← Back to results

Join Reflection AI as a GRC Engineer to build automated compliance controls and collaborate with engineering teams.

Location
New York, NY, United States
Compensation
Not disclosed
Level
mid
Type
full time

Posted by employer 1 day ago

First seen on Joblaze 10 hours ago

Last verified on the company career page 10 hours ago

Apply at Reflection AI → Save job Scanned from reflection.ai

Skills & Technologies

What you'll build

  • Design and build automated controls and monitoring
  • Partner with Engineering, Security, and IT
  • Build and maintain internal tooling
  • Translate regulatory and policy requirements
  • Support technical due diligence

Must have

  • 3-6 years of software engineering, security engineering, or DevOps/infrastructure experience
  • Hands-on experience supporting at least one security framework
  • Comfortable writing production-quality code
  • Experience translating non-technical requirements
  • Familiarity with cloud infrastructure and identity/access management concepts

Nice to have

  • Experience building or maintaining GRC tooling
  • Familiarity with one or more relevant frameworks
  • Experience with data governance or data lineage tooling
  • Background supporting a government contracting or regulated environment

Requirements

Experience
3–6 years
Visa
Sponsorship available

Not disclosed in this posting: compensation, work arrangement.

Benefits

Team Building Activities Unlimited PTO Equity/Stock Options Health Insurance Parental Leave

Joblaze summary

The GRC Engineer at Reflection AI focuses on integrating compliance into the engineering process by developing automated controls and monitoring systems that align with various security frameworks like SOC 2 and ISO 27001. This role requires proficiency in coding, particularly in Python, and experience with compliance automation tools, as well as a solid understanding of cloud infrastructure and data governance. Ideal candidates will have 3-6 years of relevant experience and the ability to translate regulatory requirements into actionable technical specifications. Reflection AI emphasizes a collaborative environment, making this position suitable for those who thrive at the intersection of c

Joblaze insights

  • Listed today — first seen on Joblaze October 11, 2026. Last confirmed on Reflection AI's careers page October 11, 2026.
  • Python appears in 43% of 200 comparable mid security roles in United States; GRC appears in 1% of 200 comparable mid security roles in United States.

Quick facts

How much experience is required?
3–6 years of relevant experience for this GRC Engineer role.
What's the tech stack?
Joblaze extracted these technologies from the posting: GRC, ISO 27001, NIST, Python, SOC 2, Vanta.
Does Reflection AI sponsor work visas for this role?
Yes — the posting indicates visa sponsorship is available for the right candidate.
What seniority level is this role?
Reflection AI targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this GRC Engineer role at Reflection AI.

From the original posting

Role summary

Reflection AI's Compliance and AI Governance function spans six pillars: AI Governance, Data Governance, Trade Compliance, Privacy Operationalization, Government Contracting Compliance, and Corporate Compliance. The team builds the policies, controls, and operating rhythms that let the company move fast while staying defensible with regulators, customers, and partners. This role sits at the intersection of compliance and engineering, partnering most closely on technical controls required by Security frameworks, AI Governance frameworks, Privacy, and Data Governance pillars to translate policy requirements into technical controls that scale.

We're looking for a Governance, Risk, & Compliance engineer who wants to work on compliance as a product problem rather than a paperwork problem. You'll build and maintain the technical infrastructure (tooling, pipelines, automated controls, evidence collection) that lets the compliance program operate at engineering scale instead of through manual review. A core part of the job is keeping our security framework compliance (SOC 2, ISO 27001, NIST) running on automated evidence rather than manual screenshotting, and building out the technical side of our Trade Compliance, Privacy, Data Governance, and TPRM program. You'll be the technical translator between compliance requirements and the engineering and security teams that have to implement them.

What You'll Do

  • Design and build automated controls and monitoring that satisfy security framework requirements (SOC 2, ISO 27001, NIST 800-53/800-171, CMMC): access reviews, data minimization, model/data lineage, continuous evidence collection

  • Partner with Engineering, Security, and IT to implement technical requirements arising from security frameworks, deemed export controls, and privacy regulations

  • Build and maintain internal tooling that supports compliance workflows (intake forms, screening checks, reporting dashboards, GRC platform integrations such as Vanta)

  • Translate regulatory and policy requirements into concrete technical specifications engineering teams can implement

  • Support technical due diligence for inbound customer security questionnaires, audits, and outbound vendor assessments

  • Maintain integrations between compliance/GRC systems and source-of-truth systems (identity, data infrastructure, model pipelines)

  • Help scope and support technical environment separations or system boundaries required for regulatory compliance (e.g., subsidiary or enclave environments)

What We're Looking For

  • 3-6 years of software engineering, security engineering, or DevOps/infrastructure experience

  • Hands-on experience supporting at least one security framework (SOC 2, ISO 27001, or NIST) as an engineer, not just as a subject

  • Comfortable writing production-quality code (Python, or similar) and working with APIs/integrations

  • Experience translating non-technical requirements (policy, regulatory, contractual) into technical implementation

  • Familiarity with cloud infrastructure and identity/access management concepts

  • Strong collaboration skills; able to work effectively with compliance, legal, and engineering stakeholders who don't share a common vocabulary

  • Experience building or maintaining GRC tooling, TPRM/vendor risk platforms, or compliance automation (e.g., Vanta or similar)

  • Familiarity with one or more relevant frameworks: CMMC, NIST 800-171/800-53, SOC 2, ISO 27001, GDPR/CCPA technical requirements

  • Experience with data governance or data lineage tooling, especially in ML/AI pipelines

  • Background supporting a government contracting or regulated environment

  • Top-tier compensation: Salary and equity structured to recognize and retain our talent globally.

Standard company text repeated across Reflection AI's postings is omitted here.

Similar positions

Reflection AI
Compliance Manager
Reflection AI · New York, NY, United States
Reflection AI
Sr. Enterprise Risk Governance Specialist
Reflection AI · New York, NY
Cursor
Security GRC Engineer
Cursor · San Francisco
HappyRobot
GRC Compliance Specialist
HappyRobot · Spain