Box
GRC Controls Automation Engineer
About this role
Box seeks an experienced GRC Controls Automation Engineer to modernize compliance frameworks and embed security controls directly into the software development lifecycle. You'll design automated solutions across multiple regulatory standards while collaborating with cross-functional teams to improve processes and maintain Box's compliance posture.
What you'll do
- Design and implement automated compliance controls focused on embedding security into SDLC processes
- Provide compliance guidance on new product features, infrastructure changes, and deviations
- Assess security and compliance posture across multiple frameworks (ISO, PCI, NIST, SOC 2) and recommend improvements
- Support audit activities by maintaining accurate process documentation and identifying compliance gaps
- Coordinate cross-functional meetings to remediate control gaps and communicate issues to management
- Participate in cloud and application security strategic planning and execution
What they're looking for
- GRC and controls automation
- Regulatory frameworks (NIST 800-53, PCI, ISO 27x, SOC 2)
- GCP cloud computing
- Data governance and model validation
- Security and compliance assessment
- Cross-functional communication and stakeholder management
- Process improvement and standardization
- AI architecture familiarity
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Box
Box builds cloud-native infrastructure and content management platforms, operating large-scale backend services, Kubernetes-based systems, and edge networking solutions. The company is hiring senior engineers to design and operate mission-critical infrastructure systems, as well as solutions engineers to drive sales and technical implementations with SMB and mid-market customers.
- Website
- box.com
Likely interview questions
- Describe a time you embedded compliance controls into a software development process and how you measured effectiveness.
- How would you approach modernizing existing GRC processes at a SaaS company operating under multiple regulatory frameworks?