hirly

6sense

Sr. Security Assurance Engineer

United States, Remote

Apply through hirly

hirly scores this role against your resume, shows its reasoning, then writes a resume and cover letter for it and fills the application with you. Free to start — no card required.

hirly's read of this role

Seniority
Senior
Country
US
Work mode
Remote-friendly
First seen by hirly
3 Sept 2026

Derived automatically from the posting. Sign up to see how the role scores against your own resume.

the posting

Our Mission:

6sense's mission is to multiply what matters: growth, retention, and efficiency. We envision a future where companies, teams and people reach their full potential.

Our People:

People are the heart and soul of 6sense. We serve with passion and purpose. We live by our Being 6sense values of Win as One Team, Stay Curious, Do The Right Thing, Own the Outcome, and Create Belonging. Every 6sensor plays a part in defining the future of our industry-leading technology. 6sense is a place where difference-makers roll up their sleeves, take risks, act with integrity, and measure success by the value we create for our customers. We want 6sense to be the best chapter of your career.

  • Job Title:
  • Senior Security Engineer, GRC (Governance, Risk and Compliance)
  • Organizational Reporting:
  • Director, Security Assurance
  • Function/Dept:
  • Business Technology / Security

Purpose of the Job

As members of 6sense's Security department, the Governance, Risk and Compliance (GRC) team aligns Security with business objectives while managing risks and meeting industry standards, regulations and contractual obligations. GRC enforces governance, implements risk management strategies, and ensures compliance through operating as the second line of defense.

This role is the engineering capability behind that mission. Rather than testing controls after the fact, this engineer builds the systems that test them continuously. The expectation is that controls are monitored as code, technical evidence is produced automatically from AWS and other source systems, control owners can self-serve their own evidence without a GRC ticket, and AI is used as core infrastructure across GRC workflows rather than as an experiment. Audit readiness should be a byproduct of the running system, not a project.

Job Description

Responsibilities & Accountabilities

All responsibilities of GRC Security Engineer III, and;

Design, build, and own automated security control monitoring; write production-quality code (e.g., Python) under version control, peer review, and CI/CD, and treat control logic as a maintained software asset rather than a documented procedure

Convert the control library from periodic, sample-based manual testing to continuous control monitoring (CCM): define the technical signal for each control, its test frequency, pass/fail thresholds, and alerting and escalation path

Engineer self-service technical evidence collection in AWS using native services (Config, Security Hub, CloudTrail, Organizations/SCPs, IAM Access Analyzer, Systems Manager, EventBridge, Lambda, Athena/S3, CloudWatch), so control owners and auditors retrieve current evidence on demand without GRC acting as an intermediary

Eliminate manual, screenshot-based, and ticket-driven evidence collection; retire manual test procedures as automated equivalents come online and document the transition so auditors can rely on it

Redesign GRC processes to be AI-native; apply LLMs and agentic workflows to evidence review, control mapping, gap analysis, security questionnaire and customer due diligence response, policy and procedure drafting, and risk assessment triage, with explicit human-in-the-loop review, guardrails, and output validation

Maintain a single normalized control library crosswalked across frameworks (ISO 27001, SOC 2, PCI DSS, SOX, GDPR, NIST) so that one automated test satisfies multiple obligations

Build the control-failure pipeline end to end: automated detection, enrichment, ticket creation, owner routing, SLA tracking, remediation verification, and closure, including exception and risk acceptance handling where remediation is not viable

Partner with Platform Engineering, DevOps, and IT to shift controls left into preventive guardrails: service control policies, AWS Config conformance packs, policy-as-code in CI/CD, and secure-by-default infrastructure patterns

Instrument control health reporting: automation coverage, evidence freshness, control failure rates, mean time to remediate, and audit-readiness posture, surfaced in dashboards consumable by Security leadership and control owners

Lead internal and external audit engagements with automated evidence as the primary artifact; defend automated test design, sampling logic, and the completeness and accuracy of system-generated evidence to auditors and assessors

Oversee and execute complex control tests and third-party and operational security risk assessments, using tooling and AI-assisted analysis to increase coverage and reduce cycle time, and communicate results across multiple audiences with varying levels of sensitivity

Develop issue and risk treatment plans with owners and validate remediation through automated re-testing rather than manual confirmation

Set the technical bar for the team: peer review other GRC Engineers' automation, queries, and test logic, and provide feedback, guidance, and enablement so automation ownership is distributed rather than siloed

Provide GRC technology administration, including integrations, API-based data flows, and user training and enablement

Mature security governance, training and awareness programs, using automation to target and measure them

Improve GRC handbook pages, procedures, playbooks, and technical design documentation, and maintain security program controlled documents

Execute on quarterly individual Key Results that support team Objectives (OKRs)

Key Outcomes (First 12 Months)

A defined and measurable share of the control library operating under continuous monitoring, with a credible quarter-over-quarter plan to expand coverage

Technical evidence for in-scope AWS controls generated automatically and retrievable without GRC involvement

A documented reduction in audit preparation effort and evidence request turnaround time versus the prior audit cycle

At least one materially redesigned, AI-native GRC process replacing a previously manual workflow, with measured quality and throughput results

Control failures detected by the monitoring system rather than discovered during audit or assessment

Performance Measurement

Increases the percentage of controls under automated, continuous monitoring and reduces the percentage tested manually

Increases the percentage of technical evidence collected without human intervention and maintains evidence freshness against defined SLAs

Reduces mean time to detect and mean time to remediate control failures

Reduces audit and assessment preparation hours and evidence request turnaround time

Ships maintainable, reviewed, version-controlled code and infrastructure with low operational failure and false-positive rates

Demonstrates measurable adoption of self-service evidence by control owners outside of GRC

Applies AI to GRC workflows with measured accuracy, appropriate review controls, and documented decisions on where AI is and is not relied upon

Maintains up-to-date knowledge of 6sense's product, environment, systems and architecture

Drives remediation of security risks and threats

Adheres to strict deadlines and SLAs

Participates in creation of, and executes on, milestones associated with major security projects

Develops and maintains up-to-date handbook pages, runbooks, workflows, dashboards, and technical design documentation for everything they own

Provides project status updates on a weekly basis

Actively prepares for weekly 1:1s with Manager and monthly skip levels

Administers GRC technology and its integrations

Person Specification

Educational and Experience Requirements

5+ years of experience being part of a GRC or similar team

2+ years of hands-on experience building and maintaining automation, including proficiency in at least one scripting or programming language (Python preferred) and comfort working in Git, code review, and CI/CD

Demonstrated hands-on AWS experience relevant to control monitoring and evidence generation: Config, Security

Is this role actually a fit for you?

hirly answers with a score and its reasoning, then writes the resume and cover letter if you decide to go for it.

Score it against my resume
Sr. Security Assurance Engineer at 6sense — hirly