Senior Risk & Compliance Engineer - Data at Instacart — Remote
Full job description
We're transforming the grocery industry
Instacart is a Flex First team
## Overview
Instacart's Governance, Risk and Compliance (GRC) team sits at the intersection of security, data, and business impact — and we're building an automated, engineering-grade risk program that produces real-time risk scoring, quantified exposure models, and ROI-linked investment decisions that reach the CISO, executive leadership, and the board.
We're looking for a Senior Risk & Compliance Engineer to help us get there. This is an engineering role with a data science expertise needed. You'll write production-level code, build signal ingestion pipelines, and develop probabilistic risk models that give our security organization a quantified, confidence-backed view of our risk posture — all in service of protecting Instacart's customers and products at scale.
If you're energized by the challenge of transforming a manual, reactive discipline into a data-driven, automated program — providing value across security, engineering, and executive stakeholders while doing it — this role was built for you.
## About the Job
- Build automated signal ingestion pipelines that pull real-time data from security tooling — normalizing, enriching, and scoring raw findings into actionable, ranked risk intelligence that drives remediation decisions across the organization
- Develop probabilistic risk models that express security exposure as probability distributions, giving leadership a quantified, confidence-backed view of breach likelihood and expected losses — connecting model outputs directly to investment decisions and board-level reporting
- Identify systemic choke points across the attack surface — high-leverage remediation paths where a single fix eliminates risk at scale — and prioritize them by expected impact to maximize the efficiency of our security program
- Build dashboards and data-driven insights that cascade risk visibility across security, engineering, and executive stakeholders, translating complex model outputs into language that resonates at every level of the organization
- Support risk quantification efforts that express security exposure in financial terms, connecting model outputs to investment decisions and board-level reporting
## About You
Minimum Qualifications
- 5+ years of experience in data engineering, with demonstrated ability to write production-level code in Python and SQL (PostgreSQL, Presto, or SparkSQL) — you write production level code for internal tools and infrastructure
- 3+ years of experience building and deploying machine learning or probabilistic models (e.g., Bayesian models) in a production environment
- Experience building data pipelines that ingest real-time or near-real-time data across multiple formats, handling both stream and batch processing at scale
- Experience with data modeling for classification, normalization, and risk or anomaly detection signal development
- Experience developing metrics that inform security and business decisions
Preferred Qualifications
- Familiarity with security risk concepts including threat intelligence enrichment pipelines, EPSS, or CISA KEV
- Familiarity with quantitative risk frameworks such as FAIR
- Exposure to security frameworks such as NIST CSF, SOC 2 as context for what controls the data is measuring
- Demonstrated ability to translate risk model outputs into executive or board-level narratives
- A genuine passion for building systems that protect customers and products, and a track record of operating effectively in fast-paced, ambiguous environments where the program is still being shaped
#LI-Remote
CA, NY, CT, NJ
$188,000—$230,000 USD
WA
$178,000—$220,500 USD
$171,000—$211,000 USD
All other states
$156,000—$192,000 USD
Required skills
- postgresql
- delivery
- python
- machine learning
- sql
- data engineering
- safe
- express
- data science