# Senior GRC Engineer

- Company: [Align](<https://jobstar.asia/company/align>)
- Location: Panama City, Panama - In-Office Hybrid
- Team: Legal and Compliance
- Posted: September 8, 2026

## Job description

#### **About the Role**

The Senior GRC Engineer owns audit evidence collection and technical control maintenance across A-LIGN's growing portfolio of compliance frameworks, including FedRAMP Moderate Equivalency, FedRAMP 20x, ISO 27001, ISO 42001, and SOC 2. This role bridges the GRC function and A-LIGN's technical teams, working hands-on in GCP, GitHub, and Microsoft 365 to collect evidence, verify controls, and keep A-LIGN continuously audit-ready. The Senior GRC Engineer works cross-functionally with every technical department in the company to reduce audit burden on engineering and IT while protecting the certifications that A-LIGN's clients and platforms depend on. The role also supports broader information security activities, including risk assessments, threat modeling, security reviews, and AI technical safeguards.

#### **Reports to**

Chief Information Security Officer

#### **Pay Classification**

Full-Time

#### **Responsibilities**

* Own end-to-end audit evidence collection, validation, and organization across A-LIGN's compliance frameworks, including FedRAMP (Moderate Equivalency and FedRAMP 20x), ISO 27001, ISO 42001, SOC 2, NIST 800-53, and NIST 800-171
* Maintain and continuously verify technical controls across A-LIGN's cloud and corporate environments, including Google Cloud Platform (GCP/GKE), GitHub, and Microsoft 365/Entra ID
* Serve as the primary liaison between the GRC function and technical departments (IT, Engineering, DevOps) to gather evidence, validate control implementation, and reduce audit burden on those teams
* Support FedRAMP continuous monitoring activities, including Key Security Indicator (KSI) evidence, vulnerability scan artifact collection, POA&M tracking, and assessor (3PAO) requests
* Build and maintain evidence automation, including integrations between GRC tooling and source systems (identity provider, cloud platforms, code repositories, ticketing, endpoint management) to reduce manual collection effort
* Support A-LIGN's ISO 42001 Artificial Intelligence Management System (AIMS), including AI risk register evidence, AI control monitoring, and nonconformity remediation tracking
* Prepare audit-ready evidence packages and coordinate directly with external assessors and certification bodies during assessment windows
* Monitor control health between audit cycles, identify control drift or failures, and drive remediation with control owners before findings occur
* Maintain compliance documentation, including control narratives, policies, and procedures
* Support supplier and vendor security reviews with framework-specific evidence requirements
* Track framework changes (FedRAMP 20x requirements, ISO standard revisions, SOC 2 criteria updates) and translate them into actionable control and evidence updates
* Conduct security risk assessments and contribute to A-LIGN's corporate risk management program and risk register
* Participate in threat modeling for A-SCEND features, internal systems, and AI use cases, and translate findings into control improvements
* Perform security reviews of new tools, vendors, and internal initiatives, including support for Vendor Review Board activities
* Implement and validate AI technical controls and safeguards, including data loss prevention, AI connector and agent governance, and acceptable use enforcement, in support of A-LIGN's AI Management System
* Report compliance posture, evidence status, and audit readiness metrics to the CISO and GRC leadership

#### **Minimum Qualifications**

EDUCATION

* Bachelor's degree in information systems, cybersecurity, business, or equivalent combination of education and experience

EXPERIENCE

* 5+ years of experience in information security, GRC, IT audit, or compliance engineering roles
* Hands-on experience with audit evidence collection and technical control validation for at least two of the following: FedRAMP, ISO 27001, ISO 42001, SOC 2, NIST 800-53, NIST 800-171
* DevSecOps or cloud engineering experience sufficient to independently locate and extract evidence from GCP, GitHub, and Microsoft 365/Entra ID environments
* Experience with GRC platforms and evidence automation (AuditBoard, Vanta, Drata, or similar)
* Experience supporting external audits and assessor interactions, including 3PAO assessments
* Working knowledge of vulnerability management, CI/CD pipelines, infrastructure-as-code, and identity and access management concepts
* Experience scripting or automating evidence collection (Python, PowerShell, or similar) preferred
* Familiarity with risk assessment methodologies, threat modeling (e.g., STRIDE), and security review processes preferred

CERTIFICATIONS

* CISA, CISSP, CCSK/CCSP, ISO Lead Auditor/Implementer, or relevant certifications preferred but not required

SKILLS

* Strong cross-functional collaboration and project management skills
* Ability to translate framework requirements into clear, actionable requests for technical teams
* Highly organized with the ability to manage evidence deadlines across multiple concurrent audit cycles
* Excellent written communication for control narratives, evidence descriptions, and assessor responses
* Self-directed with strong follow-through in a fast-paced, deadline-driven environment
* Proven experience utilizing AI tools to automate manual tasks, streamline workflows, and increase team efficiency
* Experience operating in PE-backed or high-growth environments preferred

#### **Benefits**

* Employer Paid Life & Health Insurance
* Competitive Bonus Structure
* Home Office Reimbursement
* Technology Allowance
* Certification Reimbursement
* BeneficiaT Discount Loyalty Program
* Personalized Career Coaching
* Generous Paid Time Off
* Paid Office Closure December 25-January 1
* Summer Hours

#### **About A-LIGN**

A-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor. To learn more, visit a-lign.com.

#### **Come Work for A-LIGN!**

Apply online today at A-LIGN.com and learn about life at A-LIGN by following us on **[LinkedIn](https://www.linkedin.com/company/a-lign/posts/?feedView=all).**

A-LIGN is an Equal Opportunity Employer.

## Apply

[Apply on Align](<https://job-boards.greenhouse.io/align/jobs/8764894002>)

Canonical job page: <https://jobstar.asia/job/senior-grc-engineer-align-panama-city-76701c90dbdedf66>
