Senior GRC Lead
$153.6k - $192kBrex
What you’ll do Brex’s Governance, Risk, and Compliance function is at an exciting and pivotal point in our maturity journey and we’re seeking a team member who can seamlessly bridge compliance expertise with technical execution. As a Senior GRC Engineer, you will drive critical GRC processes that mitigate risk, keep us compliant, and build trust with our customers and partners. You'll evolve the technical foundation of our Trust program by automating security controls, building integrations between security tools and GRC platforms, and creating scalable processes that enable Brex to maintain compliance efficiently as we expand into new markets. You'll work at the intersection of security, engineering, and compliance — translating regulatory requirements into technical solutions and building automation that eliminates manual toil. You’ll leverage your deep understanding of SOC 2, PCI DSS, ISO 27001, AI governance frameworks, and others to both design controls for emerging compliance requirements and mature existing programs through automation and continuous monitoring. You’ll support Trust Assurance, Third Party Risk Management, and other Security Risk Management initiatives. Working with our Engineering, Infrastructure, and Product teams, you'll translate compliance frameworks into technical controls and build automated systems that help us achieve world-class security as Brex expands. Your contributions will directly accelerate Brex's maturity. You'll design workflows using Tines, build integrations between security and GRC systems, and create dashboards for security metrics. You'll implement controls across the technology stack, support multiple audits (SOC 2, PCI DSS, SOX/ITGC, FINRA, ISO), and contribute to AI governance framework implementation (ISO 42001, NIST AI RMF, EU AI Act). You’ll have autonomy to build innovative solutions, collaborating cross-functionally to implement controls that enable growth while communicating technical concepts effectively across the organization. Where you’ll work This role will be based in our New York office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We currently require a minimum of two coordinated days in the office per week, Wednesday and Thursday. Starting February 2, 2026, we will require three days per week in office - Monday, Wednesday and Thursday. As a perk, we also have up to four weeks per year of fully remote work! Responsibilities Manage and scale IT infrastructure, services and tooling Work with a diverse group of IT partners to optimize our provided services Implement new services in support of Information Technologies vision Scale our services by implementing configuration as code via Terraform providers or APIs Operationalize and upskill IT and its partners by producing documentation and leading training sessions Evangelize best practices both internally and externally facing Requirements 5+ years of experience in GRC, IT Governance, or Security Engineering with a strong track record of automating manual compliance workflows. Deep experience with security frameworks such as SOC 2, PCI DSS, ISO 27001, and NIST CSF, specifically within cloud-native environments. Technical proficiency in Python (or similar scripting languages) and experience building integrations using APIs to connect security tools with GRC systems. You can read code, design integrations, and understand technical implementations. Builder mindset with the ability to design and implement automated control testing, continuous monitoring, and data-driven security metrics. You see manual processes and immediately think about how to automate them. Exceptional cross-functional collaboration and communication skills. You can translate complex compliance requirements into technical specifications that engineering teams can actually implement and influence stakeholders across technical and non-technical domains. Strong systems thinking. You have the ability to design scalable GRC architectures that grow with the company, rather than just solving for the immediate audit. Bias for action. You’re a self-starter who ships solutions quickly and iterates based on feedback. Bonus points Previous experience in Fintech or banking environments navigating complex regulatory landscapes. Hands-on experience with Tines or other SOAR platforms to automate security operations. Familiarity with AI/ML governance frameworks (NIST AI RMF, ISO 42001) or securing agentic systems. Deep knowledge of Cloud Security (AWS/GCP), infrastructure-as-code (Terraform), or DevSecOps practices. Relevant industry certifications such as CISSP, CISA, or CCSP. Experience building metrics dashboards for security visualization and reporting. Active contributions to the GRC or Security community through open-source projects or public research. Compensation The expected salary range for this role is $153,600 - $192,000. However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package. #J-18808-Ljbffr Brex
- ...ISACA is looking for a Senior Risk Advisory GRC Consultant to lead client engagements focusing on information security and compliance across various frameworks such as SOC 2 and ISO 27001. This remote position allows you to engage with cutting-edge technology while managing...SeniorRemote work
- ...A leading consulting firm seeks a Governance, Risk, and Compliance (GRC) leader to advance their programs. This remote role requires 5–7 years of experience in GRC with relevant certifications like CISSP or CISM. The successful candidate will lead policy development, perform...SeniorRemote work
- ...Radar Labs, Inc. is seeking a Senior GRC Analyst to enhance their security and compliance programs with a focus on third-party risk. This role involves collaborating with multiple teams, evaluating modern SaaS and AI tools, and improving risk management workflows. The...SeniorFlexible hours
- ...Sensiba is seeking a Senior GRC Analyst with expertise in SOC 2 audits and compliance. This role involves leading engagements, ensuring client satisfaction and managing relationships to meet compliance needs. Candidates should have a robust background in IT audit, particularly...SeniorRemote workFlexible hours
- ...Neier Inc. is seeking a highly skilled GRC Privacy Senior Analyst to lead privacy initiatives and ensure compliance with global data protection regulations. The role involves conducting Privacy Impact Assessments, developing Records of Processing, and managing Data Subject...SeniorRemote work
- A leading fintech company in New York is seeking a Senior GRC Lead who will bridge compliance expertise with technical execution. You will manage critical GRC processes to enhance risk management and compliance measures. Candidates should have over 5 years of experience...SeniorWork at office
$122.5k - $175k
...compliance at their U.S. locations. The successful candidate will enhance compliance tasks through intelligent automation, redesign GRC processes, and mentor junior staff. Ideal applicants will have a strong background in AI/ML architecture and GRC engineering, with a...SeniorFull time$95k - $110k
...Blackkite is looking for a Senior GRC Analyst to oversee compliance efforts and support customer security assessments in the United States. This role requires expertise in compliance frameworks like SOC 2 and ISO 27001, along with strong communication skills. The successful...SeniorFlexible hours- ...Oura is seeking a Senior Governance, Risk, Compliance (GRC) Analyst to join the Security Team in New York City. This role involves leading GRC initiatives, managing compliance policies, and performing risk assessments. Candidates should have over 6 years of experience...SeniorRemote workFlexible hours
$150k - $165k
...and at scale. Job Summary Earned is hiring an Information Security Lead to own and operate our security governance, compliance, and risk... ...’s degree in a related field 5+ years of hands-on experience in GRC, security compliance, IT audit, or security program management Direct...SeniorLocal areaRemote work- Globalchannelmanagement is seeking a GRC Lead with 10 years of experience in governance, risk, and compliance. The ideal candidate will lead the implementation and management of audit technology platforms, specifically AuditBoard, and support public company SOX 404 compliance...Senior
$135.32k - $163.98k
Bristol Myers Squibb is looking for a Sr Manager, ServiceNow in Princeton, NJ. This role centers on designing and maintaining the ServiceNow technical architecture, collaborating with various teams to enhance the platform. The ideal candidate will have over 8 years in ...Senior- ...Lynk is seeking a Senior Cybersecurity Compliance Officer (ISSO) to oversee compliance programs aligned with CMMC Level 2, NIST SP 800‑171, and more. This remote position requires 3–6 years in cybersecurity, with a strong focus on governance, risk, and compliance. The...SeniorRemote work
- ...HealthTech company in New York is seeking a Senior Manager - Information Security, Governance... ...governance, oversee risk assessments, and lead incident response processes. Ideal... ...familiarity with AWS, and experience with GRC tooling. This role offers competitive benefits...Senior
- Zscaler is looking for a senior compliance manager to lead FedRAMP and DoD compliance programs in the United States. This position requires over 10 years of experience and an active U.S. Secret or Top Secret/SCI security clearance. Candidates must possess expertise in AI...Senior
- ...Neier Inc. is seeking an Experienced or Senior GRC Analyst to lead cybersecurity and compliance initiatives. This full-time, remote position will focus on risk assessments, developing compliance programs, and mentoring junior analysts. The ideal candidate has over 5 years...SeniorFull timeRemote work
- ...Sysintegra Pty Ltd is looking for a ServiceNow Lead Consultant to help design and implement solutions for clients, ensuring alignment with their business requirements. The role encompasses assessing current processes, defining solution requirements, and developing comprehensive...Senior
- SOFTNET VENTURES INC is looking for a Sr. Cybersecurity Analyst II responsible for implementing cybersecurity solutions and managing risks within the organization. This role includes evaluating systems for vulnerabilities, coordinating with technical teams, and ensuring...Senior
$85k - $167k
...A leading technology company is seeking a Program Manager / Senior Analyst to oversee the lifecycle management of sensitive U.S. government authorizations. This role... ...candidate should have over 5 years of experience in GRC or IT auditing, deep knowledge of NIST standards,...Senior- ...A leading Health-Tech firm in the United States is seeking a Senior Manager for Information Security, Governance, Risk, and Compliance. In this role, you will lead security governance processes and oversee incident response, all while driving the Information Security program...Senior
- ...Origami Risk LLC. is seeking a Group Product Manager to lead a team of Product Managers. The ideal candidate will ensure cohesive product strategies through effective use of AI and insights. This role requires strong leadership, analytical, and communication skills, along...SeniorRemote workFlexible hours
$165k - $175k
Position Overview Hearst Technology’s Governance, Risk & Compliance (GRC) organization is seeking a Senior Governance Lead to drive enterprise IT governance strategy, policy architecture, and IT governance program maturity across Hearst’s diverse portfolio of businesses...Senior$195k - $280k
Holthouse Carlin & Van Trigt LLP, based in New York, is searching for a Tax Manager to oversee the review of federal and multi-state income tax returns. The successful candidate will have over 10 years of technical tax experience, including leadership in managing teams...Senior- ...Anthesis Group is seeking a Senior/Principal Consultant for their Lifecycle Assessment (LCA) team in the USA. This role involves leading technical projects, ensuring compliance with ISO standards, and engaging with clients to tailor solutions. The ideal candidate will...Senior
- ...Collaborative Solutions, LLC is looking for a Senior Principal Consultant specializing in Workday Absence & Time Tracking. This role... ...technical teams, guiding clients through the implementation, and leading project workstreams. The ideal candidate will have over 4 years...Senior
- ...Owner.com is seeking a GRC Specialist to navigate complex Risk, Compliance, and Vulnerability Management as we grow. You will drive compliance efforts, secure systems, and advise senior leadership in security risks. Requires 3+ years in compliance frameworks and 5+ years...Remote work
- ...Fint Solutions is hiring for the role of IT GRC Controls focused on managing and overseeing compliance within technology governance. The ideal candidate will have a Bachelor's degree in Information Systems or a related field and at least 3-5 years of relevant experience...
- ...Olympus Corporation of the Americas is seeking a Senior IT Security GRC Analyst to oversee governance structures for IT Security, ensuring adherence to global standards. This hybrid position is based in Pennsylvania and requires expertise in cybersecurity frameworks....
$153k - $214k
1Password is seeking a Senior Security Engineer – GRC Controls and Audit to direct compliance audit programs and lead technical audit walkthroughs with external auditors. This role demands over 5 years of experience in the GRC space, particularly strong in SOC 2 Type II...SeniorRemote work- ...A cutting-edge technology firm in the United States is seeking a Senior GRC Analyst. The role requires 5+ years of experience in risk management, compliance, and governance. You will support the organization's GRC program, maintain security compliance frameworks, and...SeniorRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Lead. Be the first to apply!
- senior fund accountant New York, NY
- senior office manager New York, NY
- senior director ecommerce New York, NY
- senior automation controls engineer New York, NY
- senior accounts payable New York, NY
- senior brand designer New York, NY
- senior financial advisor New York, NY
- senior underwriter New York, NY
- senior cost analyst New York, NY
- senior business analyst contract New York, NY

