GRC Automation Engineer (R-00187)
True Zero Technologies
Apply to this job
True Zero is seeking a GRC Automation Engineer to modernize and automate cybersecurity governance processes supporting the National Institutes of Health (NIH). This role combines cybersecurity, software engineering, workflow automation, and process improvement to reduce manual effort across the Risk Management Framework (RMF) lifecycle while improving data quality, operational visibility, and authorization readiness.
Working closely with RMF analysts, ISSOs, vulnerability management personnel, security engineers, and program leadership, the GRC Automation Engineer develops automated workflows, integrates enterprise cybersecurity data sources, and streamlines evidence collection, reporting, and compliance activities. This position plays a key role in transforming traditional governance processes into a more efficient, data driven operating model through automation, integration, and intelligent workflow design.
Job Responsibilities
- Design, develop, and maintain automated workflows supporting RMF, Assessment and Authorization (A&A), continuous monitoring, and cybersecurity governance activities.
- Develop integrations between GRC platforms, vulnerability management systems, security tools, ticketing platforms, and reporting solutions to improve operational efficiency.
- Automate evidence collection, control validation, reporting, and recurring compliance activities to reduce manual effort and improve data accuracy.
- Support the implementation and optimization of governance, risk, and compliance (GRC) platforms including JCAM, ServiceNow, or similar enterprise solutions.
- Develop scripts, APIs, dashboards, and automation workflows that improve visibility into authorization status, POA&M activities, vulnerability remediation, and enterprise cybersecurity performance.
- Collaborate with RMF analysts and ISSOs to identify manual processes suitable for automation and continuous improvement.
- Support development of executive dashboards, cybersecurity metrics, and operational reporting through automated data aggregation and visualization.
- Evaluate emerging technologies, including artificial intelligence and machine learning capabilities, to improve documentation quality, workflow efficiency, and cybersecurity decision support.
- Maintain automation documentation, workflow diagrams, technical procedures, and integration standards.
- Troubleshoot automation issues, monitor workflow performance, and implement enhancements that improve reliability and scalability.
- Support continuous improvement initiatives by identifying opportunities to simplify cybersecurity governance processes while maintaining compliance with Federal requirements.
Job Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Software Engineering, Information Technology, or a related technical discipline.
- Three or more years of experience developing automation solutions supporting cybersecurity, governance, compliance, or enterprise IT operations.
- Experience developing scripts, APIs, or workflow automation using languages such as PowerShell, Python, JavaScript, or similar technologies.
- Experience integrating enterprise platforms through REST APIs, web services, or workflow orchestration tools.
- Working knowledge of NIST RMF, FISMA, and cybersecurity governance processes.
- Experience developing dashboards, reports, or operational data visualizations.
- Strong analytical, troubleshooting, and technical documentation skills.
- Experience supporting NIH, HHS, or other Federal civilian agencies.
- Experience with JCAM, eMASS, ServiceNow GRC, Archer, Microsoft Power Platform, Power Automate, or similar governance platforms.
- Experience integrating vulnerability management platforms, SIEMs, cloud security tools, and enterprise ticketing systems.
- Familiarity with AI assisted workflow automation, document generation, or cybersecurity reporting.
- Experience supporting Continuous Diagnostics and Mitigation (CDM), continuous monitoring, or enterprise cybersecurity operations.
- Experience working in Agile development environments.
- Security+
- Certified in Governance, Risk and Compliance (CGRC)
- CISSP
- Microsoft Certified: Power Platform Developer Associate
- Microsoft Certified: Power Platform Solution Architect
- AWS Certified Developer Associate
- Azure Developer Associate
- Certified Scrum Developer (CSD)
One or more of the following is preferred:
Summary
Develops automation workflows, integrates platforms, and improves cybersecurity governance processes.
Job title
GRC Automation Engineer (R-00187)
Experience level
3+ years
Minimum experience
3+ years exp
Industry
cybersecurity
Location requirements
remote work allowed, candidate can work from anywhere
Salary
Not specified
Management role
No
Required skills
Preferred skills
Specializations
Structured locations inferred from the posting.
United States