Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Governance, Risk & Compliance (GRC) Engineer image - Rise Careers
Job details

Governance, Risk & Compliance (GRC) Engineer

Who are we?


Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or headlines.  Relentless innovation has fueled our journey to consistent leadership recognition from analysts like Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008.


Summary


Smarsh is a global leader in digital communications capture, archiving, and oversight. Smarsh is committed to embedding security as a business enabler through governance process excellence and scalable control frameworks. As a GRC Engineer, you will play a critical role in advancing our governance, risk, and compliance programs. You’ll be responsible for defining, implementing, and optimizing security controls and risk processes that support operational alignment across the organization. This role requires an understanding of how governance can scale through automation, control validation workflows, and "Policy as Code" principles. You’ll collaborate closely with engineering, security, legal, and business teams to ensure our GRC practices mature in step with our growth.


How will you contribute?
  • ISMS Governance & Controls Assurance: Lead the ongoing maintenance and enhancement of Smarsh’s ISO 27001-aligned ISMS, ensuring policies, controls, and governance processes are clear, actionable, and aligned with business operations. Author and maintain security control narratives, working closely with technical teams to ensure controls are designed with enforceability and operational alignment in mind. Oversee the Control Assurance Program, ensuring effective evidence collection, control testing, and continuous monitoring practices. Coordinate internal and external audit readiness (SOC 2, ISO 27001, FedRAMP, customer audits) through structured governance workflows.
  • Risk Management & Governance: Manage the risk assessment lifecycle, ensuring comprehensive engagement across business, technical, and third-party risk domains. Facilitate risk acceptance workflows, maintaining governance rigor through well-defined documentation and approval processes. Ensure effective governance of risk treatment plans, enabling clear tracking and status reporting.
  • Regulatory, Contractual & Client Assurance: Translate emerging regulations (e.g., DORA, SEC Cyber Rules, UK AI Act) into internal governance requirements and operational processes. Manage customer security assessments and DDQs, utilizing standardized assurance artefacts to deliver efficient, high-quality responses. Ensure external assurance artefacts are maintained and accessible through the Smarsh Trust Center.
  • Third-Party & Supply Chain Risk: Lead third-party security reviews and ensure governance controls are extended across the vendor lifecycle. Partner with Procurement and Legal to align contractual security requirements and risk acceptance criteria.
  • Policy Lifecycle & Governance Metrics: Own the policy lifecycle process, ensuring policies are regularly reviewed, updated, and tracked for compliance. Develop governance reporting and dashboards that provide clear visibility into control effectiveness, risk posture, and audit readiness. Support governance forums and leadership committees with data-driven insights and structured governance reports.
  • GRC Operations & Enablement: Lead the continual refinement of GRC workflows, ensuring operational efficiency in documentation, evidence management, and status tracking. Collaborate with Engineering and Security teams to ensure controls are practically enforceable within operational workflows. Bring forward ideas and experience around scaling governance processes through automation and control validation techniques, supporting Smarsh’s long-term governance maturity.


What will you bring?
  • 2–5 years’ experience in information security, risk management, or compliance. 
  • Working knowledge of security frameworks such as ISO 27001, SOC 2, GDPR, NIST CSF, or similar. 
  • Familiarity with GRC platforms and evidence lifecycle management 
  • Strong organizational skills with attention to detail in documentation and reporting. 
  • Effective communication skills with both technical and non-technical stakeholders. 
  • Curiosity and drive to grow into GRC Engineering with a focus on automation and scalability. 


$93,000 - $105,000 a year

The above salary range represents Smarsh's good faith and reasonable estimate of the range of possible base compensation at the time of posting. Any applicable bonus programs will be discussed during the recruiting process. 

The salary for this role will be set based on a variety of factors, including but not limited to, internal equity, experience, education, location, specialty and training. 

Local cost of living assessments are done for each new hire at the time of offer.

About our culture


Smarsh hires lifelong learners with a passion for innovating with purpose, humility and humor. Collaboration is at the heart of everything we do. We work closely with the most popular communications platforms and the world’s leading cloud infrastructure platforms. We use the latest in AI/ML technology to help our customers break new ground at scale. We are a global organization that values diversity, and we believe that providing opportunities for everyone to be their authentic self is key to our success. Smarsh leadership, culture, and commitment to developing our people have all garnered Comparably.com Best Places to Work Awards. Come join us and find out what the best work of your career looks like.

Smarsh Glassdoor Company Review
3.0 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star iconGlassdoor star icon
Smarsh DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Smarsh
Smarsh CEO photo
Kim Crawford Goodman
Approve of CEO

Average salary estimate

$99000 / YEARLY (est.)
min
max
$93000K
$105000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Smarsh logo

What it's like to work at Smarsh

Read Reviews
Similar Jobs
Photo of the Rise User
Smarsh Hybrid No location specified
Posted 9 hours ago

Lead and grow a product security team to drive secure-by-design practices, threat modeling, vulnerability management, and compliance across Smarsh products.

Photo of the Rise User
Posted 8 hours ago

Experienced cybersecurity analyst needed to perform vulnerability prevalence, sector analysis, and risk assessments for a government-focused Vulnerability Management mission in Arlington, VA.

Photo of the Rise User
Scalian Hybrid AL-17, Mobile, AL, USA
Posted 13 hours ago

Experienced SAP Business/Functional Analyst (SAP QM) needed to design, configure, and support SAP solutions for Scalian’s industrial and digital systems projects.

Photo of the Rise User
Posted 17 hours ago

Experienced cloud security engineer needed to define and enforce organization-wide cloud security policies and secure infrastructure across cloud, networking, and application domains for a mission-driven US-based organization.

Photo of the Rise User
Posted 12 hours ago

Experienced security engineer needed to lead Azure cloud security, vulnerability management, and automated remediation efforts across enterprise environments.

Prime Healthcare is hiring an IT Support Specialist I to deliver front-line helpdesk support and incident documentation at its Ontario corporate location.

Posted 5 hours ago

Lead mission-critical manufacturing IT operations and projects for a major metal-products manufacturer, ensuring uptime, compliance, and alignment with business goals.

Photo of the Rise User

An experienced, hands-on Identity Engineer is needed at MacDill AFB to implement and operate Entra ID, enterprise PAM, and IGA solutions to enforce Zero Trust and least-privilege access.

Photo of the Rise User
Posted 13 hours ago

Work remotely as a Security Engineer, Observability to build and operate scalable security telemetry and observability systems that power threat detection and incident response across cloud and on-prem environments.

d-Matrix is hiring a contract Manufacturing Infrastructure Engineer in Santa Clara to build and maintain resilient Linux, PostgreSQL, and hybrid/cloud infrastructure for production manufacturing systems.

Bah Hybrid McLean, VA
Posted 10 hours ago

Booz Allen is hiring a Systems Engineer to design tests, maintain cybersecurity toolsets, and support DevSecOps-driven infrastructure in a secure agency environment.

Photo of the Rise User
Posted 57 minutes ago

CATHEXIS is hiring a Database Administrator to maintain, secure, and optimize databases that support the VA MDE Audit program and ensure high data quality and regulatory compliance.

Photo of the Rise User
Posted 8 hours ago

Support Fort Worth city staff as an IT Help Desk Technician providing phone and email troubleshooting, ticket management, and Active Directory administration in a hybrid, public-sector environment.

Photo of the Rise User

Peraton is hiring a Configuration Manager at MacDill AFB to maintain CMDB and IT asset lifecycles for the SITEC 3 EOM contract in support of USSOCOM operations.

Where we're headed Communications technology will continue to evolve. Businesses that can embrace these technologies, manage growing data volume and harness the value in their archived communications will thrive. To achieve this, companies need s...

3 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, unknown
DATE POSTED
October 2, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!