Haystack
← Back to Jobs
Engineering

GRC Engineer

Henderson Scott LimitedNew York, NY🇺🇸United StatesPosted 5 Aug 2026

Why This Role Stands Out

This GRC Engineer role offers a fantastic opportunity to contribute to a major digital transformation within a world-renowned institution, directly impacting their security posture. You'll thrive here if you possess a blend of technical expertise and an understanding of governance, risk, and compliance, enabling you to bridge the gap between security frameworks and technical operations in a meaningful way. This position offers excellent career growth as you develop automated workflows and policy-as-code solutions, with a flexible on-site requirement of just one day per week in NYC.

Quick Overview

Work Type
On Site
Level
Mid Senior

Job Description



My client is a world reknown instituion. They are in the process of a massive digital transformation and helping make their staff more agile. While looking at their team/department- they realized they needed to upskill certain areas and hire two people for this key role.


This role is on-site 1 day per week (Friday). You must be legally able to work in the US without sponsorship and commutable to NYC.


They are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment.


The role is ideal for someone who understands both the language of security frameworks and the realities of modern technical infrastructure.


The Cybersecurity GRC Engineer will play a key role in advancing continuous compliance, improving audit readiness, supporting risk assessments, and developing repeatable methods for validating security controls. This position requires technical curiosity, sound judgment, strong documentation skills, and the ability to translate regulatory and framework requirements into actionable engineering outcomes.


Must Halves:



  • Translate cybersecurity, privacy, regulatory, and framework requirements into technical control objectives, validation procedures, and measurable security outcomes.

  • Design, implement, and maintain automated workflows for security control testing, evidence collection, compliance monitoring, and audit readiness.

  • Develop and support policy-as-code, configuration checks, compliance dashboards, and repeatable validation methods to reduce manual assessment activities.

  • Perform technical risk assessments and gap analyses for new and existing technologies, systems, applications, cloud services, vendors, and business processes.

  • Partner with cybersecurity engineering, infrastructure, application, cloud, and networking teams to evaluate whether technical controls are implemented effectively and operating as intended.

  • Collaborate with IT and engineering teams to embed secure-by-design and data-by-default protection principles into applications, services, and infrastructure, while staying current on modern attack techniques and translating that knowledge into code and tooling.

  • Review operating systems, applications, cloud resources, network devices, security platforms, and third-party technologies against organizational policies, standards, and secure configuration baselines.



Skills

Agile

Similar jobs