smartsheet

Principal Security Engineer – GRC Team Lead (Remote Eligible)

Apply Now

At a Glance

Location
Bellevue, Washington, United States
Work Regime
remote
Experience
10+ years
Posted
2026-07-08T17:33:16-04:00

Key Requirements

Required Skills

AWSAzureBashCI/CDGCPPythonTerraform

Certifications

  • AWS Certified
  • CISA
  • CISM
  • CISSP
  • ISO

Domain Knowledge

  • Automation
  • Cybersecurity
  • Engineering
  • Government
  • Insurance
  • Medical
  • Regulatory
  • Retail
  • SaaS

Requirements

10+ years of experience in GRC, compliance, security engineering, or related roles, with 5+ years in a technical or leadership capacity managing compliance programs at scale.

Deep hands-on expertise in running full audit cycles across multiple frameworks, particularly SOC 2 Type II, ISO 27001, and FedRAMP.

You've managed evidence preparation, control testing, audit remediation, and continuous monitoring.

Strong technical foundation in cloud architecture and compliance: Working knowledge of AWS/GCP/Azure, infrastructure-as-code (Terraform), CI/CD pipelines, identity and access management, encryption, and logging—sufficient to design control implementations and validate technical posture.

Hands-on experience with GRC platform administration and customization (Vanta, Drata, ServiceNow GRC, or equivalent), including integration design and workflow automation.

Proficiency in policy-as-code and compliance-as-code principles: Experience implementing automated controls, policy enforcement, and continuous compliance validation through code and configuration.

Responsibilities

Own the end-to-end GRC strategy and roadmap: Lead the planning and prioritization of GRC initiatives that drive compliance maturity, reduce audit risk, and improve operational efficiency.

Design and implement policy-as-code systems: Translate compliance frameworks (SOC 2, ISO 27001, FedRAMP, HIPAA) into enforceable code, leveraging Infrastructure-as-Code (Terraform, CloudFormation) and automated compliance validation.

Build custom control frameworks: Design Smartsheet-specific Unified Control Frameworks (UCF) and Secure Control Frameworks (SCF) that map to our cloud architecture, multi-framework requirements, and organizational risk appetite.

Lead full audit cycles: Manage preparation, execution, and resolution for SOC 2 Type II, ISO 27001, FedRAMP, and other certification audits.

Own evidence gathering, audit readiness tracking, and post-audit remediation.

Architect GRC platform strategy: Evaluate, select, configure, and integrate GRC tooling (Vanta, Drata, or similar) with our cloud infrastructure, identity systems, ticketing systems, and CI/CD pipelines to enable continuous compliance monitoring.