Why this grade This listing scored 73/100, which is a B. It lost the most ground on pay transparency. See the breakdown
- Description depth 20 / 20 How much the posting actually says about the work, measured in characters of real text.
- Freshness 15 / 15 How recently it was posted. Older postings are likelier to be filled or abandoned.
- Remote clarity 15 / 15 Whether "remote" means anywhere, or is quietly restricted to one country.
- Pay transparency 12 / 25 A published salary range, worth more than any other single factor because it is what a candidate cannot find out without applying.
- Role specificity 6 / 10 Whether the listing is tagged well enough to tell what the role actually is.
- Corroboration 5 / 10 Whether more than one source carries this listing.
Every figure above is arithmetic over the posting itself — its salary field, its text, its age, its tags and how many sources carry it. How the grades work →
This listing does not state a salary
$112k – $155k
That is the middle half of what comparable roles paid on this board over the last 90 days — 50 listings that did publish a figure, median $136k. It is not this employer's offer, and we have no idea what they pay. It is only what the rest of the market advertised.
react llm
About Clerk
Clerk is on a mission to solve the user identity layer once and for all. We are a globally distributed team dedicated to providing best-in-class developer infrastructure to build the next generation of AI software. Today, we provide developers with full-stack React components and hooks like , , , useUser, and useOrganization. These APIs allow developers to build hard-to-get-right infrastructure for user identity, organization management and billing flows. We believe that a component is worth a thousand APIs.
Clerk is looking for a Senior GRC Engineer to join our Security Team. Our customers put Clerk in the middle of their authentication flow, and every one of them runs us through their own vendor review before they do. You'll own the program that makes that review easy: the controls, the evidence, the audits, and the answers.
You'll work as a hands-on engineer. Expect to spend a lot of your time writing integrations, automations, and internal tools that enforce policies and automate the evidence gathering. The goal is a program that's always current, so an audit is just someone observing it rather than a quarterly scramble.
What you'll do
Own SOC 2 Type II and HIPAA end to end: scoping, control design, evidence, auditor walkthroughs, and remediation
Scope and lead our next framework (ISO 27001 is the likely candidate) based on what customers actually ask for
Build and maintain the integrations that feed our GRC platform from our cloud providers, SaaS tools, and internal systems
Turn controls into continuous checks: policy-as-code, config drift detection, and a control-failure pipeline from detection to closure
Run the vendor security review program, from intake to periodic re-review
Own the security questionnaire and trust center workflow
Maintain the risk register and run risk assessments that produce documented decisions
Embed compliance requirements into the SDLC and change management so they're enforced by tooling, not by reminders
Reduce the number of things a human has to do to pass an audit every quarter
Who you are
5+ years in security, with demonstrated experience building automation for a GRC or compliance program
You've been the technical owner of at least one SOC 2 Type II or ISO 27001 audit and can tell us what you would do differently
You write code, and you use LLMs to get more done without lowering the bar
Hands-on with a GRC platform's API, not just its dashboard
Cloud IAM and configuration depth on at least one provider, GCP preferred
You can decide what evidence is sufficient and defend an automated test to an auditor
Comfortable being one of a few security engineers; you can scope, prioritize, and ship without a lot of process around you
Clear writer: policies, control narratives, and questionnaire answers are read by customers, so they have to be good
Nice-to-haves
Experience at an all-remote company
Shipped LLM or agentic workflows in production for compliance work
Experience at a developer-tools company
Benefits
Competitive Salary – We want you to know that we value the skills and experience you bring to the table. We go out of our way to make sure that you feel fairly compensated.
Equity Ownership – At Clerk, we believe in shared success. That's why we offer a stock option plan so that everyone can benefit from the growth and prosperity of the company.
Health Coverage – We care about your well-being. That's why we offer top-tier health insurance to ensure that your health needs are fully met.
Work Gear - Set up your ideal home office with the gear of your choice. At Clerk, we want to ensure that you have everything you need to perform at your best.
Flexible Vacation Policy – We believe in work-life balance and trust you to take the time you need. Although we recommend 25 days per year, our vacation policy is unlimited. This is in addition to observing national holidays specific to your country of residence.
Diverse and Inclusive Team – Join our exceptional, diverse, and globally distributed team at Clerk. We are committed to fostering an inclusive environment where everyone can contribute their best in building impactful products and tools for the modern web.
Apply for this role Opens jobs.ashbyhq.com — verified as the employer's own application page
Quick question · anonymous · one tap
Would you apply to this job?
Answer to see what other job seekers said.
Keep looking
Similar remote roles, still open
-
C
4h ago
Werkstudent (m/w/d) Schwachstellenmanagement: Von der SBOM zur Entscheidung
Langlauf Security Automation GmbH Lippstadt
-
C
20h ago
Senior Security Engineer, Identity and Access Management
HackerOne Netherlands, UK, USA
- D 17h ago
- C 1d ago
See every "GRC Engineer" role →
Get new “GRC Engineer” roles by email
One email a day with what is new in "GRC Engineer". Nothing new, no email.
We confirm the address first, and every mail carries an unsubscribe link. Alerts are ours, not a third party's.
Your turn · no account needed
Help the next applicant
You may know something about this listing that we cannot see from here. One tap. No account needed. Signed-in reports earn points once the evidence agrees with you.
I know what it pays
Sign in with Google to earn points for reports — 100 confirmed points buy a week of Early Access.
Where this listing came from
- 26 Sep 2026 Real Work From Anywhere first sighting
Seen on 1 board over 12 days. The employer edited the description 1× since we first recorded it.