Life360

Life360

Senior GRC Engineer

Remote, USA · Senior

Sponsorship not specified$116k-$213kDetected 64 days ago
PythonGitCloud PlatformsLLMsAgentic AICybersecurityComplianceFinancial AnalysisAuditingProcurementLeadershipFinancial ReportingInternal Audit

About the role

  • The Information Security and Technology team is responsible for keeping Life360 safe - our systems, our employees, and the tens of millions of families who trust us with their location data.
  • How we meet it is what makes this team different.
  • Security controls that don't get used aren't controls.

Responsibilities

  • Own the governance framework for Life360's agentic systems.
  • Define the policies, control sets, and compliance posture that govern how agents are built and deployed at Life360 - and build ahead of the regulation.
  • Know where AI creates leverage, where it introduces risk, and where a human needs to stay in the loop.
  • Build the policy program as code.
  • Drive SOC 2 Type 2, ISO 27001, and SOX ITGC end-to-end as management owner - managing evidence, coordinating with external assessors, and closing gaps before auditors find them. Build the automation once
  • you'll partner closely with them on shared control libraries, evidence pipelines, and walkthroughs.
  • Build an operational risk function, not a register.
  • Build the data model, workflow layer, and closed loop that turns risk from a prioritization exercise into a lifecycle with owners and treatment decisions
  • Build the cross-functional relationships that make GRC work in practice.
  • Engineering, Legal, Privacy, Internal Audit and Procurement are all load-bearing parts of this program - own those partnerships and build the workflows that make compliance a shared practice, not a security team deliverable.

Requirements

  • Experience designing or operating agentic workflows is a strong signal.
  • You can evidence controls directly in cloud environments - identity, audit logs, configuration posture, secrets management - without relying on screenshots or system owners.
  • Bachelor's degree or equivalent.

Nice to have

  • Experience taking a company through SOC 2 Type 2 or ISO 27001 certification from scratch.
  • Privacy program crossover - GDPR, CCPA, data mapping, DPIAs.
  • You've worked on the implementation side of security - engineering, operations, or incident response.
  • You don't just audit other teams' work
  • you understand it because you've done it.
  • Ai-Native Daily use: You use AI tools for real, substantive work - analysis, drafting, automation, code, investigations, evidence gathering.
  • Judgment and ownership: AI-generated work gets the same scrutiny you'd give any human-produced artifact.
  • You're accountable for everything you ship.

Skills

  • SOC 2, ISO 27001, and SOX anchor this work.
  • The second job is harder and less charted.
  • Here's what that means in practice.
  • The compliance frameworks are catching up.

Compensation

  • The US-based salary range for this position is $115,500 to $213,000.

Benefits

  • Competitive pay and benefits
  • Medical, dental, vision, life and disability insurance plans (100% paid for employees)
  • Mental Wellness Program & Employee Assistance Program (EAP) for mental well-being
  • The compensation package includes a wide range of medical, dental, vision, financial, and other benefits, as well as equity.
  • Auditors leave knowing more about how Life360 actually works than they did when they walked in - and findings get closed before they become repeat findings.

Company info

  • That obligation is the starting point.
  • We are builders.
  • Compliance programs that create friction without reducing risk aren't programs.
  • We build things that work in production, earn adoption from engineering teams, and get better over time - and we use AI to do it at a scale a traditional team couldn't.
  • We're also at an inflection point.
  • Life360 is deploying agentic systems into how we build and operate, and the security and governance implications of that are still being worked out - by us, and by the industry.
  • The threat surface is expanding.
  • The people on this team aren't waiting for either.
  • About the Job
  • Governance, Risk, and Compliance (GRC) has been on a slow progression from audit binders and manual evidence collection toward policy as code, continuous control testing, and compliance infrastructure that generates its own proof.

This listing is sourced directly from Life360's careers page and normalized into a canonical job model.