6sense
Sr. Security Assurance Engineer
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 2 days ago · Added 4 days ago
First listed 4 days ago and still open.
Salary
$141k a year
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Senior
Category
Software
Stated by the employer in the job description
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "United States, Remote, Austin, TX"
What Nomaders makes of it
- Residency required in United States
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Our Mission:
6sense's mission is to multiply what matters: growth, retention, and efficiency. We envision a future where companies, teams and people reach their full potential.
Our People:
People are the heart and soul of 6sense. We serve with passion and purpose. We live by our Being 6sense values of Win as One Team, Stay Curious, Do The Right Thing, Own the Outcome, and Create Belonging. Every 6sensor plays a part in defining the future of our industry-leading technology. 6sense is a place where difference-makers roll up their sleeves, take risks, act with integrity, and measure success by the value we create for our customers. We want 6sense to be the best chapter of your career.
Job Title: Senior Security Engineer, GRC (Governance, Risk and Compliance)
Organizational Reporting: Director, Security Assurance
Function/Dept: Business Technology / Security
Purpose of the Job
As members of 6sense's Security department, the Governance, Risk and Compliance (GRC) team aligns Security with business objectives while managing risks and meeting industry standards, regulations and contractual obligations. GRC enforces governance, implements risk management strategies, and ensures compliance through operating as the second line of defense.
This role is the engineering capability behind that mission. Rather than testing controls after the fact, this engineer builds the systems that test them continuously. The expectation is that controls are monitored as code, technical evidence is produced automatically from AWS and other source systems, control owners can self-serve their own evidence without a GRC ticket, and AI is used as core infrastructure across GRC workflows rather than as an experiment. Audit readiness should be a byproduct of the running system, not a project.
Job Description
Responsibilities & Accountabilities
Design, build, and own automated security control monitoring; write production-quality code (e.g., Python) under version control, peer review, and CI/CD, and treat control logic as a maintained software asset rather than a documented procedure
Convert the control library from periodic, sample-based manual testing to continuous control monitoring (CCM): define the technical signal for each control, its test frequency, pass/fail thresholds, and alerting and escalation path
Engineer self-service technical evidence collection in AWS using native services (Config, Security Hub, CloudTrail, Organizations/SCPs, IAM Access Analyzer, Systems Manager, EventBridge, Lambda, Athena/S3, CloudWatch), so control owners and auditors retrieve current evidence on demand without GRC acting as an intermediary
Eliminate manual, screenshot-based, and ticket-driven evidence collection; retire manual test procedures as automated equivalents come online and document the transition so auditors can rely on it
Redesign GRC processes to be AI-native; apply LLMs and agentic workflows to evidence review, control mapping, gap analysis, security questionnaire and customer due diligence response, policy and procedure drafting, and risk assessment triage, with explicit human-in-the-loop review, guardrails, and output validation
Maintain a single normalized control library crosswalked across frameworks (ISO 27001, SOC 2, PCI DSS, SOX, GDPR, NIST) so that one automated test satisfies multiple obligations
Build the control-failure pipeline end to end: automated detection, enrichment, ticket creation, owner routing, SLA tracking, remediation verification, and closure, including exception and risk acceptance handling where remediation is not viable
Partner with Platform Engineering, DevOps, and IT to shift controls left into preventive guardrails: service control policies, AWS Config conformance packs, policy-as-code in CI/CD, and secure-by-default infrastructure patterns
Instrument control health reporting: automation coverage, evidence freshness, control failure rates, mean time to remediate, and audit-readiness posture, surfaced in dashboards consumable by Security leadership and control owners
Lead internal and external audit engagements with automated evidence as the primary artifact; defend automated test design, sampling logic, and the completeness and accuracy of system-generated evidence to auditors and assessors
Oversee and execute complex control tests and third-party and operational security risk assessments, using tooling and AI-assisted analysis to increase coverage and reduce cycle time, and communicate results across multiple audiences with varying levels of sensitivity
Develop issue and risk treatment plans with owners and validate remediation through automated re-testing rather than manual confirmation
Requirements
- ·5+ years of experience being part of a GRC or similar team
- ·2+ years of hands-on experience building and maintaining automation, including proficiency in at least one scripting or programming language (Python preferred) and comfort working in Git, code review, and CI/CD
- ·Demonstrated hands-on AWS experience relevant to control monitoring and evidence generation: Config, Security Hub, CloudTrail, IAM, Organizations and SCPs, Lambda, EventBridge, S3/Athena, CloudWatch
- ·Experience retrieving, normalizing, and reconciling data across systems via APIs and SQL, and reasoning about the completeness and accuracy of that data
- ·Practical experience applying LLMs or AI agents to real workflows, including prompt and workflow design, output evaluation, and appropriate human review and guardrails
Benefits
- ·Equal Opportunity Employer:
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at 6sense, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$141k a year · You'll be taken to the employer's careers page.