smartsheet
Principal Security Engineer – GRC Team Lead (Remote Eligible)
At a Glance
- Location
- Bellevue, Washington, United States
- Work Regime
- remote
- Experience
- 10+ years
- Posted
- 2026-07-08T17:33:16-04:00
Key Requirements
Required Skills
Certifications
- AWS Certified
- CISA
- CISM
- CISSP
- ISO
Domain Knowledge
- Automation
- Cybersecurity
- Engineering
- Government
- Insurance
- Medical
- Regulatory
- Retail
- SaaS
Requirements
10+ years of experience in GRC, compliance, security engineering, or related roles, with 5+ years in a technical or leadership capacity managing compliance programs at scale.
Deep hands-on expertise in running full audit cycles across multiple frameworks, particularly SOC 2 Type II, ISO 27001, and FedRAMP.
You've managed evidence preparation, control testing, audit remediation, and continuous monitoring.
Strong technical foundation in cloud architecture and compliance: Working knowledge of AWS/GCP/Azure, infrastructure-as-code (Terraform), CI/CD pipelines, identity and access management, encryption, and logging—sufficient to design control implementations and validate technical posture.
Hands-on experience with GRC platform administration and customization (Vanta, Drata, ServiceNow GRC, or equivalent), including integration design and workflow automation.
Proficiency in policy-as-code and compliance-as-code principles: Experience implementing automated controls, policy enforcement, and continuous compliance validation through code and configuration.
Responsibilities
Own the end-to-end GRC strategy and roadmap: Lead the planning and prioritization of GRC initiatives that drive compliance maturity, reduce audit risk, and improve operational efficiency.
Design and implement policy-as-code systems: Translate compliance frameworks (SOC 2, ISO 27001, FedRAMP, HIPAA) into enforceable code, leveraging Infrastructure-as-Code (Terraform, CloudFormation) and automated compliance validation.
Build custom control frameworks: Design Smartsheet-specific Unified Control Frameworks (UCF) and Secure Control Frameworks (SCF) that map to our cloud architecture, multi-framework requirements, and organizational risk appetite.
Lead full audit cycles: Manage preparation, execution, and resolution for SOC 2 Type II, ISO 27001, FedRAMP, and other certification audits.
Own evidence gathering, audit readiness tracking, and post-audit remediation.
Architect GRC platform strategy: Evaluate, select, configure, and integrate GRC tooling (Vanta, Drata, or similar) with our cloud infrastructure, identity systems, ticketing systems, and CI/CD pipelines to enable continuous compliance monitoring.