← Back to jobs

Compliance Automation Engineer

This listing is synced directly from the company ATS.
remote
Remote - United States

Role Summary

As a Compliance Automation Engineer at Vercel, you will design and automate compliance control testing and evidence collection, significantly enhancing the company's governance, risk, and compliance posture. This mid-level role involves collaborating with both technical and non-technical teams, embedding compliance checks into CI/CD workflows, and leveraging AI/ML tools to optimize GRC processes.

Benefits & Culture

Vercel offers a competitive compensation package that includes equity and an inclusive healthcare package. The role allows for flexible time off and provides resources for remote work setup. You'll have opportunities for mentorship and professional growth through events, fostering a supportive and innovative company culture.

Full Job Description

About Vercel:

Vercel gives developers the tools and cloud infrastructure to build, scale, and secure a faster, more personalized web. As the team behind v0, Next.js, and AI SDK, Vercel helps customers like Ramp, Supreme, PayPal, and Under Armour build for the AI-native web.

Our mission is to enable the world to ship the best products. That starts with creating a place where everyone can do their best work. Whether you're building on our platform, supporting our customers, or shaping our story: You can just ship things.

About the role:

We are looking for a GRC Automation Engineer to join our Governance, Risk, and Compliance (GRC) team. You will have the opportunity to enhance our global compliance posture and further our commitment to managing enterprise risk. Your role will be instrumental in ensuring that our company operates in accordance with security requirements and embodies an environment where it’s everyone’s responsibility. This role will report to the Head of GRC and help shape the next iteration of the GRC program and further embed data governance principles and compliance requirements into the business.

Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics.

If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team.

Getting started:

  • We want you to feel like part of the team early on! Our team will help integrate you into the company with explanations on our product, policies, processes, team structure and roadmap.
  • We’re excited for you to learn, grow, and contribute right away! We trust that you’ll bring experience and knowledge that will uplift and up-level the team, but we don’t expect you to know everything on Day 1.

What you will do:

  • Design and automate control testing and evidence collection to reduce manual effort and improve accuracy.
  • Build and maintain scripts and APIs across infrastructure, endpoints, and SaaS platforms (e.g., AWS, GitHub, Okta) that interface with compliance tooling.
  • Support recurring internal and external audits (i.e., SOC 2, ISO 27001, PCI DSS, etc.) by ensuring reliable control monitoring.
  • Champion security, compliance, data governance strategies and processes, including data deletion, data retention, data storage, and more.
  • Leverage AI/ML tools to improve efficiency and outcomes for GRC processes and overall compliance posture.
  • Define technical control requirements and collaborate with internal partners to embed compliance checks into CI/CD pipelines and infrastructure deployment workflows.

About you:

  • Experience in scripting or automation with a focus on security, infrastructure, or GRC
  • Knowledge of audit processes, evidence requirements, and remediation actions for security and compliance frameworks (i.e., SOC 2, ISO 27001, PCI DSS)
  • Ability to write scripts and basic code to automate audit and evidence gathering processes
  • Ability to build API end points and command-line tools, work with structured data (JSON, CSV, YAML), and extract compliance-relevant information from security, IT, and GRC systems
  • Experience owning a project or scope, building relationships, collaborating with both technical and non-technical teams and driving initiatives to completion

Bonus if you have:

  • Familiarity with data governance, compliance or software development tools and systems (e.g., Drata, Satori, Github, etc.)
  • Experience with frontend cloud, AI/ML systems, and open source development
  • Experience with FedRAMP or NIST frameworks, such as 800-53, 800-171, RMF
  • Security certifications (e.g. CISA, CISSP)

Benefits:

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $128,000.00 - $222,000.00.  Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process. 

Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.

Similar jobs

Found 6 similar jobs