Box
GRC Controls Automation Engineer
About this role
Box seeks a GRC Controls Automation Engineer to modernize compliance frameworks and embed security directly into the software development lifecycle. You'll design scalable automation solutions, bridge regulatory requirements with technical infrastructure, and communicate Box's compliance posture across the organization.
What you'll do
- Design and implement automated compliance controls aligned with NIST, ISO, PCI, and SOC 2 frameworks
- Drive process improvements and develop innovative solutions to embed compliance into SDLC
- Provide compliance guidance on new product features, infrastructure changes, and security posture assessments
- Support cloud and application security strategic planning and maintain audit documentation
- Identify compliance gaps, coordinate cross-functional remediation efforts, and monitor ongoing compliance
- Build relationships with internal and external stakeholders while communicating compliance requirements vertically and horizontally
What they're looking for
- GRC and compliance frameworks (NIST 800-53, ISO 27x, PCI, SOC 2, AICPA)
- Cloud computing (GCP preferred)
- Security and data governance
- Process automation and optimization
- Technical communication and stakeholder management
- AI architectures and model validation understanding
- Audit support and documentation
- Cross-functional collaboration
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Box
Box builds cloud-native infrastructure and content management platforms, operating large-scale backend services, Kubernetes-based systems, and edge networking solutions. The company is hiring senior engineers to design and operate mission-critical infrastructure systems, as well as solutions engineers to drive sales and technical implementations with SMB and mid-market customers.
- Website
- box.com
Likely interview questions
- Describe your experience designing compliance controls within a SaaS environment and how you've embedded them into the SDLC.
- How have you approached automating compliance monitoring across multiple frameworks like ISO 27001, PCI, and SOC 2?