Sr Security Engineer L5; IT GRC
Listed on 2026-03-02
-
IT/Tech
Cybersecurity, Information Security
Overview
Frontdoor is reimagining how homeowners maintain and repair their most valuable asset – their home. As the parent company of two leading brands, we bring over 50 years of experience in providing our members with comprehensive options to protect their homes from costly and unexpected breakdowns through our extensive network of pre-qualified professional contractors. American Home Shield, the category leader in home service plans with approximately two million members, gives homeowners budget protection and convenience, covering up to 23 essential home systems and appliances.
Frontdoor is a cutting edge, one‑stop app for home repair and maintenance. Enabled by our Streem technology, the app empowers homeowners by connecting them in real time through video chat with pre‑qualified experts to diagnose and solve their problems. The Frontdoor app also offers homeowners a range of other benefits including DIY tips, discounts and more. For more information about American Home Shield and Frontdoor, please visit
Summary:
As an L5 Sr Security Engineer in IT GRC at Frontdoor, you will serve as an advanced practitioner that can lead complex security, risk, and compliance initiatives with deep technical and governance expertise. Serve as a recognized subject‑matter expert within one or more security domains, influencing strategy and decision‑making at the team and program level. Execute advanced risk assessments and deep‑dive analyses using structured frameworks and regulatory requirements, including NIST 800‑53, NIST CSF, SOC 2, PCI‑DSS, CIS, and SOX.
Own end‑to‑end control domains or sub‑programs, driving remediation across cross‑functional teams. Lead major compliance programs, manage high‑severity risk exceptions, vendor risk reviews, and audit responses. Implement secure engineering and SDLC fundamentals, including CI/CD controls and secure design patterns, and develop targeted automation for GRC tooling and evidence workflows. Improve operational governance processes across monitoring, evidence management, disaster recovery, and privacy support.
Provide expert guidance in architecture and change review forums. Mentor junior engineers and analysts while leading cross‑functional assessments with strong communication and execution rigor.
- Design governance artifacts (policies, standards, control catalogs).
- Perform advanced risk analysis and core digital process gap assessments.
- Drive complex risk remediation across the enterprise.
- Implement and enhance security controls across complex systems in a cloud environment.
- Lead large‑scale audits or readiness assessments (SOX, PCI‑DSS, SOC
2) - Serve as SME across multiple domains:
- Cloud Security and Governance
- Security by Design and SDLC
- Third Party Risk Management
- Vulnerability Management
- Identity and Access Management.
- Strong collaboration with engineering to implement secure coding practices and CI/CD controls.
- Lead complex risk assessments, risk remediations, and vendor risk reviews.
- Provide SME guidance in security architecture and change review forums.
- Define KPIs, capabilities, and competencies for GRC maturity across the organization.
- Coach team in bridging gaps between key stakeholders within the enterprise and GRC disciplines
- 8–10+ years in GRC, cybersecurity, audit, or risk management.
- Minimum of one professional certification (CISA, CRISC, CISSP, CGRC, CDPSE, CISM)
- Strategic thinker with leadership presence.
- Executive level communication and strategic influence.
- Strong experience leading PCI‑DSS and SOX compliance efforts.
- Deep understanding of cloud platforms, networking, application, database, and operating systems to assess security gaps.
- Familiarity with GRC software to manage, document, and report on compliance metrics.
- Ability to proactively identify emerging risks.
- Ability to operate independently with sound judgment.
- Ability to translate complex technical vulnerabilities and control deficiencies into actionable business risk remediation plans for stakeholders.
- Ability to champion GRC program improvements.
- Create repeatable automation patterns that other teams leverage.
- Build automation scripts &…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).