..., frequencies, thresholds, alerting, and escalation paths. Engineer self-service AWS evidence collection using native services so...SeniorFull timeWork at officeRemote workWork from home
- ...Development• Project Management• Quality Assurance• Business/Systems Analysis•... ...Business Continuity & Disaster Recovery• Security & PrivacySpecialties• Contract Staffing... ...DescriptionSr. Network Security/Firewall Engineer Job DetailsThe Security Engineer will be...SeniorPermanent employmentContract workFor contractorsRemote work
$102.4k - $199.7k
...National Laboratories is the nation's premier science and engineering lab for national security and technology innovation, with teams of specialists... ...What Your Job Will Be Like Sandia's Nuclear Enterprise Assurance (NEA) Team seeks a multidisciplinary R&D Systems Security...SeniorPart timeRemote workWork from homeWorldwideRelocation packageFlexible hours$130k - $180k
...possible, with the ultimate goal of enabling human life on Mars.SR. CLASSIFIED CYBER ASSURANCE ANALYST SpaceX is seeking a senior classified cyber... ...Provide expert knowledge of Nessus, Splunk and Security Center tools Provide expert knowledge of Service Now (SNOW...SeniorPermanent employmentTemporary workRemote workWeekend work$86.8k - $165.2k
...and transferable U.S. government issued security clearance is required prior to start... ...challenging.The Product Cybersecurity Engineering DoD East Florida team is hiring a Senior... ...requirements, and National Information Assurance Partnership (NIAP)Experience working with...SeniorTemporary workWork experience placementWork at officeRemote workRelocation packageFlexible hours$86.8k - $165.2k
...and transferable U.S. government issued security clearance is required prior to start date... ...Senior Systems Security (Cybersecurity) Engineer to function as a key contributor for the... ...like Anti-Tamper (AT), Software Assurance, Hardware Assurance, Cryptography, NSA Type...SeniorTemporary workWork experience placementWork at officeRemote workRelocation packageFlexible hours- SR. CYBER ASSURANCE ANALYST, LAUNCH Cyber Assurance is the practice of providing confidence that systems, products and processes meet security, regulatory and compliance obligations. It bridges governance... ..., working closely with engineers to understand systems, how controls...SeniorPermanent employmentRemote workFlexible hoursWeekend work
$130k - $180k
...with the ultimate goal of enabling human life on Mars. SR. CLASSIFIED CYBER ASSURANCE ANALYST SpaceX is seeking a senior classified cyber assurance... ...Provide expert knowledge of Nessus, Splunk and Security Center tools Provide expert knowledge of Service Now (SNOW...SeniorPermanent employmentTemporary workRemote workWeekend work- Position: Senior Security Engineer - PKI & Detection, Aircraft SecurityLocation: Fort Worth Texas (Hybrid - onsite Tuesday through Thursday... ...Practice Statements (CP/CPS), trusted roles, Levels of Assurance, and NIST SP 800-63.Strong Microsoft Sentinel experience, including...SeniorFull timeRemote workMonday to Friday
$293k - $385k
...intelligence benefits all of humanity.The Security organization protects OpenAI’s... ...products, and emerging platforms.The Host Assurance team exists to make bare metal a dependable... ...About the RoleOpenAI is seeking a Security Engineer, Host Assurance to help build the trust...Work at officeLocal areaRelocation packageFlexible hours- ...Responsibilities:Provide operational support of the Reyes Holdings global IP LAN/WAN IP infrastructures specifically for the network security systems (firewalls, Zscaler), supporting 170+ global locations and 3 major contact centersOversight of Security policies, best...SeniorRemote work
$160k - $205k
...work with some of the best information security professionals in the world in challenging... ...opportunity to shine and grow.The Cyber Security Assurance Division is looking for a Senior Full... ...and experience by mentoring junior engineers, and assist with monitoring and response...SeniorFull timeWork at officeRemote workShift workDay shift$142.2k - $213.4k
...impossible. Our employees are not only part of history, they're making history.We are looking for you to join us as a Sr. Principal Mission Assurance Engineer based in Sunnyvale, CA in the heart of Silicon Valley! This position is fully on-site (no remote or hybrid...SeniorFull timeContract workRemote workRelocation packageShift work- ...the technologies to make this possible, with the ultimate goal of enabling human life on Mars.SR. NETWORK SECURITY ENGINEERSpaceX is looking for a Sr. Network Security Engineer with deep expertise in network security technologies and a strong emphasis on remote access...SeniorPermanent employmentRemote workFlexible hoursWeekend work
$170k - $265k
...developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.SR. SECURITY ENGINEERSpaceX is looking for a Sr. Security Engineer to join the Security Operations Center to help protect and drive the SpaceX mission. Information...SeniorPermanent employmentTemporary workRemote workWeekend work$100k - $150k
...NYSE: TIC) is a leading provider of compliance, technology, and engineering consulting solutions. Professional Systems Engineering (PSE)... ...across a broad spectrum of disciplines, including electronic security, audiovisual, IT/tele/data communications, and fire systems. PSE...SeniorFull timeFor contractorsWork at officeLocal areaRemote workFlexible hoursNight shift- ...Overview The primary responsibility of the Senior Application Security Engineer (AI-First Development) is to design, orchestrate, and... ...authorized, and safe. Exploit Validation and Findings Assurance Apply human oversight at governance checkpoints...SeniorRemote work
- ...Graduation from an accredited four-year college or university with major coursework in cybersecurity, information technology security, computer engineering, computer information systems, computer science, management information systems or a related field. Full-time...SeniorFull timeWork experience placementRemote work
$155k - $187k
...Sr. Security Engineer Remote (US) About FastSpring: FastSpring is how AI, SaaS, gaming, software, and digital product companies sell online in more places around the world. We handle all payment needs from checkout to taxes so you can go farther faster. Founded...SeniorLocal areaRemote work$132.4k - $251.6k
...Status Requirements:Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship... ...the future of aerospace and defense.The Product Cybersecurity Engineering team is hiring a Senior Principal Embedded Systems Security...SeniorTemporary workWork experience placementWork at officeRemote workRelocation packageFlexible hours$172k - $286.6k
...today, we want to hear from you.Sr. Director, Cybersecurity... ...Sr. Director of Cybersecurity Engineering is responsible for leading teams... ...improve enterprise security controls and platforms across... ...science, information security/assurance, engineering, or a related field...SeniorFull time- ...Senior Security Engineer France - Remote At DataDome, security is a core part of how we build and scale. Our security team already... ...AI-enabled workflows. At the same time, our regulatory and assurance requirements are becoming more demanding, including ISO 2700...SeniorWork at officeRemote workFlexible hoursShift work
$155.58k - $320.32k
...more about our AI interview philosophy and how we use AI in our recruiting process here.Pinterest’s Security team is seeking an experienced Security Software Engineer to help keep our 619 million monthly active users safe from real-world threats. You will build tooling...SeniorWork at officeLocal areaRemote workRelocationRelocation package- ...cybersecurity professionals with advanced expertise, capable of driving enterprise security initiatives and influencing organizational resilience.As a Senior Security Software Engineer, you will design, lead, and deliver secure, scalable integration services that connect...SeniorFull timeLocal areaWork from homeRelocation package
$180k - $230k
...Sr. Security Engineer At OpenSpace, we're redefining how the world's most complex projects are built. Our AI-powered Visual Intelligence Platform uses computer vision and spatial AI to give construction teams a real-time view of what's happening on-site, helping them...SeniorLocal areaRemote workHome officeFlexible hours$135k - $202.6k
...to missions. In rapidly changing global security environments, Northrop Grumman brings informed... ...seeking Senior Principal Cyber Systems Engineers to support information systems and... ..., and best practices to support ongoing assurance and compliance efforts.Partner with cross...SeniorFull timeRemote workRelocation packageFlexible hoursShift work$132.4k - $251.6k
...and transferable U.S. government issued security clearance is required prior to start... ...than 100 years of experience and renowned engineering expertise to meet the needs of today’s... ...solutions leveraging Cybersecurity, Software Assurance, and Supply Chain Risk Management to...SeniorTemporary workWork experience placementWork at officeRemote workRelocation packageFlexible hours- ...We're looking for a Sr Security Engineer to engineer and secure our multi-cloud environment — the same cloud infrastructure that powers our product. This is a cloud-native, AI-obsessed company, and our cloud isn't just internal plumbing: it's the platform our product...SeniorFull timeShift work
- ...Senior Security Engineer Remote About Brave Brave is on a mission to protect the human right to privacy online. We’ve built a free web browser that blocks creepy third-party ads and trackers by default, a private search engine with a truly independent index, a...SeniorFull timeRemote work
$86.8k - $165.2k
...and transferable U.S. government issued security clearance is required prior to start... ...than 100 years of experience and renowned engineering expertise to meet the needs of today’s... ...SW, Systems), Cybersecurity, Software Assurance A minimum of 3 years of progressive...SeniorFull timeTemporary workWork experience placementWork at officeRemote workRelocation packageFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. Security Assurance Engineer. Be the first to apply!
- security engineering manager Remote
- application security engineer Remote
- sr information security engineer Remote
- sr security engineer Remote
- senior application security engineer Remote
- staff security engineer Remote
- principal security engineer Remote
- physical security engineer Remote
- security engineer Remote
- aws cloud security engineer Remote


