Backed by Insight.
About the role
Smartsheet maintains certifications and attestations across SOC 2 Type II, the ISO 27001/27017/27701/22301 suite, HIPAA, and other commercial compliance frameworks—and the manual work of proving those controls quarter after quarter doesn't scale with the business. We're looking for a Sr. Security Engineer I to bring an engineering mindset to our commercial GRC program: automating control monitoring, building evidence pipelines, and reducing the audit-season scramble into a default state of readiness.
What they're looking for
- 4+ years of experience in GRC engineering, security engineering, compliance automation, or IT audit support, with hands-on ownership of at least one full certification cycle (SOC 2, ISO 27001, or similar)
- Experience with cloud security fundamentals (AWS/GCP/Azure IAM, logging, encryption) and how they map to control requirements
- Solid working knowledge of SOC 2, ISO 27001 (and ideally 27017/27701), and HIPAA control requirements, and the ability to map controls across frameworks to avoid duplicated evidence work
- Comfort with scripting or light development (Python, JavaScript, or similar) to build integrations, automate evidence pulls via API, or extend GRC tooling
- Strong written communication, you can document a control, a gap, and a remediation plan clearly enough that an external auditor and an internal engineer both understand it
- A stakeholder-centric mindset: you measure success by how easy it is for engineers to stay compliant, not just by how quickly GRC can produce evidence
More about this role
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day.
Smartsheet maintains certifications and attestations across SOC 2 Type II, the ISO 27001/27017/27701/22301 suite, HIPAA, and other commercial compliance frameworks—and the manual work of proving those controls quarter after quarter doesn't scale with the business. We're looking for a Sr. Security Engineer I to bring an engineering mindset to our commercial GRC program: automating control monitoring, building evidence pipelines, and reducing the audit-season scramble into a default state of readiness. You'll work hands-on with our GRC platform, cloud, and identity tooling to make control evidence collect itself wherever possible, and you'll partner closely with engineering teams to translate compliance requirements into technical...
Browse similar: Startup jobs