ForgeApply · Job listing
Senior Cybersecurity Engineer, GRC Automation and Continuous Control Monitoring
Mpc
See all 43 open roles at Mpc →
Tailor your resume for this Mpc job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Mpc's site. Free trial, no card required.
About this role
An exciting career awaits you
At MPC, we’re committed to being a great place to work – one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment.
Position Summary
The GRC Automation & Continuous Controls Monitoring (CCM) Senior Cybersecurity Engineer is a strategic and technical role, responsible or helping turn GRC into a trust engine for the business: reducing audit friction, improving business risk exposure visibility, accelerating evidence readiness, and enabling stronger operational confidence. The role serves as the technical focal for GRC automation, developing automated evidence collection, control testing, risk intelligence, and AI-enabled governance capabilities across cloud, on-premises, identity, operational technology (OT), and security platforms. The role collaborates closely with Cyber Fusion, Enterprise Architecture, and Cyber Engineering, to design and build deterministic control-testing logic where deterministic approaches are enough; and AI agents and LLM-backed workflows where reasoning, summarization, or judgment is required, such as evidence-to-control mapping, attestation drafting, drift detection, and audit-package assembly. This position belongs to a family of jobs with increasing responsibility, competency, and skill level. Actual position title and pay grade will be based on the selected candidate’s experience and qualifications. Key Responsibilities
• Conducts detailed analyses on changes to cybersecurity solutions and its relationship to internal and external systems to assess control effectiveness and cybersecurity risk. Resolves complex multi-functional technical issues. • Leverages cybersecurity assessments, standards, control testing methodologies, and compliance frameworks to ensure compliance across security systems. • Improves the efficiency and effectiveness of Security solutions, governance processes, automated controls, and monitoring capabilities. • Analyzes existing processes and procedures and leads efforts for implementing improvements, automation opportunities, or remediation activities. • Responsible for development and submission of Standard Operating Procedures. • Analyzes business impacting events, performs initial investigation, and evaluates control performance, exceptions, and risk indicators through continuous monitoring activities. • Investigates and analyzes the nature and scope of cyber incidents, control failures, and compliance exceptions. Assists in the development of risk mitigation and remediation plans to ensure regulatory and internal compliance. compliance. • Leads implementation of global security initiatives, policies, compliance requirements, and continuous control monitoring practices. Collects, validates, and reports security metrics, control performance results, and remediation efforts associated with them. • Manages cyber security-related consulting, guidance, and support to customers and stakeholders. • Translates security principles to assist configuration teams with incorporating security and compliance requirements into build and configuration processes. • Monitors emerging IT/OT, cybersecurity, automation, and artificial intelligence technologies as well as their impact on the security, risk, and compliance landscape.
Education and Experience
• Bachelor’s Degree in Information Technology, related field or equivalent experience. • 5+ years of relevant experience required • Experience designing, implementing, and scaling GRC, CCM, or compliance automation solutions within a regulated environment required • Experience in Python or comparable automation technologies, proficient in developing, integrating, and supporting automated workflows and REST API-based data integrations across multiple enterprise systems required. • Hands-on experience integrating security-control data sources into a GRC / CCM evidence pipeline for continuous control testing required. This includes normalizing API, telemetry, configuration, vulnerability, identity, ticketing, and assessment data into control-level evidence, exception logic, ownership, frequency, and audit-ready records across at least three domains such as CNAPP / CSPM, SIEM / security data lake / XDR, CTEM / VM / ASPM, DSPM, ITSM, IAM, GRC / CCM, or AI/agent governance required. • Experience building LLM-backed agentic workflows on Azure AI Foundry, GitHub, or open-source frameworks preferred. • Familiarity with NIST AI RMF, the OWASP LLM Top 10, or comparable AI risk frameworks preferred.
Skills
• Adaptability - Maintaining effectiveness when experiencing major changes in work responsibilities or environment (e.g., people, processes, structure, or culture); adjusting effectively to change by exploring the benefits, trying new approaches, and collaborating with others to make the change successful. • AI Fundamentals - Understanding of core AI concepts and methods, ability to apply AI to job-relevant use cases and capacity to contribute to organizational AI reimagination. • Change Management - Change Management refers to a systematic approach for defining and implementing procedures and/or technologies to deal with changes in the environment. It can mean adapting to change, controlling change and/or effecting change. • Authentic Communicator - Expresses ideas and information, both verbally and in writing, clearly and credibly. Listens to understand and fosters constructive dialogue. • Cybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework.
Salary insight
This posting doesn't disclose pay. Across 336 Houston jobs with disclosed salaries on ForgeApply, the median is $125k.
See full Security Engineer salary data for Houston →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Mpc role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior Security Engineer I, GRC — Oscar · New York, New York, United States
- AI Security Engineer (GRC) — SCAN · Remote
- Cybersecurity GRC Manager — Luriechildrens · Streeterville, Chicago, IL
- Manager, Cybersecurity GRC, Global — Vantagedc · Denver, Colorado
- Senior Security GRC Analyst — Roblox · San Mateo, CA, United States
- Senior Security GRC Analyst — Salesforce · California - San Francisco
- Senior Security GRC Lead — Gongio · Austin | Chicago | New York City | Salt Lake City | San Francisco
- Senior Cyber Security Engineer - SIEM and Automation — Corebridgefinancial · Jersey City, NJ | TX-Houston
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Houston · Browse all jobs
Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview