Senior Grc Lead

Brex Brex · Fintech · New York, NY +1 · Engineering

This role focuses on building and automating GRC processes within a fintech company, ensuring compliance with various security frameworks and regulations. The Senior GRC Lead will translate regulatory requirements into technical solutions, build integrations between security and GRC systems, and create scalable automation to manage risk and maintain compliance as the company grows. The role emphasizes a builder mindset, strong systems thinking, and cross-functional collaboration to implement controls and drive continuous monitoring.

What you'd actually do

  1. Manage and scale IT infrastructure, services and tooling
  2. Work with a diverse group of IT partners to optimize our provided services
  3. Implement new services in support of Information Technologies vision
  4. Scale our services by implementing configuration as code via Terraform providers or APIs
  5. Operationalize and upskill IT and its partners by producing documentation and leading training sessions
  6. Evangelize best practices both internally and externally facing

Skills

Required

  • 5+ years of experience in GRC, IT Governance, or Security Engineering
  • automating manual compliance workflows
  • Deep experience with security frameworks such as SOC 2, PCI DSS, ISO 27001, and NIST CSF
  • cloud-native environments
  • Python (or similar scripting languages)
  • building integrations using APIs
  • connect security tools with GRC systems
  • read code, design integrations, and understand technical implementations
  • design and implement automated control testing
  • continuous monitoring
  • data-driven security metrics
  • Exceptional cross-functional collaboration and communication skills
  • translate complex compliance requirements into technical specifications
  • influence stakeholders across technical and non-technical domains
  • Strong systems thinking
  • design scalable GRC architectures
  • Bias for action
  • self-starter who ships solutions quickly and iterates based on feedback

Nice to have

  • Fintech or banking environments
  • navigating complex regulatory landscapes
  • Tines or other SOAR platforms
  • AI/ML governance frameworks (NIST AI RMF, ISO 42001)
  • securing agentic systems

What the JD emphasized

  • automating manual compliance workflows
  • cloud-native environments
  • building integrations using APIs
  • design and implement automated control testing
  • continuous monitoring
  • data-driven security metrics
  • design scalable GRC architectures