Temporal
Senior Security Engineer, GRC
United States · Senior
Sponsorship not specified$53k-$800kDetected 34 days ago
PythonBashCybersecurityComplianceHIPAALeadershipOrganizational Skills
About the role
- Join our team as a Senior Security Engineer, GRC, where you'll be the primary owner of our customer-facing compliance program and a trusted partner throughout the enterprise sales cycle. In this role, you will manage the end-to-end lifecycle of security questionnaires, due diligence requests, and compliance reviews and automate parts of that process. You
- will ensure prospective and existing customers have full confidence in our security posture and you will work closely with Sales, Legal, and Product to represent our compliance program externally, while maintaining the internal rigor of our governance and risk frameworks.
Responsibilities
- Own the intake, prioritization, and completion of all inbound customer security questionnaires, RFPs, and due diligence requests including SIG, CAIQ, and custom enterprise questionnaires with a commitment to accuracy, thoroughness, and turnaround time.
- Build and maintain a comprehensive, evergreen response library for common security and compliance questions, reducing duplication of effort and ensuring consistency across all customer engagements.
- Design and automate the third-party risk assessment process, including vendor tiering logic, questionnaire workflows, and continuous monitoring for critical vendors.
- Perform ongoing risk assessments and maintain a risk register that reflects the current threat and compliance landscape, escalating material findings to leadership with clear remediation recommendations.
- Author, maintain, and operationalize security policies and procedures
- track employee acknowledgments and manage exceptions through to resolution.
- Collaborate cross-functionally with Engineering, Legal, and Product to gather documentation, validate control descriptions, and resolve compliance gaps surfaced through customer inquiries.
- Author, maintain, and operationalize security policies and procedures; track employee acknowledgments and manage exceptions through to resolution.
- Scripting and automation fluency (Python, Bash, or similar) and a track record of building tools, not just spreadsheets.
- Strong organizational skills and the ability to manage multiple concurrent questionnaire engagements, each with distinct deadlines and stakeholder requirements.
Requirements
- 8+ years of experience in GRC, information security compliance, or a closely related field.
- Deep, hands-on experience with at least two major compliance frameworks (SOC2, ISO 27001, HIPAA, PCI-DSS, or FedRAMP), including direct involvement in audits and assessments.
- Strong understanding of the security program's influence on company revenue and a partnership mindset with the Go To Market function.
- Bachelor's degree in Information Security, Computer Science, Business, or a related field (or equivalent experience).
Nice to have
- Security certifications: CISSP, CISM, CRISC, CISA, or CCSP.
- Experience with GRC platforms such as Vanta, Drata, Sprinto, or similar.
- Familiarity with NIST CSF or NIST 800-53 control frameworks.
- Experience drafting or reviewing Data Processing Agreements (DPAs), Business Associate Agreements (BAAs), or security-related contract language.
- Experience supporting FedRAMP authorization or state-level public sector compliance programs.
Compensation
- The estimated pay range for this role is $180,000 - $225,000, depending on qualifications and location.
- Build and maintain automations to continuously validate the organization's compliance posture across key frameworks including SOC2 Type II, ISO 27001, and HIPAA, coordinating evidence collection, managing external auditor relationships, and driving readiness for annual assessments.
Benefits
- Build dashboards and reporting pipelines that provide leadership with real-time visibility into compliance posture, open risks, and program health.
- This role is eligible to participate in Temporal's equity plan.
Company info
- Serve as the primary customer-facing representative for security and compliance, leading calls and meetings with enterprise customers, prospects, and their security or procurement teams.
- Ability to translate technical security controls into clear, business-appropriate language for non-technical audiences including customers, legal teams, and executives.
Apply directly at Temporal →Create a free account for alerts like thisView Temporal immigration profile
This listing is sourced directly from Temporal's careers page and normalized into a canonical job model.