Compliance Engineer
Domain
Tech Stack
Must-Have Requirements
- ✓2–4 years in information security compliance, GRC, or a related discipline
- ✓Working knowledge of two or more: SOC 2, ISO 27001, NIST CSF/800-53, CIS Controls, NERC CIP
- ✓Experience supporting or leading external audits, including evidence collection and auditor coordination
- ✓Ability to perform cross-framework control mapping and identify gaps or conflicts
- ✓Strong written communication skills across technical and non-technical audiences
Nice to Have
- -Hands-on experience with NERC CIP (CIP-002 through CIP-014) in an OT or critical infrastructure environment
- -Familiarity with GRC platforms such as Vanta, Drata, OneTrust, or Archer
- -Certifications: CISA, CRISC, ISO 27001 Lead Implementer/Auditor, or NERC CIP
Description
About Gridware Gridware is a San Francisco-based technology company dedicated to protecting and enhancing the electrical grid. We pioneered a groundbreaking new class of grid management called active grid response (AGR), focused on monitoring the electrical, physical, and environmental aspects of the grid that affect reliability and safety. Gridware’s advanced Active Grid Response platform uses high-precision sensors to detect potential issues early, enabling proactive maintenance and fault mitigation. This comprehensive approach helps improve safety, reduce outages, and ensure the grid operates efficiently. The company is backed by climate-tech and Silicon Valley investors. For more information, please visit www.Gridware.io.
Responsibilities
Framework Implementation & Control Management Design a unified control framework mapped across SOC 2, ISO 27001, CIS IG3, NERC CIP, and NIST (CSF/800-53), eliminating duplication and creating a single source of truth for compliance posture. Develop and maintain a control library, policy inventory, and risk register. Translate technical control requirements into actionable guidance for engineering, IT, and operations teams. Audit Readiness & Evidence Collection Build a structured, repeatable evidence collection process supporting concurrent audits across all frameworks. Maintain a continuously updated evidence repository and coordinate with Engineering, DevOps, HR, and Legal to gather and validate artifacts. Serve as primary liaison with external auditors; manage schedules, fieldwork, and findings remediation through to closure. Customer Security Assurance Own intake, triage, and completion of customer security questionnaires (SIG Lite, CAIQ, custom assessments). Maintain a living questionnaire knowledge base and develop customer-facing security documentation, including trust portal content. Program Development Define compliance workflows, SOPs, tooling requirements, and automation opportunities as the program matures. Monitor regulatory changes across NERC CIP, NIS 2, and NIST; proactively communicate impacts to the team.
Required Skills 2–4 years in information security compliance, GRC, or a related discipline. Working knowledge of two or more: SOC 2, ISO 27001, NIST CSF/800-53, CIS Controls, NERC CIP. Experience supporting or leading external audits, including evidence collection and auditor coordination. Ability to perform cross-framework control mapping and identify gaps or conflicts. Strong written communication skills across technical and non-technical audiences.
Bonus Skills Hands-on experience with NERC CIP (CIP-002 through CIP-014) in an OT or critical infrastructure environment. Familiarity with GRC platforms such as Vanta, Drata, OneTrust, or Archer. Certifications: CISA, CRISC, ISO 27001 Lead Implementer/Auditor, or NERC CIP.