Startups

GRC Engineer

Clerk · Remote · Remote

← All jobs
About Clerk

The easiest way to add authentication and user management to your application. Purpose-built for React, Next.js, Remix, and “The Modern Web”. Backed by a16z.

About the role

Own SOC 2 Type II and HIPAA end to end: scoping, control design, evidence, auditor walkthroughs, and remediation Scope and lead our next framework (ISO 27001 is the likely candidate) based on what customers actually ask for

What they're looking for

  • 5+ years in security, with demonstrated experience building automation for a GRC or compliance program
  • You've been the technical owner of at least one SOC 2 Type II or ISO 27001 audit and can tell us what you would do differently
  • You write code, and you use LLMs to get more done without lowering the bar
  • Hands-on with a GRC platform's API, not just its dashboard
  • Cloud IAM and configuration depth on at least one provider, GCP preferred
  • You can decide what evidence is sufficient and defend an automated test to an auditor
More about this role

Clerk is on a mission to solve the user identity layer once and for all. We are a globally distributed team dedicated to providing best-in-class developer infrastructure to build the next generation of AI software. Today, we provide developers with full-stack React components and hooks like , , , useUser , and useOrganization . These APIs allow developers to build hard-to-get-right infrastructure for user identity, organization management and billing flows. We believe that a component is worth a thousand APIs .

Clerk is looking for a Senior GRC Engineer to join our Security Team. Our customers put Clerk in the middle of their authentication flow, and every one of them runs us through their own vendor review before they do. You'll own the program that makes that review easy: the controls, the evidence, the audits, and the answers.

You'll work as a hands-on engineer. Expect to spend a lot of your time writing integrations, automations, and internal tools that enforce policies and automate the evidence gathering. The goal is a program that's always current, so an audit is just someone observing it rather than a quarterly scramble.

Own SOC 2 Type II and HIPAA end to end: scoping,...

Read the full posting on Clerk's site ↗

Security

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.