Startups

Sr. GRC Engineer

Pendo · Raleigh, NC · On-site

← All jobs
About Pendo

Backed by Battery and Sapphire.

About the role

Pendo's Information Security team protects the data entrusted to Pendo and helps ensure our products are built with security and privacy by design. The team spans Security Operations, Product Security, and Compliance and Risk. With a small team and broad scope, the work directly supports the security, resilience, and trust of Pendo's products and operations.

What they're looking for

  • 3 to 5 years of hands-on security experience with demonstrated ownership of compliance programs or security operations work, rather than participation alone
  • Deep working knowledge of at least two of the following frameworks: SOC 2, ISO 27001, PCI-DSS, FedRAMP, GovRAMP, or the NIST 800-series
  • Demonstrated ability to independently own auditor relationships and manage an audit cycle end-to-end, including responding directly to auditor questions
  • Experience leading incident response investigations from triage through root cause analysis and producing post-incident documentation that engineering teams can act on
  • Demonstrated ability to translate security risk into business-risk language that enables leaders to make investment and prioritization decisions
  • Active, demonstrated use of AI tools to accelerate security workflows such as evidence collection, policy drafting, regulatory research, or detection analysis
More about this role

Pendo's Information Security team protects the data entrusted to Pendo and helps ensure our products are built with security and privacy by design. The team spans Security Operations, Product Security, and Compliance and Risk. With a small team and broad scope, the work directly supports the security, resilience, and trust of Pendo's products and operations.

The Sr. GRC Engineer is an AI-first technical leader who helps drive the evolution of Pendo's governance, risk, and compliance program. This role independently leads complex compliance, risk, and incident-response work while identifying program maturity gaps, translating security risk into business terms, and contributing to security roadmap and investment decisions. Success means building durable controls and programs that reduce risk and operational friction, not simply completing audits.

This role is based in our Raleigh office.

  • AI-driven compliance and operations acceleration: Use AI to accelerate audit evidence preparation, policy documentation, control testing workflows, and regulatory research. Evaluate GRC platform automation capabilities and integrate AI tooling where it reduces manual overhead, then document and...

Read the full posting on Pendo's site ↗

Information Security

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.