← Back to job listings
KI
Staff GRC Engineer
Kikoff · San Francisco, United States
About The Role
Join Kikoff as a Staff Trust & Assurance Engineer, where you will be responsible for establishing and leading the Trust & Assurance function within Security. You will own the design, operation, and attestation of cybersecurity controls, and work closely with various departments to ensure compliance and security. This role emphasizes automation, code-backed control operations, and AI-assisted evidence workflows.
- Conception, operation, and attestation of cybersecurity controls for external auditors, regulators, and B2B customers.
- Management of the SOC 2 Type II program, including scoping, control design, evidence collection, walkthroughs, and external auditor management.
- Leadership of security compliance, customer assurance, and third-party risk management work streams.
- Understanding of cloud infrastructure and modern AI-native technologies
- Has owned at least one SOC 2 Type II cycle end-to-end, including design, evidence, walkthroughs, and auditor defense
- Hands-on experience with PCI DSS, including SAQ environments and tokenization-driven scope reduction
- Demonstrated experience managing external auditors and translating control requirements into engineering deliverables
- Comfortable operating across functional boundaries, including Engineering, Legal, and Finance
- Excellent written communication, with the ability to produce auditor-ready documentation and engineering-ready specifications
- 7+ years of experience in security compliance, GRC, or technical audit, with a primary focus on cloud-native environments
- Able to read and modify code, infrastructure-as-code, and IAM policies. Comfortable working in Git-based engineering workflows and shipping changes through CI/CD
- Prior experience as a control owner supporting SOX IT general controls audits in a pre-IPO or newly public company
- Experience building or operating AI- or LLM-driven GRC automation, including custom agents, MCP servers, or evidence-collection pipelines
- Background in IPO readiness or newly public company environments
- Familiarity with ISO 27001, ISO 42001, FedRAMP, CMMC 2.x, or NIST 800-53
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring