Playlist Logo

Playlist

Senior GRC Engineer

Posted 19 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
150K-170K Annually
Senior level
Remote
Hiring Remotely in United States
150K-170K Annually
Senior level
Own Playlist's technical GRC architecture across multiple compliance frameworks. Build and maintain a unified Master Control List, framework crosswalks, evidence workflows, and control lifecycle processes. Automate compliance evidence collection and develop AI-powered GRC tools for risk quantification, vendor assessments, and monitoring. Partner with engineering, legal, finance, auditors, and product teams to translate requirements into actionable controls and harmonize compliance across multiple brands and acquisitions.
The summary above was generated by AI
About the Company:

At Playlist, life's richest moments happen when people step away from screens to move, connect, explore, and play. We're building the definitive platform for intentional living, connecting people with inspiring experiences in fitness, wellness, and beyond. With popular brands like Mindbody and ClassPass, Playlist empowers businesses and individuals, making it effortless for aspirations to become actions. Join us in reshaping technology's role to foster meaningful, real-world connections.

Who we are

The GRC team at Playlist owns governance, risk, third-party risk, and compliance across a portfolio that spans Mindbody, ClassPass, Booker, Kite, and EGYM, with more brands coming as the company grows. We operate without a playbook, building programs, frameworks, and control architecture in an environment that's complex, not just big. The team works closely with Engineering, Legal, Finance, and product teams to make compliance real rather than ceremonial. If you want to do meaningful work on hard problems with people who take both rigor and pragmatism seriously, we'd love to meet you.

Your role

As a Senior GRC Engineer, you'll own the technical spine of how Playlist manages its control environment. That means designing the architecture that lets the team work across multiple compliance frameworks without duplicating effort at every audit, and making sure control design, evidence requirements, and implementation keep pace with regulatory change and business growth.

You'll be expected to act as a technical leader who can help mature our governance, risk, compliance, in a way that is durable, measurable, and embedded into how our systems operate day to day. Your time will center on two related workstreams. The first is building and maintaining Playlist's Master Control List, a live control architecture mapped across PCI DSS, SOC 1 Type II, ISO 27001, HITRUST, and NIST CSF/800-53 that teams can use and navigate. The second is managing the full lifecycle of controls and evidence requirements as new standards are adopted, updated, or expanded to cover newly acquired brands.

You will
  • Design and build framework crosswalks and control mappings across PCI DSS, SOC 1 Type II, ISO 27001, HITRUST, and NIST CSF/800-53, using languages such as OSCAL as the translation layer to preserve framework-specific requirements while reducing duplicate audit burden
  • Own the Master Control List end-to-end, including control nomenclature, relational database architecture, evidence linkages, and the operational model for ongoing maintenance across Playlist's multi-brand footprint
  • Manage the full lifecycle of controls, evidence requirements, and implementation as new standards are adopted, requirements change, or acquired entities are brought into scope
  • Drive evidence automation in GRC tooling, building collection workflows that scale without turning every audit season into a manual sprint
  • Partner with Security Engineering, Legal, and Finance to validate that control design reflects how the business operates, translating compliance requirements into implementation guidance that engineering teams can act on
  • Design, build and maintain AI-powered GRC tooling, multi-agent pipelines for risk quantification, evidence automation, vendor risk assessment, and compliance monitoring using cloud native tools and APIs, so the team's analytical and operational capacity scales without scaling headcount
  • Identify rationalization opportunities across frameworks, so adding a new standard to the portfolio means incremental work, not starting from scratch
About the right team member

You think in systems, not checklists. You're the person who looks at five overlapping compliance frameworks and immediately starts sketching how they relate to each other, where the evidence reuse opportunities are, and what a sustainable architecture looks like long-term. You also see AI as a genuine lever, not a novelty, and you know how to wire agentic workflows into compliance programs in ways that hold up under audit scrutiny. You're equally comfortable whiteboarding a control schema, shipping a pipeline, and sitting with an auditor challenging a scope interpretation. You don't wait for someone to hand you the answer; you dig in, form a view, and bring it to leadership with the reasoning laid out. You're precise without being rigid, and you understand that compliance programs have to serve the business, not the other way around.

You'll thrive in this role with experience in:

Must Have:

  • 6+ years of experience in security engineering, GRC, or compliance engineering, with direct hands-on work across multiple regulatory frameworks
  • Deep working knowledge of PCI DSS, SOC 1 or SOC 2, HITRUST, and at least one of ISO 27001 or NIST CSF/800-53
  • Experience designing or maintaining control frameworks, crosswalks, or unified control architectures across multiple compliance standards
  • Hands-on experience managing evidence requirements and control implementation, not just documentation
  • Proficiency with compliance automation tooling (Optro, Drata, Vanta, Hyperproof, Anecdotes, or similar)
  • Ability to translate technical control design into clear implementation guidance for engineering and product teams
  • Experience building or operating agentic AI workflows (LLM-based pipelines, multi-agent systems, RAG architectures) in a production or near-production context

Nice to Have:

  • Hands-on experience with AWS services (Lambda, Step Functions, EventBridge, S3, Aurora/RDS) for building and maintaining compliance automation infrastructure
  • Experience supporting external audits or assessments as a primary technical contact
  • Exposure to multi-brand or post-acquisition control harmonization
  • Certifications such as CISA, CISSP, ISO 27001 Lead Implementer, CCSFP (HITRUST), or PCI ISA
  • Experience in a SaaS or consumer marketplace environment

It is the Company's intent to pay all Team Members competitive wages and salaries that are motivational, fair and equitable. The goal of Company's compensation program is to be transparent, attract potential employees, meet the needs of all current employees, and encourage Team Members to stay with our organization. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to skill set, depth of experience, certifications, and specific work location.

The base salary range for this position in the United States is $150,000 to $170,000. The total compensation package for this position may also include a performance bonus, benefits and/or other applicable incentive compensation plans

Have we piqued your curiosity?

Sound like the role for you? We’d love to hear from you! Even if you’re not 100% sure about potential fit, we still encourage you to apply. We’re looking for the right person, not the perfect series of checkboxes.

The Company is an Equal Opportunity Employer. We highly value diversity at our company and encourage people of all different backgrounds, experiences, abilities and perspectives to apply. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or other protected characteristics.

By entering your email and phone number and submitting your application, you consent to receive emails, calls and SMS about your application and other roles at The Company, including by auto-dialer. Message and data rates may apply. Opt-out or text STOP to cancel at any time. If you are a California resident or reside outside the United States then by submitting your application you confirm that you have read, understood, agree and - where applicable - grant your prior, free, informed and express consent for the processing of your personal information, including sensitive personal information, as described in our California Applicant Privacy Notice or International Applicant Privacy Notice (as applicable).

Note: This description outlines key responsibilities but isn’t intended to cover every task or duty. Additional responsibilities may be assigned as needed to support the team and business goals.

Similar Jobs

7 Days Ago
In-Office or Remote
CA, USA
185K-327K Annually
Senior level
185K-327K Annually
Senior level
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
Build and operate GRC data pipelines, integrations, policy-as-code, continuous control monitoring, evidence automation, and agentic AI workflows. Normalize security data from diverse systems, create auditable evaluation harnesses, govern AI systems, and define technical direction across teams. Partner with security governance, compliance, and engineering groups to transform manual governance processes into scalable products.
Top Skills: AWSBuildkiteCi/CdClaudeGCPGoGrpcHTTPJavaJSONKotlinKubernetesLlm ApisModel Context ProtocolProtocol BuffersPythonSnowflakeSQLTerraform
Yesterday
Remote
United States
Senior level
Senior level
Security • Cybersecurity
Owns audit evidence collection, technical control validation, continuous monitoring, and compliance documentation across FedRAMP, ISO 27001, ISO 42001, SOC 2, and NIST frameworks. Partners with IT, Engineering, and DevOps teams, supports external assessors, automates evidence collection, tracks remediation, and contributes to risk assessments, threat modeling, vendor reviews, and AI security safeguards.
Top Skills: AuditboardCi/CdData Loss PreventionDrataGitGoogle Cloud Platform (Gcp)Google Kubernetes Engine (Gke)Identity And Access ManagementInfrastructure As CodeMicrosoft 365Microsoft Entra IdPowershellPythonStrideVantaVulnerability Management
27 Days Ago
Remote
United States
Senior level
Senior level
Artificial Intelligence • Information Technology • Software
Lead federal compliance engagements for clients pursuing FedRAMP and NIST certifications. Own strategic advisory, gap assessments, FedRAMP 20x readiness, OSCAL/JSON/YAML machine-readable artifacts, CCM continuous monitoring integrations, and third-party assessment orchestration while mentoring a small compliance team and maintaining executive client relationships.
Top Skills: AWSAws GovcloudAzureAzure GovernmentCmmcCspmFedramp 20XGCPGdprGrc PlatformsInfrastructure As Code (Iac)Iso 27001JSONNist Sp 800-171Nist Sp 800-53Opa/RegoOscalPythonRmfSoc 2Yaml

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account