SonicJobs Logo
Left arrow iconBack to search

Compliance Engineer

Gridware
Posted 5 months ago, valid for 14 days
Location

San Francisco, San Francisco 94102, CA

Salary

$120,000 - $145,000 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • Gridware, a San Francisco-based technology company focused on enhancing the electrical grid, is seeking a Compliance Engineer with 2-4 years of experience in information security compliance or a related field.
  • The role involves designing and implementing a unified control framework across multiple compliance standards, as well as managing customer-facing security assurance and audit readiness.
  • Candidates should have knowledge of frameworks such as SOC 2, ISO 27001, and NIST, along with strong communication skills for both technical and non-technical audiences.
  • The position offers a salary range of $120,000 to $145,000 per year, and applicants must be authorized to work in the country without visa sponsorship.
  • Gridware provides a range of benefits including health insurance, paid parental leave, and a unique 'Off the Grid' two-week paid break for employees.

About Gridware

Gridware is a San Francisco-based technology company dedicated to protecting and enhancing the electrical grid. We pioneered a groundbreaking new class of grid management called active grid response (AGR), focused on monitoring the electrical, physical, and environmental aspects of the grid that affect reliability and safety. Gridware’s advanced Active Grid Response platform uses high-precision sensors to detect potential issues early, enabling proactive maintenance and fault mitigation. This comprehensive approach helps improve safety, reduce outages, and ensure the grid operates efficiently. The company is backed by climate-tech and Silicon Valley investors. For more information, please visit www.Gridware.io.


Role Description

We are building our information security compliance program and this role sits at the center of that effort. As our Compliance Engineer, you will work directly with the Head of Information Security to design, implement, and operationalize controls across multiple frameworks (SOC 2, ISO 27001, NIS 2, CIS IG3, NERC CIP, and NIST). You will also own customer-facing security assurance, including security questionnaires and audit evidence requests. 

 

This is a high-visibility role for someone energized by building structure in ambiguous environments and who understands that good compliance is good engineering. 

\n


Responsibilities
Framework Implementation & Control Management
  • Design a unified control framework mapped across SOC 2, ISO 27001, CIS IG3, NERC CIP, and NIST (CSF/800-53), eliminating duplication and creating a single source of truth for compliance posture. 
  • Develop and maintain a control library, policy inventory, and risk register. 
  • Translate technical control requirements into actionable guidance for engineering, IT, and operations teams. 
Audit Readiness & Evidence Collection
  • Build a structured, repeatable evidence collection process supporting concurrent audits across all frameworks. 
  • Maintain a continuously updated evidence repository and coordinate with Engineering, DevOps, HR, and Legal to gather and validate artifacts. 
  • Serve as primary liaison with external auditors; manage schedules, fieldwork, and findings remediation through to closure. 
Customer Security Assurance
  • Own intake, triage, and completion of customer security questionnaires (SIG Lite, CAIQ, custom assessments). 
  • Maintain a living questionnaire knowledge base and develop customer-facing security documentation, including trust portal content. 
Program Development
  • Define compliance workflows, SOPs, tooling requirements, and automation opportunities as the program matures. 
  • Monitor regulatory changes across NERC CIP, NIS 2, and NIST; proactively communicate impacts to the team. 


Required Skills
  • 2–4 years in information security compliance, GRC, or a related discipline. 
  • Working knowledge of two or more: SOC 2, ISO 27001, NIST CSF/800-53, CIS Controls, NERC CIP. 
  • Experience supporting or leading external audits, including evidence collection and auditor coordination. 
  • Ability to perform cross-framework control mapping and identify gaps or conflicts. 
  • Strong written communication skills across technical and non-technical audiences. 


Bonus Skills
  • Hands-on experience with NERC CIP (CIP-002 through CIP-014) in an OT or critical infrastructure environment. 
  • Familiarity with GRC platforms such as Vanta, Drata, OneTrust, or Archer. 
  • Certifications: CISA, CRISC, ISO 27001 Lead Implementer/Auditor, or NERC CIP. 


\n
$120,000 - $145,000 a year
\n

**At this time, Gridware is unable to provide visa sponsorship or immigration support for this role. We’re only able to consider candidates who are currently authorized to work in the country of employment without visa sponsorship now or in the future.**


This describes the ideal candidate; many of us have picked up this expertise along the way. Even if you meet only part of this list, we encourage you to apply!


Benefits

Health, Dental & Vision (Gold and Platinum with some providers plans fully covered) 

Paid parental leave 

Alternating day off (every other Monday)

“Off the Grid”, a two week per year paid break for all employees. 

Commuter allowance 

Company-paid training 




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.