Skip to content
← Back to job listings

GRC Automation & Assurance Lead

Rokt · New York, United States

External listingfull-timeabout 1 month ago

About The Role

Join Rokt, a leading technology company in the e-commerce space, as a GRC Automation & Assurance Lead. In this role, you will be responsible for owning the audit, assurance, and compliance pillar of our GRC program, leading the design and engineering of agentic systems that run it. You will work closely with various teams to drive ISO 27001, SOC 1, and SOC 2 programs to clean outcomes, and continuously evaluate and improve automated controls. This is a unique opportunity to combine compliance rigor with AI engineering in a fast-paced environment.

  • Architect, build, and maintain agents on Rokt's internal Security Agent Suite for GRC workflows, including client security questionnaires, evidence collection, control testing, vendor assessments, DPIAs, and audit preparation.
  • Design new GRC automations end-to-end: scope the workflow, build the agent or tool, validate outputs, and roll it out with the rest of the GRC team.
  • Lead the ISO 27001:2022 surveillance and recertification cycles, and SOC 1 and SOC 2 Type 2 audits, end-to-end.
  • Working knowledge of ISO 27000 family, SOC 1, SOC 2, NIST CSF, and privacy regulations (GDPR, CCPA, CPRA); bonus for PCI-DSS, CIS, SCF, ISO 42001, NIST AI RMF
  • 4+ years of relevant experience in Governance, Risk & Compliance, ideally in a fast-moving tech environment
  • Solid grasp of controller/processor concepts and broader privacy fundamentals
  • Hands-on internal auditing experience against ISO 27001 and SOC 2
  • Track record managing external audits end-to-end, including evidence collection, auditor engagement, and findings remediation
  • Strong written and verbal communication; able to translate technical detail into business language for leadership, clients, and auditors
  • Demonstrated ability to break complex compliance requirements into scalable, automated processes that don't slow the business down
  • Understanding of LLM risks and controls — prompt injection, model misuse, agent autonomy, data leakage — and how they map to frameworks like OWASP Agentic Top 10 or NIST AI RMF
  • Highly responsive, autonomous, and resilient
  • Comfort with version control (Git/GitHub) and basic scripting (Python or TypeScript)
  • Demonstrated experience designing and shipping agentic AI systems — not just using a chatbot. You have built agents that take actions, call tools, integrate with APIs, and complete multi-step workflows
  • Bias for shipping, comfort with ambiguity, and a builder mindset
  • Familiarity with at least one agent framework (Google ADK, LangGraph, OpenAI Agents SDK, MCP, or similar) and the core patterns: tool use, memory, evaluation, guardrails
  • Working knowledge of basic IT, cloud (AWS preferred), APIs, and SQL
  • Strong attention to detail balanced with willingness to use AI to extend it
  • Comfortable using AI coding agents (Claude Code, Cursor, Copilot, or similar) to build and maintain internal tools; able to read, modify, and ship code even if you don't consider yourself a software engineer

This is an external listing. JobSpring does not represent or verify the employer. Report this listing