Skip to main content

Commercial GRC Engineer - Sr. Security Engineer I

Smartsheet
Hybrid - Bellevue, WA or Remote - USUpdated 1d ago
Base salary
$175k–$228k
Published base salary range
Location
Hybrid - Bellevue, WA or Remote - US
Remote eligibility
Employment
Full-time
Senior
Role family
Security
B2B SaaS
Apply on job-boards.greenhouse.io
Job actionsApply now
Job actionsApply now

About the job

About the Role

Smartsheet is seeking a Sr. Security Engineer I to bring an engineering mindset to our commercial GRC program. This role focuses on automating control monitoring, building evidence pipelines, and reducing audit-season scramble into a state of readiness. You will work hands-on with our GRC platform, cloud, and identity tooling, and partner with engineering teams to translate compliance requirements into technical control logic.

Responsibilities

  • Own control automation for SOC 2, ISO 27001/27017/27701, HIPAA, and related frameworks.
  • Express controls and mappings as version-controlled code.
  • Translate compliance requirements into technical control logic and integrations.
  • Shift compliance left by participating in architecture reviews and defining control requirements.
  • Design engineer-facing compliance experiences (self-service status, guardrails, feedback in CI/CD, Jira, Slack).
  • Evaluate control effectiveness and propose alternatives.
  • Support full audit cycles, coordinate evidence, and track remediation.
  • Build dashboards for real-time visibility into control health.
  • Eliminate duplicate evidence-gathering across frameworks.
  • Diagnose root causes of control failures and fix underlying gaps.
  • Partner with GRC Team Lead and SATellite engineering to extend the internal GRC platform.

Qualifications

  • 4+ years of experience in GRC engineering, security engineering, compliance automation, or IT audit support, with hands-on ownership of at least one full certification cycle.
  • Hands-on experience with GRC platforms (Vanta, Drata, Secureframe, or homegrown).
  • Cloud security fundamentals (AWS/GCP/Azure IAM, logging, encryption).
  • Working knowledge of SOC 2, ISO 27001, HIPAA control requirements.
  • Scripting or light development (Python, JavaScript, or similar).
  • Strong written communication.
  • Stakeholder-centric mindset.
  • Ability to trace control failures to root cause.
  • Legally eligible to work in the U.S. on an ongoing basis.

Compensation & Benefits

US Base Salary Pay Range: $175,000—$227,500 USD. Eligible for market competitive incentive opportunity.

Benefits include: employer subsidized medical/vision and dental coverage, 401k match (50% of contribution up to 6% of eligible pay), monthly stipend, Flexible Time Away Program, Sick Time Off, life insurance, short-term and long-term disability, 12 paid holidays, up to 24 weeks of parental leave, volunteer day, professional development (Udemy), company funded perks (counseling membership, retail discounts, personal Smartsheet account), teleworking options.

Skills & tags

What you can verify before applying

Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.