
About Clerk
Clerk is on a mission to solve the user identity layer once and for all. We are a globally distributed team dedicated to providing best-in-class developer infrastructure to build the next generation of AI software. Today, we provide developers with full-stack React components and hooks like useUser and useOrganization. These APIs allow developers to build hard-to-get-right infrastructure for user identity, organization management, and billing flows. We believe that a component is worth a thousand APIs.
Clerk is looking for a Senior GRC Engineer to join our Security Team. Our customers put Clerk in the middle of their authentication flow, and every one of them runs us through their own vendor review before they do. You'll own the program that makes that review easy: the controls, the evidence, the audits, and the answers.
You'll work as a hands-on engineer. Expect to spend a lot of your time writing integrations, automations, and internal tools that enforce policies and automate evidence gathering. The goal is a program that's always current, so an audit is just someone observing it rather than a quarterly scramble.
What You'll Do
- Own SOC 2 Type II and HIPAA end-to-end: scoping, control design, evidence, auditor walkthroughs, and remediation.
- Scope and lead our next framework (ISO 27001 is the likely candidate) based on what customers actually ask for.
- Build and maintain the integrations that feed our GRC platform from our cloud providers, SaaS tools, and internal systems.
- Turn controls into continuous checks: policy-as-code, config drift detection, and a control-failure pipeline from detection to closure.
- Run the vendor security review program, from intake to periodic re-review.
- Own the security questionnaire and trust center workflow.
- Maintain the risk register and run risk assessments that produce documented decisions.
- Embed compliance requirements into the SDLC and change management so they're enforced by tooling, not by reminders.
- Reduce the number of things a human has to do to pass an audit every quarter.
Who You Are
- 5+ years in security, with demonstrated experience building automation for a GRC or compliance program.
- You've been the technical owner of at least one SOC 2 Type II or ISO 27001 audit and can tell us what you would do differently.
- You write code and use LLMs to get more done without lowering the bar.
- Hands-on with a GRC platform's API, not just its dashboard.
- Cloud IAM and configuration depth on at least one provider (GCP preferred).
- You can decide what evidence is sufficient and defend an automated test to an auditor.
- Comfortable being one of a few security engineers; you can scope, prioritize, and ship without a lot of process around you.
- Clear writer: policies, control narratives, and questionnaire answers are read by customers, so they have to be high quality.
Nice-to-Haves
- Experience at an all-remote company.
- Shipped LLM or agentic workflows in production for compliance work.
- Experience at a developer-tools company.
Benefits
- Competitive Salary: Fair compensation matching your skills and experience.
- Equity Ownership: Stock option plan so everyone shares in the growth and success of the company.
- Health Coverage: Top-tier health insurance.
- Work Gear: Choose your ideal home office setup.
- Flexible Vacation Policy: Unlimited vacation policy (25 days recommended per year) plus national holidays in your country of residence.
- Diverse and Inclusive Team: Join an exceptional, globally distributed team committed to building modern web infrastructure.
Benefits
Equity, Health, Equipment, Home office, Unlimited PTO, Wellness
Open to
Worldwide
Sign in to track applications and earn points.