Kelly Services logo

GRC Engineer (Hybrid NYC)

Kelly Services

New York, NY · HybridFull-time$150–170K/yrSeen 1 day agoSeen in employer's feed 1 day ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$150–170K/yr
Location
New York, NYHybrid
Schedule
Full-time
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The GRC Engineer will establish and lead a new cybersecurity service line for startup clients, owning security programs from audit readiness through technical implementation. The role combines governance, risk, and compliance work with hands-on engineering, including endpoint, mobile-device, and identity controls. It is based in Midtown Manhattan on a strict hybrid schedule of four days in the office and one remote day, with client-site travel.

Skills & qualifications

RequiredNice to have

Skills

CommunicationAudit ManagementVantaDrataSecureframeEDR AdministrationSentinelOneMDM AdministrationMosyleJamfIntuneIdentity and Access ManagementOktaEntra IDCloud PlatformsSOC 2NIST CSFISO 27001

Qualifications

5+ Years Security and GRC Experience

Full job description

$140000 - $175000

Job Title: GRC Engineer (Hybrid NYC)

Location: New York, NY (Hybrid): 4 days in office, 1 day remote

This highly successful Managed Service Provider (MSP) based in Midtown Manhattan acts as the dedicated technology backbone for top-tier VC firms and high-growth startups. Currently in an aggressive growth phase, they are launching a brand-new cybersecurity service line to meet the high demand from their exclusive client base. Led by two highly involved founders, this firm offers a fast-paced, collaborative environment where you will partner face-to-face with the next generation of tech innovators.

As the GRC Engineer, you will serve as the founding leader of this new cybersecurity division. This rare, highly visible role perfectly bridges Governance, Risk, and Compliance (GRC) with hands-on technical engineering. You will take total ownership of client security programs end-to-end, guiding startups through compliance paperwork while actively implementing the technical controls to keep them up to code. You must be an exceptional, client-facing communicator capable of translating complex cyber concepts into clear, actionable advice for non-technical founders.

Requirements

  • 5 to 7+ years of experience bridging Information Security, IT operations, and hands-on GRC implementation.

  • Exceptional communication skills with the ability to confidently explain technical cyber risks to non-technical audiences.

  • Hands-on experience managing a full audit cycle utilizing platforms like Vanta, Drata, or Secureframe.

  • Technical background administering EDR (e.g., SentinelOne) and MDM (e.g., Mosyle, Jamf, Intune).

  • Deep understanding of identity and access management tools like Okta or Entra ID, alongside major cloud platforms.

  • Strong command of compliance frameworks, including SOC 2, NIST CSF, and ISO 27001.

Responsibilities

  • Build and lead a brand-new cybersecurity and GRC service line from the ground up for high-growth startup clients.

  • Travel to client sites to conduct assessments, acting as the authoritative face of the cybersecurity division.

  • Take end-to-end ownership of client security programs, managing audit readiness, gap analysis, and auditor liaison.

  • Translate compliance documentation into action by deploying, tuning, and hardening endpoint security, MDM fleets, and identity solutions.

  • Create, manage, and enforce comprehensive security policies while ensuring all technical implementations strictly meet compliance codes.

This position offers a competitive base salary of $150,000 to $170,000, depending on experience. Operating on a strict hybrid schedule (4 days onsite, 1 day remote) out of a Midtown Manhattan office, this role requires a highly driven individual ready to thrive alongside a dedicated team. If you are an autonomous security expert looking to build a critical business unit from scratch and make a massive impact, this is the opportunity for you.

Motion Recruitment Partners (MRP) is an Equal Opportunity Employer. All applicants must be currently authorized to work on a full-time basis in the country for which they are applying, and no sponsorship is currently available. Employment is subject to the successful completion of a pre-employment screening. Accommodation will be provided in all parts of the hiring process as required under MRP’s Employment Accommodation policy. Applicants need to make their needs known in advance.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.