← Back to results

Sr. GRC Engineer

Drive the evolution of Pendo's governance, risk, and compliance program as a Sr. GRC Engineer in a hybrid work environment.

Location
Raleigh, NC, United States
Compensation
$133.4k–$160k/yr
Level
senior
Type
full time · Hybrid

Posted by employer 1 day ago

First seen on Joblaze 1 day ago

Last verified on the company career page 1 day ago

Apply at Pendo → Save job Scanned from pendo.io

What you'll build

  • Lead complex compliance, risk, and incident-response work
  • Own one or more regulatory compliance programs end-to-end
  • Conduct organizational risk assessments
  • Lead incident response for complex security events
  • Work directly with engineering, product, and IT teams

Must have

  • 3 to 5 years of hands-on security experience
  • Deep working knowledge of at least two compliance frameworks
  • Demonstrated ability to independently own auditor relationships
  • Experience leading incident response investigations
  • Ability to translate security risk into business-risk language
  • Active use of AI tools to accelerate security workflows

Nice to have

  • Experience with SIEM or EDR platforms
  • GRC platform administration experience
  • Experience operationalizing threat intelligence
  • A security certification such as CISA, CISSP, CISM
  • Experience working in a SaaS company

Practical constraints

  • In-office 3 days per week unless designated remote

AI in the day-to-day

Use AI to accelerate audit evidence preparation, policy documentation, control testing workflows, and regulatory research.

Requirements

Experience
3–5 years

Not disclosed in this posting: visa sponsorship.

Benefits

401k Match Equity/Stock Options Flexible Time Off Health Insurance

Joblaze summary

The Sr. GRC Engineer at Pendo plays a crucial role in enhancing the company's governance, risk, and compliance framework by independently managing complex compliance programs and incident responses. This position requires a strong foundation in security practices, particularly with frameworks like SOC 2 and ISO 27001, alongside a proactive approach to integrating AI tools into compliance workflows. Ideal candidates will have several years of hands-on experience in security operations and a knack for translating technical risks into business terms. Pendo's small, collaborative team environment emphasizes strategic thinking and innovation in security practices.

Joblaze insights

  • Listed yesterday — first seen on Joblaze September 25, 2026. Last confirmed on Pendo's careers page September 25, 2026.
  • Salary band is below the typical range for Security roles (median ~$170,000).
  • Starts above 27% of 22 comparable senior security roles in United States that list SOC 2 we track (median $167,673 across 18 companies).
  • SOC 2 appears in 8.7% of 310 comparable senior security roles in United States; PCI-DSS appears in 1.6% of 310 comparable senior security roles in United States.

Quick facts

Is the Sr. GRC Engineer role remote?
It's hybrid — Pendo expects some on-site time in Raleigh, NC, United States.
What's the salary range?
Pendo lists $133,400–$160,000 for this role.
How much experience is required?
3–5 years of relevant experience for this Sr. GRC Engineer role.
Where is the role based?
Pendo is hiring for this position in Raleigh, NC, United States.
What's the tech stack?
Joblaze extracted these technologies from the posting: AI, FedRAMP, GovRAMP, ISO 27001, NIST 800-series, PCI-DSS.
What seniority level is this role?
Pendo targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Sr. GRC Engineer role at Pendo.

From the original posting

Sr. GRC Engineer

The Team + The Role

Pendo's Information Security team protects the data entrusted to Pendo and helps ensure our products are built with security and privacy by design. The team spans Security Operations, Product Security, and Compliance and Risk. With a small team and broad scope, the work directly supports the security, resilience, and trust of Pendo's products and operations.

The Sr. GRC Engineer is an AI-first technical leader who helps drive the evolution of Pendo's governance, risk, and compliance program. This role independently leads complex compliance, risk, and incident-response work while identifying program maturity gaps, translating security risk into business terms, and contributing to security roadmap and investment decisions. Success means building durable controls and programs that reduce risk and operational friction, not simply completing audits.

This role is based in our Raleigh office.

What this looks like day-to-day

  • AI-driven compliance and operations acceleration: Use AI to accelerate audit evidence preparation, policy documentation, control testing workflows, and regulatory research. Evaluate GRC platform automation capabilities and integrate AI tooling where it reduces manual overhead, then document and share effective approaches with the team.
  • Security program strategy and roadmap: Identify maturity gaps across compliance and security operations and translate them into prioritized roadmap recommendations grounded in business risk. Contribute to security investment discussions, clarify tradeoffs between coverage, cost, and risk, and anticipate emerging regulatory requirements before they become audit findings.
  • Compliance program ownership: Own one or more regulatory compliance programs end-to-end, including SOC 2 Type II, ISO 27001/42001, PCI-DSS, GovRAMP, or FedRAMP. Lead control design, evidence collection, auditor relationships, and remediation tracking to maintain effective and durable compliance programs.
  • Risk assessment and prioritization: Conduct organizational risk assessments and present findings to leadership with clear prioritization and investment-level recommendations. Translate technical exposure into business-risk language that enables leaders to make informed decisions without requiring additional security interpretation.
  • Incident response leadership: Lead incident response for complex, multi-system security events from investigation through resolution. Conduct root cause analysis, run post-incident reviews, and own resulting actions that turn incident findings into measurable program improvements.
  • Cross-functional partnership: Work directly with engineering, product, and IT teams to deliver compliance requirements, validate implementations, and embed security into day-to-day operations. Translate compliance obligations into actionable technical requirements and influence how partner teams approach security as well as what they deliver.

You're a builder, not a maintainer.

You're most energized when there isn't a clear path yet, and you get to define it. You don't wait for direction; you identify gaps, shape solutions, and drive them forward. At Pendo, great Sr. GRC Engineers don't just follow instructions; they operate as strategic advisors, influencing decisions, guiding stakeholders, and elevating how we work.

You're AI-curious - genuinely.

Must-haves

  • 3 to 5 years of hands-on security experience with demonstrated ownership of compliance programs or security operations work, rather than participation alone.
  • Deep working knowledge of at least two of the following frameworks: SOC 2, ISO 27001, PCI-DSS, FedRAMP, GovRAMP, or the NIST 800-series.
  • Demonstrated ability to independently own auditor relationships and manage an audit cycle end-to-end, including responding directly to auditor questions.
  • Experience leading incident response investigations from triage through root cause analysis and producing post-incident documentation that engineering teams can act on.
  • Demonstrated ability to translate security risk into business-risk language that enables leaders to make investment and prioritization decisions.
  • Active, demonstrated use of AI tools to accelerate security workflows such as evidence collection, policy drafting, regulatory research, or detection analysis.
  • Strong written and verbal communication skills, with the ability to tailor recommendations effectively for engineering, auditor, and leadership audiences.

Nice-to-haves

  • Experience with SIEM or EDR platforms such as Splunk, Elastic, CrowdStrike, or SentinelOne, including independently writing and tuning detection rules.
  • GRC platform administration experience with tools such as Vanta, Drata, or Archer, including automation configuration and third-party integrations.
  • Experience operationalizing threat intelligence or conducting threat hunting using MITRE ATT&CK.
  • A security certification such as CISA, CISSP, CISM, Security+, or equivalent.
  • Experience working in a SaaS company with concurrent multi-framework compliance obligations.

Compensation: The expected base salary range for this role to be performed in Raleigh, NC is $133,400 - $160,000.

Benefits: Highly competitive, employer-heavy coverage, including $0 premium options, strong 401(k) match, equity, and flexible time off.

Standard company text repeated across Pendo's postings is omitted here.

Similar positions

Pendo
Software Engineer, Full Stack
Pendo · Raleigh, NC, United States
Pendo
Sr. Software Engineer (AI)
Pendo · New York, NY
Pendo
Sr. Software Engineer
Pendo · Sheffield, England, UK
Pendo
Software Engineer (AI)
Pendo · New York, NY
Peregrine