Mondays start in the GRC platform: whatever failed over the weekend — an unencrypted volume, a public bucket, an offboarding that didn’t complete — gets root-caused and either corrected directly or turned into a precise, pre-scoped ticket. Midweek is evidence work: writing the scripts that pull records automatically, uploading what can’t be automated, keeping screenshots and exports inside their freshness windows. There’s a standing block for people-driven controls — access reviews, security-training completion, background checks on new hires — and, in audit season, for pulling the samples the auditor requests.
The title matters because of what it isn’t: a GRC analyst manages documents and risk registers, while a compliance engineer works in IAM policies, Terraform, and CI pipelines. The formal definition sits in the glossary under compliance engineer.
A startup with one framework generates a few hundred hours of this work a year — too much to ignore, too little to hire for. That arithmetic is what managed providers are built on: Agency assigns compliance engineers across a small set of clients, under vCISO leadership that owns strategy while the engineers own execution.
No — the analyst role centers on documentation, risk registers, and process; the engineering role centers on cloud, identity, and automation. Mature programs need both, and they’re rarely the same person.
A fraction of one. Before a few hundred employees you need recurring hours, not a headcount line — which is why the role is commonly bought through managed compliance services instead of hired.