TherapyNotes, LLC Logo

TherapyNotes, LLC

GRC Engineer

Reposted Yesterday
Remote
Hiring Remotely in United States
100K-140K Annually
Mid level
Remote
Hiring Remotely in United States
100K-140K Annually
Mid level
The GRC Engineer will handle risk assessments, automate GRC processes, maintain policies, and support compliance frameworks while collaborating with security teams.
The summary above was generated by AI

About Us

TherapyNotes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth, and more so clinicians can focus on awesome patient care.

We're a dynamic team of pros who love to innovate and push the envelope, keeping our software cutting-edge. Join us, and let's revolutionize behavioral health software together while making a real difference!

About The Position

TherapyNotes is seeking a GRC Engineer who combines strong foundational GRC expertise with the ability to design and implement scalable, automated solutions. This role is responsible for both executing core GRC functions (e.g., risk assessments, policy management, third-party risk) and transforming those processes through engineering and automation.

The ideal candidate understands how GRC work is performed today—and has the technical skills to improve, scale, and modernize it.

What You'll Do

Core GRC Operations (Hands-On Execution)

  • Conduct third-party risk assessments (TPRM), including vendor reviews, security questionnaires, and risk evaluations
  • Maintain and update security policies, standards, and procedures
  • Support compliance initiatives across frameworks (SOC 2, ISO 27001, HIPAA, NIST, etc.)
  • Perform internal risk assessments, control testing, and gap analyses

GRC Engineering & Automation

  • Identify manual, repetitive GRC processes and design automated solutions
  • Build and maintain automated evidence collection (via APIs, scripts, and integrations)
  • Implement continuous control monitoring (CCM) to replace point-in-time audits
  • Translate compliance requirements into technical controls and system configurations
  • Validate control effectiveness through automated testing and monitoring
  • Enable real-time or near-real-time risk visibility through dashboards and reporting systems
  • Work with Security Engineering to continuously audit configurations and remediate drift programmatically
  • Build scalable workflows for vendor risk assessments, re-assessments and tracking
  • Integrate vendor data into centralized risk systems
  • Automate intake, review, and monitoring processes for third-party security posture
  • Develop self-service audit evidence systems and dashboards
  • Partner with auditors to provide API-driven or system-generated evidence

What We're Looking For

  • Bachelor’s degree in Computer Science, Engineering, or related field (or equivalent experience)
  • 3–6+ years in security engineering, GRC, GRC engineering, or cloud security roles
  • Strong experience with scripting/programming (Python, Go, or similar)
  • Hands-on experience with cloud platforms (AWS, Azure, or GCP)
  • Familiarity with Infrastructure as Code (Terraform, CloudFormation, etc.)
  • Deep understanding of security controls and how they map to compliance frameworks
  • Experience integrating APIs and building automation pipelines

Bonus Points

  • Experience with policy-as-code tools
  • Experience with GRC automation platforms
  • Familiarity with SIEM, SOAR, and security telemetry systems
  • Experience building internal tools or platforms for compliance and risk management
  • Certifications such as CISSP, CISM, CRISC, or cloud security certifications

What We Offer

  • Competitive salary - $100,000-$140,000
  • Employer sponsored health, dental, vision, life, and disability insurance
  • Retirement plan with company contribution
  • Annual company profit sharing
  • Personal development/training budget
  • Open, collaborative work environment
  • Extensive 2-week onboarding plan
  • Comprehensive mentorship program

Similar Jobs

8 Days Ago
Remote
USA
116K-213K Annually
Senior level
116K-213K Annually
Senior level
Kids + Family • Mobile
The Senior GRC Engineer at Life360 will lead governance frameworks, ensuring compliance with regulations, and utilize AI tools for automating control processes and evidence collection, while managing security risks and maintaining relationships across departments.
Top Skills: Ai ToolsApi IntegrationGitIso 27001Nist CsfPythonSoc 2
11 Days Ago
Remote
USA
130K-150K Annually
Senior level
130K-150K Annually
Senior level
Hardware • Machine Learning • Security • Software
The Senior GRC Engineer will design and implement automated governance, risk, and compliance systems, integrating security in cloud environments and collaboration across teams to enhance compliance processes and risk measurement.
Top Skills: AIAWSCi/CdCloudFormationLlmsTerraform
15 Days Ago
Remote
United States
Senior level
Senior level
Artificial Intelligence • Information Technology • Software
As a Sr. GRC Engineer, you will lead and manage CMMC compliance projects, develop documentation, guide clients in assessments, and mentor a team to meet cybersecurity standards in defense contracting.
Top Skills: Aws GovcloudAzure GovernmentCmmcFedrampGcc HighNist 800-171Nist 800-53

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account