6sense Senior Security Engineer, GRC at 6sense responsible for designing and building automated security control monitoring systems. Convert manual testing to continuous control monitoring and engineer self-service evidence collection in AWS.
Responsibilities
All responsibilities of GRC Security Engineer III, and;
Design, build, and own automated security control monitoring; write production-quality code (e.g., Python) under version control, peer review, and CI/CD, and treat control logic as a maintained software asset rather than a documented procedure
Convert the control library from periodic, sample-based manual testing to continuous control monitoring (CCM): define the technical signal for each control, its test frequency, pass/fail thresholds, and alerting and escalation path
Engineer self-service technical evidence collection in AWS using native services (Config, Security Hub, CloudTrail, Organizations/SCPs, IAM Access Analyzer, Systems Manager, EventBridge, Lambda, Athena/S3, CloudWatch), so control owners and auditors retrieve current evidence on demand without GRC acting as an intermediary
Eliminate manual, screenshot-based, and ticket-driven evidence collection; retire manual test procedures as automated equivalents come online and document the transition so auditors can rely on it
Redesign GRC processes to be AI-native; apply LLMs and agentic workflows to evidence review, control mapping, gap analysis, security questionnaire and customer due diligence response, policy and procedure drafting, and risk assessment triage, with explicit human-in-the-loop review, guardrails, and output validation
Maintain a single normalized control library crosswalked across frameworks (ISO 27001, SOC 2, PCI DSS, SOX, GDPR, NIST) so that one automated test satisfies multiple obligations
Build the control-failure pipeline end to end: automated detection, enrichment, ticket creation, owner routing, SLA tracking, remediation verification, and closure, including exception and risk acceptance handling where remediation is not viable
Partner with Platform Engineering, DevOps, and IT to shift controls left into preventive guardrails: service control policies, AWS Config conformance packs, policy-as-code in CI/CD, and secure-by-default infrastructure patterns
Instrument control health reporting: automation coverage, evidence freshness, control failure rates, mean time to remediate, and audit-readiness posture, surfaced in dashboards consumable by Security leadership and control owners
Lead internal and external audit engagements with automated evidence as the primary artifact; defend automated test design, sampling logic, and the completeness and accuracy of system-generated evidence to auditors and assessors
Oversee and execute complex control tests and third-party and operational security risk assessments, using tooling and AI-assisted analysis to increase coverage and reduce cycle time, and communicate results across multiple audiences with varying levels of sensitivity
Qualification
Big 4 (KPMGBachelor's degree in a related fieldRelevant industry certificationsCompetencies and Behaviors
Preferred
Experience with infrastructure as code (Terraform, CloudFormation) and policy-as-code (OPA/Rego, AWS Config custom rules, cfn-guard, or similar)
Experience implementing or operating continuous control monitoring at scale in a SaaS or multi-account cloud environment
Experience integrating GRC or compliance automation platforms via API rather than through the UI
Experience building internal self-service tooling used by engineers or control owners
Big 4 (KPMG, Deloitte, PwC, EY) or similar experience
Bachelor's degree in a related field
Relevant industry certifications, such as CISSP, CISM, GIAC, AWS Certified Security – Specialty, or CCSK/CCSP, are highly desirable