FlexHired LogoFlexHired
Logo of Engine

Engine

Senior GRC Analyst

Job Summary

The Senior GRC (Governance, Risk, and Compliance) Analyst at Engine will be responsible for managing GRC tools, overseeing compliance with standards such as SOC 2, GDPR, and CCPA, and conducting risk assessments and audits. The role involves developing security procedures, coordinating contingency planning, and ensuring vendor compliance. The ideal candidate has experience with GRC functions, security frameworks, and cloud security, along with excellent organizational and leadership skills. The position offers a competitive salary, benefits, and opportunities for growth within a fast-paced, high-growth company.

Required Skills

Compliance
Cloud Security
Risk Management
Vendor Management
Security Frameworks
Security Controls
Governance
GRC Platforms
Privacy Law
Audit Management
Data Protection
Security Concepts
Key Management
Security Procedures
Contingency Planning
Identity and Access Management (IAM)

Benefits

Equity
Remote Work Options
Bonuses
Perks
Hybrid Work Environment
Competitive Base Pay

Job Description

Join Our Journey at Engine

At Engine, we’re revolutionizing work travel. Our modern travel platform isn’t just about booking trips; it’s about transforming how businesses and their teams experience travel. From seamless booking options with top airlines, hotels, and car rental providers to single-invoice billing and flexible trip modifications, we make travel not only easier to manage but also enjoyable. Backed by powerhouse investors like Telescope Partners, Blackstone, Elefund, and Permira, we’re growing fast—and we want you to be part of it.

Engine is seeking a highly-skilled and motivated Senior GRC (Governance, Risk, and Compliance) Analyst to join our team. In this role, you will be responsible for strengthening our security posture, ensuring compliance with critical standards such as SOC 2, GDPR, and CCPA, and managing audits, risk assessments, and compliance tracking across the organization. You will work closely with senior leadership, employees, and external auditors to ensure that Engine adheres to best practices in governance, risk management, and compliance.

Your Mission:
As part of the Engine team, you’ll play a vital role in an environment where innovation meets collaboration. Here’s what you’ll take charge of:

  • Lead the configuration and management of GRC tools (Trust Centers, Learning Management Systems, Compliance Tracking, etc.) to ensure integration with security systems.
  • Manage the main dashboard for SOC 2 reporting, ensuring accuracy and compliance.
  • Develop and maintain a comprehensive risk management program and conduct risk assessments.
  • Manage and conduct regular audits (weekly, monthly, quarterly, and bi-annual) across business, IT, and security processes to ensure best practices and legal compliance.
  • Oversee the development and execution of security procedures across multiple domains.
  • Develop, update, and maintain Contingency Planning strategies and procedures, including coordination of annual tabletop drills.
  • Execute routine operational tasks related to security awareness training.
  • Audit the access and compliance of third-party vendors and contractors.
  • Review procurement requests for security standards and ensure all engagements meet company standards and regulatory requirements.
  • Collaborate cross-functionally to identify and monitor security controls, map security controls to issues and risks, and mature the audit processes related to security controls that apply across multiple security frameworks.

What You’ll Bring to Engine:
We’re looking for someone who’s ready to make an impact and grow alongside us:

  • Proven experience in managing GRC functions, ideally within a fast-paced, high-growth company.
  • Strong understanding of ISO 27001, SOC 2, GDPR, CCPA, PCI-DSS, and SOX compliance standards.
  • Excellent organizational, communication, and leadership skills.
  • Ability to manage complex GRC initiatives and work across multiple teams.
  • Ability to handle high-stress situations and effectively manage IT emergencies.
  • Skilled in using GRC platforms and tools to manage compliance and risk management activities.
  • Strong knowledge of security concepts, including risk management, identity and access management (IAM), key management, data protection, and network security.
  • Track record of building security/GRC programs across various domains.
  • Certifications such as CISA, CISM, CISSP, CRISC, or CCEP
  • Experience with data protection and privacy law compliance.
  • Familiarity with cloud security components of platforms like AWS, GCP, or Azure.
  • Excellent problem-solving, analytical, and communication skills.
  • Ability to work collaboratively with cross-functional teams, including IT, engineering, and HR teams.
  • A passion for mentoring others.
Applications for this role will be accepted through November 25, 2025 or until the role is filled. We encourage you to apply early, as we may begin reviewing applications before the deadline

Compensation
Our compensation packages are based on several factors, including your experience and expertise. In addition to a competitive base salary, total compensation may include equity and/or variable pay (OTE). Your recruiter will share your complete compensation package as you move through the process.

Base Pay Range
$140,000$190,000 USD

The Engine Edge: Perks & Compensation
We believe in rewarding great work with great benefits:

  • Compensation: Competitive base pay tied to role and experience, with opportunities for bonuses, commissions, and equity.
  • Benefits: Check out our full list at engine.com/culture.
  • Environments for Success: Different roles have different needs in terms of the environments that drive success which is why we have a hybrid-hub model. Whether you are in one of our amazing offices or fully remote, we’ll make sure you have what you need to succeed.

Perks and benefits may vary based on employment type, location, and more.

Ready to Build the Future of Work Travel?
Join us on our mission to transform how work travel works—for businesses, for travelers, and for the industry. Apply now and let’s make travel simpler, smarter, and more enjoyable—together.

Interested in this job?

Application deadline: Open until filled

Logo of Engine

Engine

Business travel, simplified. Access 750,000+ hotels at exclusive rates (average 26% savings) with no agent-assist fees or contracts. Sign up for our hotel Engine today!

See more jobs
Date PostedAugust 5th, 2025
Job TypeContract
LocationRemote - USA
Salary$140,000 - $190,000
Exciting remote opportunity (requires residency in United States) for a Senior GRC Analyst at Engine. Offering $140,000 - $190,000 (contract). Explore more remote jobs on FlexHired!

Safe Remote Job Search Tips

Verify Employer Thoroughly

Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.

Never Pay to Get a Job

Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.

Safeguard Your Personal Information

Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.

Scrutinize Communication & Interviews

Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.

Beware of Unrealistic Offers

If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.

Insist on a Formal Contract

Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.

Related Jobs

Contract
$135,000 - $180,000
Remote - USA

Subscribe Newsletter

Never miss a remote job opportunity. Subscribe to our newsletter today and receive exclusive job alerts, career advice, and industry insights delivered straight to your inbox.