Automation Compliance Engineer, IT Compliance (2026 Graduate)
- Posted 2 months ago
- Be among the first 10 applicants
Job Description
Job Description:
- Design and implement workflowbased control automation for Regulatory Standards (e.g., ISO, PCI) and SOX 404 ITGCs, using:
- Explicit start-action-evidence-end flows.
- Triggers from tickets, changemanagement systems, HR events, or IAM changes.
- Delivered via tools such as n8n, Camunda, Azure Logic Apps, or custom MCPstyle servers.
- Build and operate MCPstyle or MCPcompatible servers that expose:
- Tools: RESTful endpoints for trigger evidence collection, run access review, validate change ticket, etc..
- Resources: Standardized data sources (logs, IAM, ticket data) formatted for AI agents or workflow engines.
- Auth patterns: API keys, bearer tokens, OAuth2, or OIDCstyle flows that can be consumed by agents or external tools.
- Engineer APIfirst automation:
- Write scripts and connectors (Python, Node.js, Bash, etc.) that call, compose, and orchestrate APIs from:
- IAM, IdP, PAM, HRIS, ticketing, cloud IAM, and logging platforms, etc.
- GRC platforms (e.g., ServiceNow, 6clicks, or similar) via REST APIs.
- Implement:
- Authentication and authorization (API keys, Bearer, OAuth2, JWT, Basic, MTLS).
- Pagination, retry with backoff, ratelimiting, and safe error handling.
- Idempotency and safe state transitions for auditcritical operations.
- Write scripts and connectors (Python, Node.js, Bash, etc.) that call, compose, and orchestrate APIs from:
- Translate ISO 27001 controls and SOX 404 ITGCs into automated workflows:
- Example pattern:
- Trigger: new user join or role change in IAM.
- Action: call APIs to validate entitlements, crosscheck against SoD, and emit evidence to a GRC tool.
- Outcome: workflowgenerated record for ISO 27001 access control and SOX logicalaccess control.
- Maintain one source of truth for control logic (code / config) and use workflow IDs as controlevidence bindings.
- Example pattern:
- Design AIagentready interfaces:
- Expose structured, MCPstyle endpoints or OpenAPI specs so that LLM agents or workflow tools can call concrete tools (e.g., get latest access review for System X, run changeticketcompleteness check).
- Handle dynamic policy enforcement: shortlived tokens, contextaware access, and audit logging for each AI or agent call.
- Integrate with data platforms and SIEM/logging:
- Use logs, change tickets, and identity events as workflow inputs.
- Build automated tests for control effectiveness (e.g., if a production change is not approved, fire an alert and record as control failure) linked to ISO / SOX control IDs.
- Maintain auditready workflow artifacts:
- Log all workflow steps, including timestamps, input, user/agent context, and outputs.
- Ensure workflow outputs are machinable (JSON, structured logs) and can be replayed or reasoned over by auditors or AI agents.
Requirements:
- Bachelor's degree or above in computer science, computer engineering or related disciplines.
- Strong understanding of authorization and authentication:
- API keys, Bearer tokens, OAuth2 (client, JWT, PKCE), Basic Auth, MTLS, and OIDCstyle flows.
- Handson experience implementing these in Python, Node.js, or Go (or similar).
- Deep practical experience with:
- RESTful APIs: understanding of HTTP methods, status codes, pagination, ratelimiting, and idempotency.
- API clients: writing or using libraries that handle auth, retries, and error handling for large datasets.
- Experience building or integrating with:
- Workflow / orchestration tools (n8n, Airflow, Logic Apps, Camunda, etc.) or MCPstyle servers / Model Context Protocolcompatible tooling.
- GRC platforms via APIs (e.g., ServiceNow, 6clicks, or similar).
- Familiarity with:
- ISO 27001 (especially Annex A controls related to access management, change control, and operations).
- SOX 404 ITGCs (logical access, change management, computer operations, data integrity).
Preferred Qualifications:
- OpenAPI / Swagger to MCPstyle tool generation (e.g., converting production APIs into MCP servers or AIagent tools).
- Experience with MCP servers or similar controlplane architectures that expose tools, resources, and prompts for AI agents.
- Background in security automation, CI/CD, or DevSecOps (number of tools: n8n, Terraform, Ansible, Docker, logging pipelines).
- Prior involvement in SOX 404 audits and ISO 27001 certification projects, with a focus on how to automate evidence collection rather than manual spreadsheets.
More Info
Job Type:
Industry:
Function:
Employment Type:

