Senior GRC Lead
$153.6k - $192kBrex
What You’ll Do Brex’s Governance, Risk, and Compliance function is at an exciting and pivotal point in our maturity journey and we’re seeking a team member who can seamlessly bridge compliance expertise with technical execution. As a Senior GRC Engineer , you will drive critical GRC processes that mitigate risk, keep us compliant, and build trust with our customers and partners. You’ll evolve the technical foundation of our Trust program by automating security controls, building integrations between security tools and GRC platforms, and creating scalable processes that enable Brex to maintain compliance efficiently as we expand into new markets. You’ll work at the intersection of security, engineering, and compliance — translating regulatory requirements into technical solutions and building automation that eliminates manual toil. You’ll leverage your deep understanding of SOC 2, PCI DSS, ISO 27001, AI governance frameworks, and others to both design controls for emerging compliance requirements and mature existing programs through automation and continuous monitoring. You’ll support Trust Assurance, Third Party Risk Management, and other Security Risk Management initiatives. Working with our Engineering, Infrastructure, and Product teams, you'll translate compliance frameworks into technical controls and build automated systems that help us achieve world-class security as Brex expands. Your contributions will directly accelerate Brex's maturity. You’ll design workflows using Tines, build integrations between security and GRC systems, and create dashboards for security metrics. You’ll implement controls across the technology stack, support multiple audits (SOC 2, PCI DSS, SOX/ITGC, FINRA, ISO), and contribute to AI governance framework implementation (ISO 42001, NIST AI RMF, EU AI Act). You’ll have autonomy to build innovative solutions, collaborating cross-functionally to implement controls that enable growth while communicating technical concepts effectively across the organization. Where you’ll work This role will be based in our New York office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We require a minimum of two coordinated days in the office per week, Wednesday and Thursday. Up to four weeks per year of fully remote work is available. Responsibilities Manage and scale IT infrastructure, services and tooling Work with a diverse group of IT partners to optimize our provided services Implement new services in support of Information Technologies vision Scale our services by implementing configuration as code via Terraform providers or APIs Operationalize and upskill IT and its partners by producing documentation and leading training sessions Evangelize best practices both internally and externally facing Requirements 5+ years of experience in GRC, IT Governance, or Security Engineering with a strong track record of automating manual compliance workflows. Deep experience with security frameworks such as SOC 2, PCI DSS, ISO 27001, and NIST CSF, specifically within cloud-native environments. Technical proficiency in Python (or similar scripting languages) and experience building integrations using APIs to connect security tools with GRC systems. You can read code, design integrations, and understand technical implementations. Builder mindset with the ability to design and implement automated control testing, continuous monitoring, and data-driven security metrics. You see manual processes and immediately think about how to automate them. Exceptional cross-functional collaboration and communication skills. You can translate complex compliance requirements into technical specifications that engineering teams can actually implement and influence stakeholders across technical and non-technical domains. Strong systems thinking. You have the ability to design scalable GRC architectures that grow with the company, rather than just solving for the immediate audit. Bias for action. You’re a self-starter who ships solutions quickly and iterates based on feedback. Bonus points Previous experience in Fintech or banking environments navigating complex regulatory landscapes. Hands-on experience with Tines or other SOAR platforms to automate security operations. Familiarity with AI/ML governance frameworks (NIST AI RMF, ISO 42001) or securing agentic systems. Deep knowledge of Cloud Security (AWS/GCP), infrastructure-as-code (Terraform), or DevSecOps practices. Relevant industry certifications such as CISSP, CISA, or CCSP. Experience building metrics dashboards for security visualization and reporting. Active contributions to the GRC or Security community through open-source projects or public research. Compensation The expected salary range for this role is $153,600 - $192,000. However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package. #J-18808-Ljbffr Brex
- ...A leading consulting firm seeks a Governance, Risk, and Compliance (GRC) leader to advance their programs. This remote role requires 5–7 years of experience in GRC with relevant certifications like CISSP or CISM. The successful candidate will lead policy development, perform...SeniorRemote work
$122.5k - $175k
...compliance at their U.S. locations. The successful candidate will enhance compliance tasks through intelligent automation, redesign GRC processes, and mentor junior staff. Ideal applicants will have a strong background in AI/ML architecture and GRC engineering, with a...SeniorFull time$95k - $110k
...Blackkite is looking for a Senior GRC Analyst to oversee compliance efforts and support customer security assessments in the United States. This role requires expertise in compliance frameworks like SOC 2 and ISO 27001, along with strong communication skills. The successful...SeniorFlexible hours- A leading fintech company in New York is seeking a Senior GRC Lead who will bridge compliance expertise with technical execution. You will manage critical GRC processes to enhance risk management and compliance measures. Candidates should have over 5 years of experience...SeniorWork at office
$95k - $105k
...Subsplash is looking for a Senior GRC Analyst to integrate people, policy, and technology to enhance security and risk operations. This role involves leading compliance audits, developing data flows, and tracking risk management metrics. With a competitive compensation...SeniorRemote work- Globalchannelmanagement is seeking a GRC Lead with 10 years of experience in governance, risk, and compliance. The ideal candidate will lead the implementation and management of audit technology platforms, specifically AuditBoard, and support public company SOX 404 compliance...Senior
- Oura is seeking a Senior Governance, Risk, Compliance (GRC) Analyst to join the Security Team in New York City. This role involves leading GRC initiatives, managing compliance policies, and performing risk assessments. Candidates should have over 6 years of experience...SeniorRemote workFlexible hours
- ...Lynk is seeking a Senior Cybersecurity Compliance Officer (ISSO) to oversee compliance programs aligned with CMMC Level 2, NIST SP 800‑171, and more. This remote position requires 3–6 years in cybersecurity, with a strong focus on governance, risk, and compliance. The...SeniorRemote work
- ...Zscaler is looking for a senior compliance manager to lead FedRAMP and DoD compliance programs in the United States. This position requires over 10 years of experience and an active U.S. Secret or Top Secret/SCI security clearance. Candidates must possess expertise in...Senior
- ...HealthTech company in New York is seeking a Senior Manager - Information Security, Governance... ...governance, oversee risk assessments, and lead incident response processes. Ideal... ...familiarity with AWS, and experience with GRC tooling. This role offers competitive benefits...Senior
$85k - $167k
...A leading technology company is seeking a Program Manager / Senior Analyst to oversee the lifecycle management of sensitive U.S. government authorizations. This role... ...candidate should have over 5 years of experience in GRC or IT auditing, deep knowledge of NIST standards,...Senior$106.61k - $284.28k
CVS Health is seeking a Cyber Resiliency Manager to define operational activities and execute on strategic direction related to cyber resiliency. The ideal candidate will have at least 7 years of experience in cyber resiliency and internal audit, with a strong understanding...Senior- CVS Health is seeking a Cyber Resiliency Manager to drive operational activities related to cyber resiliency. This role will manage and implement strategic directions, consult on improving internal controls, and partner with stakeholders for effective cybersecurity practices...Senior
$160k - $190k
Alldus is seeking an experienced ServiceNow Architect/Lead Developer to join their team in New York, NY. This role focuses on IRM/GRC and Third-Party Risk Management (TPRM). You will be responsible for leading the development team, creating technical roadmaps, and implementing...Senior$165k - $175k
Position Overview Hearst Technology’s Governance, Risk & Compliance (GRC) organization is seeking a Senior Governance Lead to drive enterprise IT governance strategy, policy architecture, and IT governance program maturity across Hearst’s diverse portfolio of businesses...Senior- ...Anthesis Group is seeking a Senior/Principal Consultant for their Lifecycle Assessment (LCA) team in the USA. This role involves leading technical projects, ensuring compliance with ISO standards, and engaging with clients to tailor solutions. The ideal candidate will...Senior
- ...Owner.com is seeking a GRC Specialist to navigate complex Risk, Compliance, and Vulnerability Management as we grow. You will drive compliance efforts, secure systems, and advise senior leadership in security risks. Requires 3+ years in compliance frameworks and 5+ years...Remote work
- ...Bitcoin Depot is hiring a Security and GRC Manager to oversee security, GRC, and IT endpoint management in a remote-first environment... ...implement security policies, manage third-party vendor assessments, and lead compliance initiatives. Essential duties include conducting...Remote work
- ...A cutting-edge technology firm in the United States is seeking a Senior GRC Analyst. The role requires 5+ years of experience in risk management, compliance, and governance. You will support the organization's GRC program, maintain security compliance frameworks, and...SeniorRemote work
- ...Expertise in ERP controls for SAP, Oracle, and NetSuite. Solid understanding of IT General Controls (ITGC). Proficiency with data analytics tools such as Power BI, Tableau, or advanced Excel. Familiarity with GRC frameworks and regulatory standards...
$90k - $100k
...Cognisys is seeking a Senior Information Consultant to join its GRC Consulting team. The role involves leading GRC engagements, mentoring junior staff, and providing high-quality advisory services. The candidate must have over 5 years of experience in security and compliance...SeniorRemote work$95k - $105k
...Subsplash is looking for a GRC Analyst to join its Remote team in the United States. In this role, you'll be a strategic lead in advancing security and risk operations by identifying gaps and implementing best practices. With a salary range of $95,000-$105,000/yr, you...SeniorRemote work$70k - $90k
A leading technology firm is seeking an Audit Board (GRC) Implementation Specialist. This remote role requires over 10 years of experience and deep technical expertise in implementing API-based integrations across GRC ecosystems. The candidate will lead platform administration...Remote work- ...We are seeking a highly skilled GRC Tech Lead with a strong focus on AuditBoard to join our team. The successful candidate will have extensive experience supporting/managing audit technology platforms. You will lead the configuration and governance of AuditBoard...
- ...RegScale is hiring a Senior Content Marketing Manager to lead the brand voice and content strategy, generating awareness and demand across all channels.... ...SaaS content marketing, preferably in cybersecurity or GRC. Responsibilities include developing a full editorial calendar...Senior
- ...Framework Ventures is seeking a Security GRC Lead to enhance trust and safeguard reputation by scaling governance, risk, and compliance programs. The ideal candidate will have over 6 years of experience in security governance, risk management, and compliance, with deep...Remote workFlexible hours
- ...A telehealth company is seeking a GRC Engineer to enhance their security governance and compliance automation. The role involves building workflows, integrating systems, and creating dashboards for real-time insights. Candidates should have over 5 years of experience,...Senior
$225k - $250k
The Blackstone Group L.P. is seeking a Principal for its BXMA Credit Team in New York. The role involves leading investment sourcing, underwriting, and monitoring across various credit asset classes. Ideal candidates will have over 5 years of experience in relevant fields...Senior- ...A leading cybersecurity company is seeking a Senior Governance, Risk & Compliance Specialist to join their Technology Risk & Compliance team. This remote role... ...preferred hybrid near San Jose, CA, involves implementing GRC frameworks for FedRAMP and DoD authorizations,...SeniorRemote work
- ...Gifts Officer to identify and manage significant donations of $1 million and more. This role involves cultivating relationships with senior leadership, faculty, and volunteers in support of pediatric and OBGYN initiatives. Candidates should have at least six years of...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Lead. Be the first to apply!
- senior development executive New York, NY
- senior technical manager New York, NY
- senior medical writer New York, NY
- senior procurement specialist New York, NY
- senior software development engineer in test New York, NY
- senior communications specialist New York, NY
- senior manager data science New York, NY
- senior platform engineer New York, NY
- senior procurement New York, NY
- senior director product management New York, NY

