Senior GRC Engineer

🏢 DataLock Consulting Group · all DataLock Consulting Group jobs
📍 United States
📅 Posted 2026-08-23 · via Himalayas
🏷 GRC-Engineering,Cybersecurity,Security-Engineering,Risk-Management,Federal-Cybersecurity,Senior-GRC-Automation-Engineer,Senior-GRC-Consultant,Senior-Security-GRC-Analyst,GRC-Senior-Analyst,GRC-Technical-Lead,Security-GRC-Lead,Senior-SAP-GRC-Consultant
Apply on original site ↗

This is a remote position.
The Senior GRC Engineer is a seasoned cybersecurity professional responsible for maintaining and advancing the cybersecurity posture of a federal program, system, or enclave. This role operates at the intersection of cybersecurity, engineering, and risk management and is designed for an experienced practitioner who applies engineering rigor to develop high-quality, technically sound, and actionable security artifacts.
This position goes beyond static compliance and documentation. The Senior GRC Engineer guides system and engineering teams in designing, developing, implementing, and maintaining secure solutions aligned with evolving mission needs and threat environments. While the role produces documentation in support of the NIST Risk Management Framework, the emphasis is on meaningful security engineering outcomes rather than technical writing alone.
The Senior GRC Engineer champions the organization’s transition to a modern GRC Engineering model by promoting continuous assurance, automated evidence collection, integrated risk scoring, and scalable control inheritance. The role supports modernization initiatives, including DevSecOps, Zero Trust architectures, supply chain risk management, artificial intelligence and machine learning enabled security, responsible citizen development, and cybersecurity across both IT and operational technology environments.
Through leadership and technical expertise, this role strengthens system resilience, improves risk-based decision making, and accelerates secure mission delivery across federal environments.

Responsibilities
• Maintain and strengthen the cybersecurity posture of assigned federal programs, systems, or enclaves.
• Guide system owners, ISSOs, and engineering teams in applying GRC engineering principles throughout the system lifecycle.
• Lead and support Risk Management Framework activities, including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
• Produce high-quality security and privacy artifacts that are technically sound, actionable, and aligned with engineering realities.
• Support achievement and maintenance of Authorities to Operate (ATOs) and manage associated Plans of Action and Milestones (POA&Ms).
• Brief senior leadership on risk posture, authorization status, and remediation strategies.
• Apply DevSecOps principles to integrate security into CI/CD pipelines and modern development workflows.
• Support Zero Trust architecture implementation, supply chain risk management, and modernization initiatives.
• Apply continuous integration, continuous delivery, and continuous security principles across environments.
• Support implementation and analysis of SAST, DAST, Software Composition Analysis, secrets management, and GitHub-based workflows.
• Apply Infrastructure as Code, virtualization, and containerization concepts to security engineering and assessment activities.
• Utilize endpoint protection, integrity monitoring, and SIEM tooling to support security operations and monitoring.
• Implement and assess authentication, authorization, and identity federation mechanisms including SAML, OAuth, and OIDC.
• Apply PKI, encryption technologies, and FIPS implementation requirements.
• Analyze network architectures, topologies, and protection mechanisms to assess confidentiality, integrity, and availability risks.
• Leverage OSCAL for machine-readable control catalogs, baselines, System Security Plans, and assessment documentation.
• Analyze and interpret software vulnerabilities using CVE, CWE, and CVSS scoring methodologies.
• Evaluate supplier and product trustworthiness as part of supply chain risk management efforts.
• Develop and maintain cybersecurity and privacy policies aligned with organizational objectives.
• Apply cybersecurity and privacy principles related to confidentiality, integrity, availability, authentication, and non-repudiation.
• Assess security and privacy cont

← All remote jobs