Life360 logo
Life360

Life360 is an award-winning, San Francisco, California-based family network app that allows families to share their location and collaborate and communicate wit

Senior GRC Engineer

Location

United States

Posted

18 days ago

Salary

$115.5K - $213K / year

Seniority

Senior

Bachelor Degree5 yrs expEnglishCloudPython

Job Description

Senior GRC Engineer

Life360

• Own the governance framework for Life360's agentic systems. The major compliance frameworks are still figuring out how to account for autonomous agents. Define the policies, control sets, and compliance posture that govern how agents are built and deployed at Life360 — and build ahead of the regulation. • Take an agentic approach to GRC itself. Automate evidence collection, draft control narratives, triage vendor questionnaires — use AI and internal tooling to do the work humans shouldn't be doing manually. Write the integrations and pipelines that make it real. Know where AI creates leverage, where it introduces risk, and where a human needs to stay in the loop. • Build the policy program as code. Policies in Git, peer-reviewed via pull request. Requirements expressed as enforceable rules and automated checks, not static PDFs. A common controls framework that satisfies SOC 2, ISO 27001, NIST CSF, and future frameworks from a single control reference — no rework. • Drive SOC 2 Type 2, ISO 27001, and SOX ITGC end-to-end as management owner — managing evidence, coordinating with external assessors, and closing gaps before auditors find them. Build the automation once; satisfy three frameworks. • Build an operational risk function, not a register. Quantitative-leaning, FAIR-informed, and connected to live data sources across cloud security posture, endpoint detection, vulnerability management, and asset inventory. Risk scoring that reflects current reality and is actionable at every altitude — service owner to board executive leadership, with Audit Committee reporting on enterprise risk coordinated with Internal Audit. Build the data model, workflow layer, and closed loop that turns risk from a prioritization exercise into a lifecycle with owners and treatment decisions. • Mature the TPRM program. Tiered reviews by risk and data sensitivity. Automated evidence collection and agent-based workflows that reduce friction for vendors and internal teams alike — making it easier to do this right than to skip it. • Be the auditor's primary management contact. Own scoping, walkthroughs, evidence delivery, and management responses for SOC 2, ISO 27001, and SOX ITGC. Auditors leave knowing more about how Life360 actually works than they did when they walked in — and findings get closed before they become repeat findings. • Build the cross-functional relationships that make GRC work in practice. Engineering, Legal, Privacy, Internal Audit and Procurement are all load-bearing parts of this program — own those partnerships and build the workflows that make compliance a shared practice, not a security team deliverable. • Maintain clear role boundaries between management’s first- and second-line GRC operations and Internal Audit’s third-line independent assurance.

Job Requirements

  • 5+ years in GRC, security engineering, or a hybrid role where you owned both the policy and control side and the technical implementation — not one or the other.
  • You build with AI tools, not just use them. You've used LLMs and agents in real work — drafting, code, automation, investigation — and can make judgment calls about where AI creates leverage and where it introduces risk. Experience designing or operating agentic workflows is a strong signal.
  • Coding ability that ships. Python or equivalent — you can call APIs, build integrations, schedule jobs, and deploy a working pipeline without help. Show us something you built.
  • You can evidence controls directly in cloud environments — identity, audit logs, configuration posture, secrets management — without relying on screenshots or system owners. You pull evidence from APIs.
  • You've implemented, integrated, or significantly extended a modern GRC platform. You know what these platforms actually solve, where they fall short, and when to write your own code instead.
  • SOC 2, ISO 27001, and NIST AI RMF at the control level, not just the headers. You understand how these frameworks are evolving to account for AI and agentic systems.
  • You've worked through SOX ITGC cycles at a public company — managing evidence, walkthroughs, and findings with external auditors.
  • Built or scaled a TPRM program — you've designed tiering, pushed back on bad vendors, and automated parts of the assessment workflow.
  • Quantitative risk experience — you've owned a risk register and made it useful to engineers and executives. FAIR or equivalent methodology in real use is a strong signal.
  • Clear writing — policies, control narratives, audit responses, and risk statements that engineers and lawyers both understand.
  • Bachelor's degree or equivalent.

Benefits

  • Competitive pay and benefits
  • Medical, dental, vision, life and disability insurance plans (100% paid for employees)
  • 401(k) plan with company matching program
  • Mental Wellness Program & Employee Assistance Program (EAP) for mental well-being
  • Flexible PTO, 13 company-wide days off throughout the year
  • Winter and Summer Weeklong Synchronized Company Shutdowns
  • Learning & Development programs
  • Equipment, tools, and reimbursement support for a productive remote environment
  • Free Life360 Platinum Membership for your preferred circle
  • Free Tile Products

Related Categories

Related Job Pages

More Compliance Jobs

Flywire logo

Compliance Manager

Flywire

Delivering the most important & complex payments.

Compliance18 days ago
Full TimeRemoteTeam 1,001-5,000Since 2011H1B Sponsor

• Monitoring relevant Canadian regulatory developments, particularly as they relate to payments regulation, consumer protection, money service business and fintech laws generally; • Supporting the Global Payments team on ongoing bank and payment partner management, including explaining our global Legal, Compliance and Regulatory framework and conducting onsite visits if needed; • Assisting with analysis and introduction of new products and services; • Managing Canadian Regulator and Law Enforcement relationships and interactions, if any; • Reviewing the regulatory environment for Flywire’s suite of services, determining if licensure or additional permissions are required or an exemption applies (and under what circumstances); • Building and maintaining needed Canadian AML/CTF programs, policies and procedures; • Assisting the Global AML/CTF compliance operations team, including sanctions screening, transaction monitoring, fraud monitoring and KYC; • Managing the regulatory reporting (EFTR, STR) and response process, by ensuring clear allocation of responsibilities for regularly scheduled and ad hoc filings, and maintaining a repository of prior filings and information used to respond to regulatory inquiries or consultations; • Coordinate and develop presentations, responses and reporting to management, regulators, clients, FI Partners and governing bodies, as required; • Assist with development of internal communications, presentations, and training materials; • Conducting regulatory reviews and due diligence on potential business acquisition targets, as required; • Maintain documentation on regulatory requests supported and responses provided; • Support additional Risk Governance projects and initiatives as needed; • Support global artificial intelligence development as it relates to AML/CTF and sanctions regulations • Drive and own the regulatory compliance aspects of our business in Canada and advise on AML regulations; • Localize and administer an AML/CFT compliance program and maintain a risk assessment to comply with applicable local requirements -- including transaction monitoring functions; • Work on various projects and miscellaneous issues both in Canada and globally such as partner KYC audits, client onboarding, and product enhancements; • Create insights on regulatory and supervisory topics for effective business response and mature risk governance practices

Canada
$140K - $150K / year
Gympass logo

Reporting, Compliance Specialist

Gympass

Bringing movement to the world, one employee at a time.

Compliance18 days ago
Full TimeRemoteTeam 1,001-5,000Since 2012H1B Sponsor

Reporting/Compliance Specialist Remote locations Salt Lake City, UT Chicago, IL Boise, ID Phoenix, AZ Seattle, WA time type Full time   Our people at JLL are shaping the future of real estate for a better world by combining world class services, advisory and technology for our clients. We are committed to hiring the best, most talented people and empowering them to thrive, grow meaningful careers and to find a place where they belong.  Whether you’ve got deep experience in commercial real estate, skilled trades or technology, or you’re looking to apply your relevant experience to a new industry, join our team as we help shape a brighter way forward.    The selected candidate must reside in the US and reside within the Central, Mountain, or Pacific Time Zone   What this job involves: The Reporting/Compliance Specialist provides critical support to Integrated Facilities Management clients and internal stakeholders by optimizing JLL managed services operations and sourcing strategies, with primary responsibility for managing procurement compliance and establishing comprehensive procurement metrics, reporting, and compliance tracking programs. You'll serve as the steward of data quality and integrity across all procurement-related systems on the account, establishing data entry standards, validation rules, and quality control processes while regularly auditing systems to identify and resolve discrepancies that could compromise reporting accuracy. The position requires you to design and launch the procurement metrics and compliance reporting program from the ground up, defining key performance indicators focused on compliance status, spend performance, supplier metrics, and risk exposure while developing scalable reporting frameworks. You'll own and administer the account's sourcing request intake and tracking tool in Smartsheet, proactively monitoring all requests to identify and address stagnating items by engaging with stakeholders to drive resolution. The role combines deep analytical capabilities with compliance oversight, requiring you to analyze large datasets from multiple sources, build executive-level dashboards providing clear visibility into procurement compliance status and spend analytics, and serve as the primary authority for procurement compliance on the account. You'll oversee spend analytics across all procurement categories, develop supplier performance scorecards, and ensure all suppliers and procurement activities comply with organizational policies and regulatory obligations. This position demands consistent availability during standard business hours with reliable technology access for real-time responsiveness through phone, email, and video collaboration to support time-sensitive client needs.   What your day-to-day will look like: - Serve as the steward of data quality and integrity across all procurement-related systems, establishing and enforcing data entry standards, validation rules, and quality control processes while regularly auditing systems to identify and resolve data discrepancies - Design and launch the procurement metrics, compliance reporting, and monitoring program for the account, defining key performance indicators and establishing repeatable processes for data collection, validation, and compliance reporting - Own and administer the account's sourcing request intake and tracking tool in Smartsheet, monitoring all incoming requests, proactively identifying stagnating requests, and engaging with stakeholders to understand barriers and drive resolution - Design and build dashboards that provide clear visibility into procurement compliance status, spend analytics, supplier performance, and operational trends, developing executive-level reporting for compliance metrics and spend by category and supplier - Serve as the primary owner and authority for procurement compliance on the account, monitoring and enforcing compliance requirements including Certificate of Insurance documentation, contract terms, supplier certifications, and regulatory obligations - Oversee collection, analysis, and reporting of spend metrics across all procurement categories, developing comprehensive spend visibility including expenditures by category, supplier, service line, location, and time period - Manage supplier performance data collection, tracking, and reporting across the supplier base, developing supplier performance scorecards that provide visibility into how suppliers perform against established standards and service level agreements - Analyze large datasets by combining and reconciling data from multiple sources including ERP exports, financial systems, spend data, contract repositories, and work order systems to identify compliance trends and spending patterns - Track contract expiration timelines and renewal pipelines to ensure uninterrupted compliance, configure automated alerts and reporting within Smartsheet, and establish standardized documentation requirements to support audit readiness - Provide guidance and training to ensure consistent data entry practices across the procurement team and operations stakeholders while continuously refining dashboards to improve clarity, usability, and strategic insight   Required qualifications: - 3-5 years of strategic sourcing, procurement compliance, contract management, spend analytics, risk management, or operational analytics experience for services or indirect categories - Strong understanding of procurement compliance requirements including insurance documentation, contract terms and conditions, supplier certifications, and regulatory obligations - Experience with spend analysis, category spend tracking, and financial data analysis - Advanced Microsoft Excel skills including pivot tables, advanced formulas, VLOOKUP/XLOOKUP, data validation, and analysis of large datasets - Experience using Smartsheet to build and administer intake tools, workflows, dashboards, and automated tracking systems - Demonstrated ability to combine and analyze data from multiple systems and sources   Preferred qualifications: - Experience building dashboards using Power BI, Tableau, or similar business intelligence tools - Experience with JLL procurement systems including Jaggaer, Corrigo, or Aravo - Experience developing supplier performance metrics and scorecards - Bachelor's degree (BA/BS) from four-year college or university   This position does not provide visa sponsorship. Candidates must be authorized to work in the United States without sponsorship. Estimated compensation for this position: 76,100.00 – 122,700.00 USD per year Location: Remote –Boise, ID, Chicago, IL, Phoenix, AZ, Salt Lake City, UT, Seattle, WA Personalized benefits that support personal well-being and growth:   JLL recognizes the impact that the workplace can have on your wellness, so we offer a supportive culture and comprehensive benefits package that prioritizes mental, physical and emotional health. Some of these benefits may include: - 401(k) plan with matching company contributions - Comprehensive Medical, Dental & Vision Care - Paid parental leave at 100% of salary  - Paid Time Off and Company Holidays - Early access to earned wages through Daily Pay

North Dakota + 26 moreAll locations: North Dakota | South Dakota | Nebraska | Kansas | Oklahoma | Texas | Minnesota | Iowa | Missouri | Arkansas | Louisiana | Wisconsin | Illinois | Kentucky | Mississippi | Alabama | Washington | Oregon | California | Nevada | Idaho | Utah | Arizona | Montana | Wyoming | Colorado | New Mexico
$76.1K - $122.7K / year
GP Strategies logo

Senior Oracle Analyst – Compliance & Reporting

GP Strategies

A global consulting company, GP Strategies specializes in performance improvement for businesses. Founded in 1966, GP Strategies' world headquarters are based in Columbia, Maryland

Compliance18 days ago

• Design, develop, and maintain BI Publisher (BIP) reports, OTBI analyses, dashboards, and data models across Oracle Fusion Finance (GL, AP, AR, FA, Projects) and HCM (Core HR, Payroll, Benefits, Compensation) modules. • Develop complex SQL and PL/SQL queries for data extraction, transformation, validation, and reporting performance optimization. • Build General Ledger balance reports and financial statements using Oracle Financial Reporting Studio (FRS). • Design and support compliance and regulatory reporting including SOX, statutory financial reporting, payroll regulatory reporting, audit, and internal controls. • Support external and internal audits by delivering validated, reconciled financial and HR data extracts. • Perform data reconciliation between sub-ledgers and General Ledger. • Develop parameter-driven, bursting, and role-based secure reporting solutions. • Design and maintain BI Publisher layouts and templates including Purchase Orders, invoices, and Oracle Recruiting Cloud (ORC) forms. • Develop reporting solutions for Timecards, Absence Management, Payroll, Workers Compensation, and Benefits. • Support BICC data extractions, enterprise data integrations, and E-Invoicing integrations using REST and SOAP APIs. • Configure and support Oracle Fusion security roles, row-level security, and HCM data security policies ensuring compliance with segregation of duties and data privacy requirements. • Support bulk data loads, data migration, and conversion activities using FBDI and HDL, including validation reporting. • Maintain and enhance Descriptive Flexfields (DFFs) and complex cross-subject-area joins in OTBI. • Support Oracle Fusion P2T refresh activities, quarterly updates, and regression testing of reports. • Collaborate with functional and technical teams for testing, deployments, integrations, and release management. • Track work items using Azure DevOps (ADO), manage backlogs, and provide reporting status to stakeholders.

India
Job Closed
Quzara LLC logo

Compliance Analyst, GRC/RMF

Quzara LLC

Cybersecurity & Managed Services firm providing Technical Advisory support to Federal and Commercial customers.

Compliance18 days ago
Full TimeRemoteTeam 11-50Since 2015H1B No Sponsor

• The Compliance Analyst (GRC/RMF Focused) supports governance, risk, and compliance (GRC) initiatives by developing, maintaining, and managing security documentation and compliance artifacts aligned with federal standards. • This role plays a key part in supporting Risk Management Framework (RMF) activities, continuous monitoring, and authorization efforts across federal and regulated environments. • This role requires strong expertise in NIST SP 800-53, FISMA, and related guidance, with the ability to translate technical system configurations into clear, audit-ready documentation. • The ideal candidate is detail-oriented, organized, and capable of managing multiple compliance workstreams while engaging effectively with both technical and non-technical stakeholders.

United States