GRC Automation Engineer

🏢 Granicus · all Granicus jobs
📍 United States
💰 USD 103,600 - 123,000 / annual
📅 Posted 2026-08-16 · via Himalayas
🏷 GRC-Engineering,Security-Automation,Compliance-Engineering,AI-Engineering,Governance-Risk-And-Compliance,Senior-GRC-Automation-Engineer,GRC-Engineer,GRC-Automation,GRC-Security-Engineer,GRC-Technical-Lead
Apply on original site ↗

The Company
Serving the People Who Serve the People

Granicus is driven by the excitement of building, implementing, and maintaining technology that is transforming the Govtech industry by bringing governments and its constituents together. We are on a mission to support our customers with meeting the needs of their communities and implementing our technology in ways that are equitable and inclusive. Granicus has consistently appeared on the GovTech 100 list over the past 5 years and has been recognized as the best companies to work on BuiltIn.

Over the last 25 years, we have served 5,500 federal, state, and local government agencies and more than 300 million citizen subscribers power an unmatched Subscriber Network that use our digital solutions to make the world a better place. With comprehensive cloud-based solutions for communications, government website design, meeting and agenda management software, records management, and digital services, Granicus empowers stronger relationships between government and residents across the U.S., U.K., Australia, New Zealand, and Canada. By simplifying interactions with residents, while disseminating critical information, Granicus brings governments closer to the people they serve—driving meaningful change for communities around the globe.

Want to know more? See more of what we do here.
Job Summary

We are looking for a GRC Automation Engineer who has experience with AI tools and building automation. The role will identify, evaluate and implement AI-enabled solutions that improve governance, risk and compliance processes whilst maintaining security, privacy and regulatory requirements.

This role blends information security and compliance with automation, engineering, and solutioning. We are looking for someone who is inquisitive, a builder, and a problem solver who will partner with the GRC team to learn the current processes and build automation to increase team effectiveness and enable the team to grow into more in-depth security analysis.

What Your Impact Will Look Like

- Build automations that reduce manual work across information security and compliance activities, including evidence collection, control validation, audit preparation, POA&M tracking, continuous monitoring, reporting, and task management.

- Build third party security review automations to support new procurement and recurring reviews, including for third parties that impact FedRAMP, CJIS, HIPAA, PCI, and IP.

- Use AI-enabled tools, AI agents, low-code/no-code platforms, scripts, APIs, and integrations to streamline repeatable compliance workflows and improve consistency, traceability, and timeliness. Design, test and optimise AI-assisted workflows and prompts to increase operational efficiency.

- Evaluate emerging AI technologies and identify practical applications for governance, risk and compliance use cases.

- Assess AI-enabled automations for security, privacy, regulatory compliance, auditability and alignment with organisational AI governance standards.

- Leverage AI-assisted analysis to identify trends, risks, control gaps and remediation opportunities across security and compliance data.

- Partner with Security, Engineering, Product, IT, Legal, and business teams to understand current manual processes, document requirements, and translate them into automated workflows.

- Support automation across multiple compliance frameworks, including FedRAMP, CJIS, ISO 27001, ISO 42001, SOC 2, PCI, HIPAA, FISMA, and CyberEssentials, including controls and governance requirements associated with AI technologies.

- Support ongoing transformation from FedRAMP rev5 legacy reporting and auditing requirements to the new Consolidated New Rules (CNRs) and 20.x. This includes transforming vulnerability management (scan to tickets to reporting, modern risk analysis and scoring, trend analysis), inventory management and reporting for FedRAMP, POA&M reporting, and deviation management.

- Evaluate team processes to

← All remote jobs