Senior Grc Lead

Brex Brex · Fintech · New York, NY +1 · Engineering

Brex is seeking a Senior GRC Lead to drive critical GRC processes, mitigate risk, and ensure compliance. The role involves automating security controls, building integrations between security and GRC platforms, and creating scalable processes. The ideal candidate will leverage expertise in security frameworks and AI governance to design controls, mature existing programs through automation, and support various audits. This role requires a builder mindset with strong technical proficiency in scripting and API integrations, and the ability to translate complex compliance requirements into technical solutions.

What you'd actually do

  1. Manage and scale IT infrastructure, services and tooling
  2. Work with a diverse group of IT partners to optimize our provided services
  3. Implement new services in support of Information Technologies vision
  4. Scale our services by implementing configuration as code via Terraform providers or APIs
  5. Operationalize and upskill IT and its partners by producing documentation and leading training sessions
  6. Evangelize best practices both internally and externally facing

Skills

Required

  • 5+ years of experience in GRC, IT Governance, or Security Engineering
  • Deep experience with security frameworks such as SOC 2, PCI DSS, ISO 27001, and NIST CSF, specifically within cloud-native environments
  • Technical proficiency in Python (or similar scripting languages)
  • experience building integrations using APIs to connect security tools with GRC systems
  • systems thinking
  • cross-functional collaboration and communication skills

Nice to have

  • Fintech or banking environments
  • Tines or other SOAR platforms
  • AI/ML governance frameworks (NIST AI RMF, ISO 42001)
  • securing agentic systems

What the JD emphasized

  • automating manual compliance workflows
  • design and implement automated control testing, continuous monitoring, and data-driven security metrics
  • translate complex compliance requirements into technical specifications
  • AI governance frameworks