Senior Grc Lead

Brex Brex · Fintech · New York, NY +1 · Engineering

This role focuses on building and automating GRC processes within a fintech company, translating regulatory requirements into technical solutions. It involves integrating security tools, creating scalable compliance processes, and implementing controls across the technology stack, including AI governance frameworks. The goal is to maintain compliance and build trust as the company expands.

What you'd actually do

  1. Manage and scale IT infrastructure, services and tooling
  2. Work with a diverse group of IT partners to optimize our provided services
  3. Implement new services in support of Information Technologies vision
  4. Scale our services by implementing configuration as code via Terraform providers or APIs
  5. Operationalize and upskill IT and its partners by producing documentation and leading training sessions
  6. Evangelize best practices both internally and externally facing

Skills

Required

  • 5+ years of experience in GRC, IT Governance, or Security Engineering
  • strong track record of automating manual compliance workflows
  • Deep experience with security frameworks such as SOC 2, PCI DSS, ISO 27001, and NIST CSF
  • Technical proficiency in Python (or similar scripting languages)
  • experience building integrations using APIs
  • systems thinking
  • cross-functional collaboration and communication skills

Nice to have

  • Fintech or banking environments
  • Tines or other SOAR platforms

What the JD emphasized

  • automating manual compliance workflows
  • automating security controls
  • building integrations between security tools and GRC platforms
  • creating scalable processes
  • automating manual toil
  • design controls for emerging compliance requirements
  • mature existing programs through automation
  • continuous monitoring
  • automated systems
  • build automated systems
  • design workflows using Tines
  • build integrations between security and GRC systems
  • create dashboards for security metrics
  • implement controls across the technology stack
  • support multiple audits
  • contribute to AI governance framework implementation
  • build innovative solutions
  • implement controls that enable growth
  • automating manual compliance workflows
  • building integrations using APIs
  • design and implement automated control testing
  • continuous monitoring
  • data-driven security metrics
  • automate them