Replit

Replit

GRC Engineer

Foster City, CA · Full-time

Sponsorship not specifiedDetected 69 days ago
AWSGCPCybersecurityComplianceSalesSupply ChainHIPAALeadershipCommunicationCollaboration

About the role

  • We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and risk management ecosystem.
  • You will architect the systems and processes that automate trust, partnering deeply across the organization.
  • We need a pragmatic operator who understands that GRC exists to enable the business-balancing rigorous standards with the velocity of a high-growth startup.

Responsibilities

  • Technical Depth: Act as a technical subject matter expert for the GRC team. You will drive quality, technical depth, and operational efficiency in our security controls.
  • Engineering & Architecture: Partner with Architects and Engineering Leads to "bake in" compliance requirements early in the design phase.
  • Legal & Privacy: Work closely with Legal Counsel to interpret and implement requirements for Privacy (GDPR, CCPA) and emerging AI-specific regulations (e.g., EU AI Act).
  • Sales & GTM: Enable the Sales team by managing the Customer Trust Center and handling complex security questionnaires. You will serve as a subject matter expert in customer calls to build confidence with enterprise prospects.
  • Auditor Relationships: Own and cultivate the primary relationship with external auditors. You will serve as the bridge between auditors and internal teams, ensuring requests are reasonable, clear, and relevant to our tech stack.
  • Framework Evolution: Manage and evolve our compliance posture across SOC 2, ISO 27001, and prepare the organization for future certifications in regulated markets (e.g., FedRAMP, ITAR, PCI, HIPAA).

Requirements

  • Ability to speak the language of engineering, cloud (GCP/AWS), and security architecture.
  • You can anticipate how architectural decisions impact risk and compliance.
  • Deep experience with SOC 2, ISO 27001, PCI, HIPPA, and Privacy laws.
  • Strong ability to explain risk and tradeoffs to technical (Engineers), legal, and commercial (Sales/Execs) stakeholders.
  • Experience with GRC automation tools (e.g., Vanta, Drata) and a bias toward reducing manual toil.

Nice to have

  • Familiarity with FedRAMP, ITAR, or AI regulation is a strong plus.
  • Pragmatism: You distinguish between "checking a box" and reducing risk.
  • You focus on outcomes over optics.
  • Business Enablement: You understand that your role is to help Replit sell to the enterprise safely, supporting innovation through technical trust.
  • Solutions-Oriented: You are collaborative and low-ego.
  • You prefer fixing root causes and empowering teams through automation over manual bureaucracy.
  • Clarity: You can take a complex regulation and explain exactly what it means for a specific engineering team in plain English.
  • This is a full-time role that can be held from our Foster City, CA office.

Skills

  • 8+ years of experience in GRC or Information Security

Compensation

  • 💰 Competitive Salary & Equity

Benefits

  • Own the technical vision for Replit's GRC program, moving the team from manual workflows toward "Compliance-as-Code" and automated evidence collection.

Company info

  • Champion a culture of security and privacy across the company, educating teams on why controls exist rather than just enforcing them.
  • Cross-Functional Collaboration
  • Replit Blog https://blog.replit.com/
  • Amjad TED Talk https://youtu.be/kCudFI4tcpg?si=l4ViCejV_f2RZkDi
  • Operating Principles https://blog.replit.com/operating-principles
  • Reasons not to work at Replit https://blog.replit.com/reasons-not-to-join-replit

This listing is sourced directly from Replit's careers page and normalized into a canonical job model.