Senior Security Engineer, GRC
Temporal Technologies · United States and Canada - Remote Opportunity
- Location
- United States and Canada - Remote Opportunity
- Workplace
- Remote
- Level
- Senior
- Posted
- 3 months ago
About this role
About Us
Temporal is an open source programming model that can simplify code, make applications more reliable, and help developers focus on the important things like delivering features faster. We are on a mission to be the reliable foundation of every developer’s toolbox, and are building the team that will make that happen. Our values guide us - they are present in how we show up, make decisions, and work together to make an impact. We’re curious, driven, collaborative, genuine and humble. Temporal is growing and we are looking for those who share our values, challenge 'standard' thinking, and want to influence our future. If you have a passion for improving the developer experience, building world-class open-source software and communities, and want to be a part of our amazing team, we'd love to hear from you!
Summary
Join our team as a Senior Security Engineer, GRC, where you'll be the primary owner of our customer-facing compliance program and a trusted partner throughout the enterprise sales cycle. In this role, you will manage the end-to-end lifecycle of security questionnaires, due diligence requests, and compliance reviews and automate parts of that process. You will ensure prospective and existing customers have full confidence in our security posture and you will work closely with Sales, Legal, and Product to represent our compliance program externally, while maintaining the internal rigor of our governance and risk frameworks.
What You'll Do
- Own the intake, prioritization, and completion of all inbound customer security questionnaires, RFPs, and due diligence requests including SIG, CAIQ, and custom enterprise questionnaires with a commitment to accuracy, thoroughness, and turnaround time.
- Serve as the primary customer-facing representative for security and compliance, leading calls and meetings with enterprise customers, prospects, and their security or procurement teams.
- Build and maintain a comprehensive, evergreen response library for common security and compliance questions, reducing duplication of effort and ensuring consistency across all customer engagements.
- Build and maintain automations to continuously validate the organization's compliance posture across key frameworks including SOC2 Type II, ISO 27001, and HIPAA, coordinating evidence collection, managing external auditor relationships, and driving readiness for annual assessments.
- Build dashboards and reporting pipelines that provide leadership with real-time visibility into compliance posture, open risks, and program health.
- Design and automate the third-party risk assessment process, including vendor tiering logic, questionnaire workflows, and continuous monitoring for critical vendors.
- Perform ongoing risk assessments and maintain a risk register that reflects the current threat and compliance landscape, escalating material findings to leadership with clear remediation recommendations.
- Conduct third-party vendor risk assessments, including use case-specific risk analysis, ongoing tiering and monitoring, and implementation recommendations.
- Author, maintain, and operationalize security policies and procedures; track employee acknowledgments and manage exceptions through to resolution.
- Coordinate and participate in customer security review meetings, including onsite or virtual sessions with enterprise security, legal, and procurement stakeholders.
- Collaborate cross-functionally with Engineering, Legal, and Product to gather documentation, validate control descriptions, and resolve compliance gaps surfaced through customer inquiries.
What You'll Bring
- 8+ years of experience in GRC, information security compliance, or a closely related field.
- Deep, hands-on experience with at least two major compliance frameworks (SOC2, ISO 27001, HIPAA, PCI-DSS, or FedRAMP), including direct involvement in audits and assessments.
- Proven track record managing high volumes of security questionnaires and enterprise due diligence requests, including SIG and CAIQ formats.
- Strong understanding of the security program’s influence on company revenue and a partnership mindset with the Go To Market function.
- Scripting and automation fluency (Python, Bash, or similar) and a track record of building tools, not just spreadsheets.
- Strong customer-facing communication skills, you are equally comfortable presenting to a CISO, walking a procurement team through a control matrix, or discussing technical security controls with customer engineering leaders.
- Solid understanding of risk management principles, with hands-on experience performing risk assessments and maintaining a risk register.
- Ability to translate technical security controls into clear, business-appropriate language for non-technical audiences including customers, legal teams, and executives.
- Strong organizational skills and the ability to manage multiple concurrent questionnaire engagements, each with distinct deadlines and stakeholder requirements.
- Bachelor's degree in Information Security, Computer Science, Business, or a related field (or equivalent experience).
Nice to Have
- Security certifications: CISSP, CISM, CRISC, CISA, or CCSP.
- Experience with GRC platforms such as Vanta, Drata, Sprinto, or similar.
- Familiarity with NIST CSF or NIST 800-53 control frameworks.
- Background in SaaS, fintech, or healthcare environments with regulated data handling requirements.
- Experience drafting or reviewing Data Processing Agreements (DPAs), Business Associate Agreements (BAAs), or security-related contract language.
- Experience supporting FedRAMP authorization or state-level public sector compliance programs.
Compensation
- The estimated pay range for this role is $180,000 - $225,000, depending on qualifications and location.
- This role is eligible to participate in Temporal's equity plan.
Compensation ranges reflect salary and commission compensation (when applicable) across several geographic markets. Employment offers carefully consider multiple factors, including prior experience, knowledge, expertise, skillset, market location, and job level assessed during the interview process. Employee benefits and perks below are for full-time employees, part-time or temporary positions are excluded. U.S. Benefits
- Unlimited PTO, 12 Holidays + 2 Floating Holidays
- 100% Premiums Coverage for Medical, Dental, and Vision
- AD&D, LT & ST Disability, and Life Insurance (Standard & Supplemental Available)
- Empower 401K Plan
- Additional Perks for Learning & Development, Lifestyle Spending, Home Office Setup, Professional Memberships, WFH Meals, Internet Stipend and more!
International Benefits
Paid Time Off (PTO) and Benefits outside the United States vary by country, and are issued in partnership with Remote.com. Additionally, Temporal offers perks to all international employees for learning & career development, a lifestyle spending account, home office setup, professional memberships, work-from-home meals, and access to the Calm app for mental wellness.
Travel
Temporal is a globally distributed, collaborative team that values opportunities for in-person connection. Occasional travel may be required for company events, team offsites, and other meaningful moments that bring us together.
Temporal Technologies is an Equal Opportunity Employer. Temporal Technologies does not discriminate on the basis of race, religion, color, sex, gender identity, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law. All employment is decided on the basis of qualifications, merit, and business need. We embrace and celebrate differences and diversity. Temporal is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. If you need to request a reasonable accommodation, please let your Recruiter know so we can assist. We are not working with external recruitment agencies, thanks.
As published by Temporal Technologies. Applications are handled on their site.
Skills this posting mentions
About Temporal Technologies
Use Workflow as Code™ to build and operate resilient applications using developer friendly primitives. Write business logic - not glue code - and Temporal takes care of the rest.
All 55 openings at Temporal TechnologiesOne click, then it is written
Apply to Temporal Technologies with a resume written for this role.
Queue Senior Security Engineer, GRC and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Temporal Technologies’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Temporal Technologies
See all- 5 weeks ago
Senior Platform Architect - West
United States - Remote OpportunityRemote
$200k - $225k/yrSeniorEngineering - 6 weeks ago
Staff Software Engineer, AI Foundations (AI Agent Optimization)
United StatesRemote
$224k - $302k/yrStaffEngineering - 6 weeks ago
- 7 weeks ago
Senior Manager, Solutions Architecture - New Logo
United States - Remote OpportunityRemote
$280k - $340k/yrManagerSales - 7 weeks ago
Sr. Workplace Employee Experience Manager
United States - San Francisco
$200k - $250k/yrManagerPeople and HR - 7 weeks ago
GTM Compensation and Insights Manager
United States - Remote OpportunityRemote
$176k - $220k/yrManagerPeople and HR
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Temporal Technologies publishes. Refolk is not the employer and does not handle their hiring. Applications go to Temporal Technologies directly.