Full-Time

Senior GRC Engineer

Updated on 2/7/2025

Spire

Spire

501-1,000 employees

Satellite data for maritime and weather analytics

Data & Analytics
Automotive & Transportation

Compensation Overview

$130k - $170kAnnually

+ Annual Equity Awards

Senior

Washington, DC, USA

This position will require you to work a minimum of three days per week in office.

Category
Cybersecurity
IT & Security
Required Skills
Bash
Python
AWS
Go
JIRA

You match the following Spire's candidate preferences

Employers are more likely to interview you if you match these preferences:

Degree
Experience
Requirements
  • Bachelor's degree in Information Security, Cyber Security, Computer Science, Computer Engineering, Software Development, or a related field, or equivalent experience in a relevant area.
  • Minimum of 3-5 years of hands-on technical experience in an IT, engineering, GRC, or security role, preferably in the aerospace, satellite, or Government industries.
  • In-depth knowledge of EAR, ITAR, ISO 27001, NIST 800-171, and NIST 800-53.
  • Ability to automate security control, compliance, and configuration audits utilizing scripting languages such as bash, Python, Go, or similar.
  • Experience implementing and managing GRC tools and technologies, such as GRC platforms, SIEM solutions, and vulnerability management systems.
  • Experience reviewing risk analyses, drafting corrective action plans, and driving the risk treatment process.
  • Relevant experience working and communicating with internal and external systems and process auditors.
  • In depth knowledge of security framework controls as they apply to public cloud (AWS preferred), hybrid, self-hosted, and SaaS environments.
  • Ability to transform and communicate organizational compliance requirements into internal engineering requirements for various teams including engineering and security.
  • Ability to partner with colleagues, independently manage and run complex projects, and prioritize efforts for risk reduction.
  • Excellent analytical and problem-solving skills.
  • Develop clear and concise written content.
  • Excellent project and task management skills, preferably using Jira.
  • Strong communication and interpersonal abilities.
  • Ability to work independently and as part of a team.
Responsibilities
  • Conduct thorough assessments and audits to ensure continued compliance with EAR/ITAR, ISO 27001, NIST 800-171 and any additional future security frameworks or contractual security requirements.
  • Operate Spire’s Information Security Management System by outlining projects, executing workflows, and coordinating tasks with other teams as needed.
  • Design, implement, and manage GRC tools and technologies to streamline processes for risk assessment, compliance monitoring, and incident management, including development of automation tools and automating auditing tasks.
  • Develop and implement GRC and cybersecurity strategies and policies in line with regulatory and certification requirements.
  • Provide guidance and training to staff on compliance matters related to export controls and security standards.
  • Collaborate with cross-functional teams to address compliance issues and develop corrective action plans.
  • Work with Spire’s Legal department to incorporate new legislative requirements into existing policies and procedures.
  • Monitor applicable cybersecurity regulations for changes and incorporate new requirements into existing policies and procedures.
  • Generate new documentation and maintain existing documentation such as stakeholder analyses, scope statements, risk assessment and treatment procedures, performance monitoring and measurement plans, etc.
  • Conduct risk assessments and develop risk mitigation strategies.
  • Prepare and submit compliance reports to regulatory agencies and internal stakeholders, including NIST SSPs and POAMs.
  • Participate in external and internal audits including gathering audit evidence both directly and indirectly through coordination with other teams.
Desired Qualifications
  • Professional certifications such as CISSP, CISA, CRISC, or similar are highly desirable.

Spire Global, Inc. specializes in satellite data and analytics, focusing on maritime tracking, weather forecasting, and global intelligence. The company operates a network of nanosatellites that collect real-time data on ship locations, weather conditions, and other important metrics. This information is processed and made available to clients, such as shipping companies and government agencies, through APIs and digital platforms, allowing them to enhance their decision-making and improve operational efficiency. Spire stands out from its competitors by offering extensive coverage and accuracy, particularly in busy maritime areas like the South China Sea. The company's goal is to deliver high-quality data solutions that help clients optimize their operations and navigate complex environments.

Company Stage

IPO

Total Funding

$445.8M

Headquarters

Tysons, Virginia

Founded

2012

Growth & Insights
Headcount

6 month growth

0%

1 year growth

-1%

2 year growth

0%
Simplify Jobs

Simplify's Take

What believers are saying

  • Partnership with LatConnect60 expands Spire's reach in agriculture and forestry sectors.
  • Collaboration with Thales and ESSP diversifies services into aviation surveillance.
  • £3.5 million UK Space Agency funding boosts weather forecasting technology.

What critics are saying

  • Class action lawsuits could lead to financial liabilities and reputational damage.
  • Revenue recognition issues may result in regulatory scrutiny and investor distrust.
  • Emerging competition from companies like LatConnect60 may erode market share.

What makes Spire unique

  • Spire uses nanosatellites for real-time maritime tracking and weather forecasting.
  • The company offers data through APIs, enhancing client decision-making capabilities.
  • Spire focuses on high-traffic maritime zones, ensuring unparalleled data coverage.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Hybrid Work Options

Unlimited Paid Time Off

Professional Development Budget

Mental Health Support

Company Equity