Compliance Engineer
Gridware
公司概况
他们的工作
Gridware是一家开创性的初创公司,专注于通过创新技术增强电网的韧性。他们的核心产品,主动电网响应(AGR),利用安装在电杆上的Gridscope传感器实时监测配电电力线路的各种条件。这些传感器由太阳能供电,并通过设备对设备、蜂窝和卫星网络进行通信,确保无论电网电压如何都能持续运行(来源:gridware.io)。该技术旨在检测一系列问题,包括植被接触、倒下的电线和设备故障,使公用事业公司能够进行预测性维护和动态断电,以防止野火和停电(来源:cbsnews.com)。目标市场包括美国电力公用事业,特别是在加利福尼亚州和中西部等易发生野火的地区,并计划未来进行国际扩展(来源:promptloop.com)。他们的产品与公用事业运营管理系统无缝集成,覆盖超过9000万的现场工时,并通过合作伙伴关系服务于40%的美国客户(来源:gridware.io)。
项目与业绩
Gridware已成功在八个州部署了大约13,000个传感器,特别是在加利福尼亚州的高风险野火区域,覆盖约1,000英里的电力线路。他们的技术被认为能够防止野火,报告显示其警报成功阻止了冒烟的植被点燃(来源:cbsnews.com)。值得注意的整合包括与PG&E的高阻抗故障检测合作,以及与Puget Sound Energy的试点项目,旨在改善风暴和野火修复的优先级。在一个案例中,加利福尼亚北部的一个电路停电巡逻时间减少了70%,而中西部的一家公用事业公司在四个电路上节省了400,000分钟的停电时间(来源:gridware.io)。正在进行的项目包括与NorthWestern Energy在蒙大拿州城市的2024年试点,专注于实时资产监测以减轻野火风险(来源:northwesternenergy.com)。
近期发展
在过去两年中,Gridware筹集了大量资金以支持其增长和扩展努力。在2024年,他们宣布了一轮由红杉资本主导的2640万美元的A轮融资,此前在2023年获得了由Lowercarbon Capital和Fifty Years共同主导的1050万美元种子扩展融资(来源:gridware.io)。这笔资金旨在增强他们在美国的运营并为国际部署做准备。此外,Gridware因其创新技术而获得认可,包括在2022年被《时代》杂志评选为最佳发明之一,因其Gridscope传感器而受到关注,并在2023年被《福布斯》评选为30位30岁以下的杰出人物(来源:engineering.berkeley.edu)。该公司继续深化与公用事业的合作关系,包括计划于2024年底与NorthWestern Energy进行试点项目(来源:northwesternenergy.com)。
在这里工作
Gridware提供多种以工程为中心的职位,包括软件工程、电气设计工程、数据工程和技术招聘等职位。该公司由电工和工程师组成,反映出一种强调与现场工人合作的文化,以及以使命为导向的野火预防方法(来源:climatepeople.com)。招聘主要集中在他们的湾区总部,他们正在迅速扩展团队以支持传感器的生产和部署工作。Gridware的文化被描述为严格且以使命为导向,强烈关注实现实际成果,例如其技术记录的显著现场工时(来源:gridware.io)。虽然来源中没有详细说明具体的员工福利,但公司的风险投资背景表明可能会提供具有竞争力的初创公司福利(来源:cbsnews.com)。
最后更新于 2月 23, 2026 | 报告问题
We are building our information security compliance program and this role sits at the center of that effort. As our Compliance Engineer, you will work directly with the Head of Information Security to design, implement, and operationalize controls across multiple frameworks (SOC 2, ISO 27001, NIS 2, CIS IG3, NERC CIP, and NIST). You will also own customer-facing security assurance, including security questionnaires and audit evidence requests.
This is a high-visibility role for someone energized by building structure in ambiguous environments and who understands that good compliance is good engineering.
Responsibilities
Framework Implementation & Control Management
- Design a unified control framework mapped across SOC 2, ISO 27001, CIS IG3, NERC CIP, and NIST (CSF/800-53), eliminating duplication and creating a single source of truth for compliance posture.
- Develop and maintain a control library, policy inventory, and risk register.
- Translate technical control requirements into actionable guidance for engineering, IT, and operations teams.
Audit Readiness & Evidence Collection
- Build a structured, repeatable evidence collection process supporting concurrent audits across all frameworks.
- Maintain a continuously updated evidence repository and coordinate with Engineering, DevOps, HR, and Legal to gather and validate artifacts.
- Serve as primary liaison with external auditors; manage schedules, fieldwork, and findings remediation through to closure.
Customer Security Assurance
- Own intake, triage, and completion of customer security questionnaires (SIG Lite, CAIQ, custom assessments).
- Maintain a living questionnaire knowledge base and develop customer-facing security documentation, including trust portal content.
Program Development
- Define compliance workflows, SOPs, tooling requirements, and automation opportunities as the program matures.
- Monitor regulatory changes across NERC CIP, NIS 2, and NIST; proactively communicate impacts to the team.
Required Skills
- 2-4 years in information security compliance, GRC, or a related discipline.
- Working knowledge of two or more: SOC 2, ISO 27001, NIST CSF/800-53, CIS Controls, NERC CIP.
- Experience supporting or leading external audits, including evidence collection and auditor coordination.
- Ability to perform cross-framework control mapping and identify gaps or conflicts.
- Strong written communication skills across technical and non-technical audiences.
Bonus Skills
- Hands-on experience with NERC CIP (CIP-002 through CIP-014) in an OT or critical infrastructure environment.
- Familiarity with GRC platforms such as Vanta, Drata, OneTrust, or Archer.
- Certifications: CISA, CRISC, ISO 27001 Lead Implementer/Auditor, or NERC CIP.
$120,000 - $145,000 a year
At this time, Gridware is unable to provide visa sponsorship or immigration support for this role. We're only able to consider candidates who are currently authorized to work in the country of employment without visa sponsorship now or in the future.
This describes the ideal candidate; many of us have picked up this expertise along the way. Even if you meet only part of this list, we encourage you to apply!
Benefits
Health, Dental & Vision (Gold and Platinum with some providers plans fully covered)
Paid parental leave
Alternating day off (every other Monday)
"Off the Grid", a two week per year paid break for all employees.
Commuter allowance
Company-paid training
立即申请
职位已过期?请告知 Gridware 您是在 Rejobs 上找到这份工作的。这将帮助我们成长,并让更多人投身于可再生能源工作!
立即申请
职位已过期?请告知 Gridware 您是在 Rejobs 上找到这份工作的。这将帮助我们成长,并让更多人投身于可再生能源工作!
获取工作提醒
获取旧金山,加利福尼亚州,美国地区网络安全领域职位的提醒
加入人才库
让顶尖清洁能源雇主找到你
职位详情
2026年4月5日
全职
公司
- 旧金山,加利福尼亚州,美国
2-4 years
UTC-07:00