Commercial GRC Engineer - Sr. Security Engineer I
About this role
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day.
Smartsheet maintains certifications and attestations across SOC 2 Type II, the ISO 27001/27017/27701/22301 suite, HIPAA, and other commercial compliance frameworks—and the manual work of proving those controls quarter after quarter doesn't scale with the business. We're looking for a Sr. Security Engineer I to bring an engineering mindset to our commercial GRC program: automating control monitoring, building evidence pipelines, and reducing the audit-season scramble into a default state of readiness. You'll work hands-on with our GRC platform, cloud, and identity tooling to make control evidence collect itself wherever possible, and you'll partner closely with engineering teams to translate compliance requirements into technical control logic they can actually build against. This is a builder's role within GRC—less checklist administration, more systems thinking applied to compliance. Our approach is grounded in GRC Engineering principles: automate early and often, treat controls and their mappings as code, favor continuous assurance over periodic checks, and build compliance that engineers can consume as easily as they contribute to it.
This role reports to the Senior Director, GRC Engineering and can be based in our Bellevue, WA office or remotely from anywhere in the US where Smartsheet is a registered employer.
You Will:
• Own control automation for SOC 2, ISO 27001/27017/27701, HIPAA, and related commercial frameworks: design and build automated evidence collection and continuous control monitoring across cloud, identity, endpoint, and SaaS systems. • Express controls, control tests, and cross-framework mappings as version-controlled code so they are reviewable, testable, and reusable rather than locked in a single tool's configuration. • Translate compliance requirements into technical control logic, workflows, and integrations, partnering with engineering, IT, and security teams to embed controls into existing systems and pipelines rather than bolting them on after the fact. • Shift compliance left by participating in architecture and design reviews, defining control requirements as acceptance criteria for new systems, and helping teams build compliant-by-default infrastructure. • Design the engineer-facing experience of compliance: self-service control status, guardrails and paved-road patterns, and compliance feedback delivered in the tools teams already use (CI/CD, Jira, Slack) rather than only in the GRC platform. • Evaluate whether controls actually reduce relevant risk—not just whether they exist—and propose alternative controls when a framework default doesn't fit our threat model or workload architecture. • Support full audit cycles end-to-end: coordinate evidence requests, populate and maintain the evidence library, respond to auditor follow-ups, and track remediation items through closure for SOC 2, ISO, and HIPAA assessments. • Build and maintain dashboards and reporting that give GRC and security leadership real-time visibility into control health, evidence freshness, and audit readiness across frameworks. • Identify and eliminate duplicate evidence-gathering effort across overlapping frameworks by mapping controls once and reusing that mapping across SOC 2, ISO, and HIPAA. • Diagnose the root causes of recurring control failures or stale evidence and fix the underlying process, tooling, or ownership gap rather than the symptom. • Partner with the GRC Team Lead and SATellite engineering to extend our internal GRC platform's control, evidence, and risk-lifecycle capabilities.