- Salary
- $86k – $103k
- Location
- Saint Louis Support Center, United States of America
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Engineering
- Experience
- 5+ years
- Education
- Bachelor
- Source
- Workday
Description
Position Summary
The Sr. Information Security GRC Engineer serves as the operational owner for the organization's regulatory compliance, which includes PCI, Information Technology Audit Management, Third-Party service provider oversight, and security-related data privacy programs. This role is responsible for ensuring the organization maintains a strong compliance posture, remains audit-ready, meets regulatory and contractual obligations, and effectively manages security risks through governance and oversight.
As a senior individual contributor, this position drives outcomes through influence, collaboration, and accountability rather than direct authority. The role partners closely with Information Security, Technology, Legal, Privacy, Internal Audit, Procurement, HR, Marketing, and business stakeholders to coordinate assessments, manage audits, oversee remediation efforts, and strengthen the organization's overall security governance framework.
Success in this role is measured by successful audit outcomes, reduction of repeat findings, timely remediation of identified risks, and the ability to make compliance processes efficient, predictable, and business enabling.
Location: St. Louis, MO (hybrid)
Essential Responsibilities
Regulatory Compliance Program Ownership
- Serve as the operational owner for security regulatory compliance activities, including monitoring applicable legal, regulatory, contractual, and industry requirements and translating them into actionable security and compliance obligations.
- Maintain compliance mappings, control inventories, evidence repositories, and assessment documentation across applicable frameworks and standards.
- Conduct compliance assessments and gap analyses, coordinate remediation efforts, and maintain a centralized tracker for regulatory, PCI, audit, and third-party findings throughout the mitigation lifecycle.
- Provide guidance to business and technology teams regarding compliance requirements and support responses to regulatory inquiries, assessments, and examinations.
PCI Compliance Program Ownership
- Coordinate the organization's PCI compliance program, including assessment readiness, evidence collection, control validation, stakeholder coordination, and remediation management.
- Partner with business and technology teams to maintain PCI documentation, support annual assessments, monitor control effectiveness, and drive continuous improvement of PCI-related controls and processes.
Audit Management & Assurance
- Serve as the operational owner for security audit activities, including internal audits, external audits, customer assessments, and regulatory reviews.
- Coordinate audit planning, evidence collection, stakeholder engagement, audit responses, corrective action plans, and remediation activities.
- Maintain audit readiness by ensuring required documentation, evidence, and controls remain current, supportable, and aligned to regulatory and business requirements.
Risk Management
- Conduct cybersecurity risk assessments across technology platforms, business processes, third parties, cloud environments, and emerging technologies.
- Maintain security risk registers and issue management processes while partnering with stakeholders to evaluate risks, validate controls, and implement mitigation strategies.
- Monitor and report significant compliance and cybersecurity risks, trends, and remediation progress to leadership.
Privacy & Data Governance Partnership
- Partner with Privacy, Legal, HR, Marketing, and Technology teams to support privacy, data protection, and information governance initiatives.
- Participate in privacy impact assessments, data protection reviews, and governance activities related to data classification, retention, acceptable use, AI governance, and emerging technology risks.
- Evaluate security and compliance risks associated with personal, confidential, and sensitive information and recommend appropriate safeguards.
Third-Party Security Compliance
- Coordinate security compliance reviews and risk assessments for vendors, service providers, and strategic partners.
- Review System and Organization Controls (SOC) reports, certifications, attestations, questionnaires, contracts, and other due diligence documentation.
- Partner with Procurement, Legal, and business stakeholders to identify third-party risks, manage remediation efforts, and monitor ongoing compliance obligations throughout the vendor lifecycle.
Metrics, Reporting & Program Management
- Develop and maintain security compliance metrics, dashboards, and key performance indicators that measure program effectiveness and organizational maturity.
- Provide executive-level reporting on compliance posture, audit results, regulatory obligations, risk trends, and remediation progress.
- Support executive leadership, audit committees, and regulatory reporting requirements while identifying opportunities for continuous improvement across governance and compliance programs.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, Business Administration, Accounting, Audit, or a related field.
- 5+ years of experience in Information Security, Governance, Risk Management, Compliance, Audit, Privacy, or related disciplines.
- Experience coordinating security audits, assessments, compliance programs, or governance initiatives involving multiple stakeholders.
- Experience conducting security and compliance assessments and driving remediation activities through completion.
- Experience interpreting regulatory requirements and mapping them to technical, administrative, and operational controls.
- Strong understanding of security governance principles, risk management methodologies, and security control frameworks.
- Demonstrated ability to influence outcomes and drive accountability without direct authority.
- Strong project management, organizational, analytical, and problem-solving skills.
- Excellent written, verbal, and presentation skills.
- Ability to manage multiple priorities in a fast-paced environment.
Success Measures
- Successful completion of PCI, internal, external, customer, and regulatory audits.
- Timely closure of audit findings, compliance gaps, and risk remediation activities.
- Reduction of repeat audit findings and recurring control deficiencies.
- Effective maintenance of security policies, standards, governance processes, and compliance documentation.
- Improved organizational compliance maturity and audit readiness.
- Accurate, meaningful, and actionable executive reporting.
- Continuous reduction of security and compliance risks through proactive assessment and remediation.
- Strong partnerships with Legal, Privacy, Internal Audit, Procurement, Technology, HR, Marketing, and business stakeholders.
The actual pay offered will be determined by multiple factors, including but not limited to the candidate’s relevant experience, job-related knowledge, skills, and geographical location. Individual compensation decisions are dependent upon the facts and circumstances of each position and candidate.
Saint Louis Support Center