yandex
B
brex
Страна
США
Зарплата
153 600 $ – 192 000 $
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
SeniorГибридПолная занятость

Senior GRC Lead

Оценка ИИ

Brex — топовый финтех-единорог с сильной инженерной культурой. Вакансия предлагает отличную компенсацию, работу с современным стеком (AI, Tines, Terraform) и высокую степень автономности в принятии решений.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует редкого сочетания глубоких знаний в области комплаенса (SOC 2, PCI DSS) и серьезных технических навыков, включая программирование на Python и работу с инфраструктурой как кодом (Terraform). Высокая планка ответственности за автоматизацию процессов в регулируемой финтех-среде.

Анализ зарплаты

Медиана175 000 $
Рынок145 000 $ – 210 000 $
Оценка ИИ

Предлагаемая зарплата ($153k - $192k) полностью соответствует рыночным стандартам для Senior GRC ролей в Сан-Франциско, где медиана составляет около $175k. С учетом опционов (equity), совокупный доход может значительно превышать рыночные показатели.

Сопроводительное письмо

I am writing to express my strong interest in the Senior GRC Lead position at Brex. With over five years of experience at the intersection of security engineering and compliance, I have developed a specialized focus on automating manual workflows and building scalable GRC architectures in cloud-native environments. My background in implementing SOC 2, PCI DSS, and ISO 27001 frameworks, combined with my technical proficiency in Python and API integrations, aligns perfectly with Brex's mission to build an AI-powered spend platform with world-class security.

In my previous roles, I have successfully translated complex regulatory requirements into actionable technical specifications for engineering teams. I am particularly excited about the opportunity to leverage tools like Tines and Terraform to drive continuous monitoring and automate control testing. My experience in fintech has taught me how to balance rigorous security standards with the speed and agility required in a high-growth environment. I am eager to bring my 'builder mindset' to Brex and contribute to the maturity of your Trust program and AI governance initiatives.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в brex уже сейчас

Присоединяйтесь к Brex, чтобы автоматизировать комплаенс в одной из самых инновационных финтех-компаний мира!

Описание вакансии

Why join us

Brex is the AI-powered spend platform. We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses. Tens of thousands of companies from startups to enterprises — including DoorDash, Flexport, and Compass — use Brex to proactively control spend, reduce costs, and increase efficiency on a global scale.

Working at Brex allows you to push your limits, challenge the status quo, and collaborate with some of the brightest minds in the industry. We’re committed to building a diverse team and inclusive culture and believe your potential should only be limited by how big you can dream. We make this a reality by empowering you with the tools, resources, and support you need to grow your career.

Engineering

Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It’s an environment where engineering is a craft, and builders become leaders.

What you’ll do

Brex’s Governance, Risk, and Compliance function is at an exciting and pivotal point in our maturity journey and we’re seeking a team member who can seamlessly bridge compliance expertise with technical execution. As a Senior GRC Engineer, you will drive critical GRC processes that mitigate risk, keep us compliant, and build trust with our customers and partners. You'll evolve the technical foundation of our Trust program by automating security controls, building integrations between security tools and GRC platforms, and creating scalable processes that enable Brex to maintain compliance efficiently as we expand into new markets. You'll work at the intersection of security, engineering, and compliance — translating regulatory requirements into technical solutions and building automation that eliminates manual toil.

You'll leverage your deep understanding of SOC 2, PCI DSS, ISO 27001, AI governance frameworks, and others to both design controls for emerging compliance requirements and mature existing programs through automation and continuous monitoring. You’ll support Trust Assurance, Third Party Risk Management, and other Security Risk Management initiatives. Working with our Engineering, Infrastructure, and Product teams, you'll translate compliance frameworks into technical controls and build automated systems that help us achieve world-class security as Brex expands.

Your contributions will directly accelerate Brex's maturity. You'll design workflows using Tines, build integrations between security and GRC systems, and create dashboards for security metrics. You'll implement controls across the technology stack, support multiple audits (SOC 2, PCI DSS, SOX/ITGC, FINRA, ISO), and contribute to AI governance framework implementation (ISO 42001, NIST AI RMF, EU AI Act).

You'll have autonomy to build innovative solutions, collaborating cross-functionally to implement controls that enable growth while communicating technical concepts effectively across the organization.

Where you’ll work

This role will be based in our San Francisco office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We currently require a minimum of two coordinated days in the office per week, Wednesday and Thursday. Starting February 2, 2026, we will require three days per week in office - Monday, Wednesday and Thursday. As a perk, we also have up to four weeks per year of fully remote work!

Responsibilities

  • Manage and scale IT infrastructure, services and tooling
  • Work with a diverse group of  IT partners to optimize our provided services
  • Implement new services in support of Information Technologies vision
  • Scale our services by implementing configuration as code via Terraform providers or APIs
  • Operationalize and upskill IT and its partners by producing documentation and leading training sessions
  • Evangelize best practices both internally and externally facing

Requirements

  • 5+ years of experience in GRC, IT Governance, or Security Engineering with a strong track record of automating manual compliance workflows.
  • Deep experience with security frameworks such as SOC 2, PCI DSS, ISO 27001, and NIST CSF, specifically within cloud-native environments.
  • Technical proficiency in Python (or similar scripting languages) and experience building integrations using APIs to connect security tools with GRC systems. You can read code, design integrations, and understand technical implementations.
  • Builder mindset with the ability to design and implement automated control testing, continuous monitoring, and data-driven security metrics. You see manual processes and immediately think about how to automate them.
  • Exceptional cross-functional collaboration and communication skills. You can translate complex compliance requirements into technical specifications that engineering teams can actually implement and influence stakeholders across technical and non-technical domains.
  • Strong systems thinking. You have the ability to design scalable GRC architectures that grow with the company, rather than just solving for the immediate audit.
  • Bias for action.You’re a self-starter who ships solutions quickly and iterates based on feedback.

Bonus points

  • Previous experience in Fintech or banking environments navigating complex regulatory landscapes.
  • Hands-on experience with Tines or other SOAR platforms to automate security operations.
  • Familiarity with AI/ML governance frameworks (NIST AI RMF, ISO 42001) or securing agentic systems.
  • Deep knowledge of Cloud Security (AWS/GCP), infrastructure-as-code (Terraform), or DevSecOps practices.
  • Relevant industry certifications such as CISSP, CISA, or CCSP.
  • Experience building metrics dashboards for security visualization and reporting.
  • Active contributions to the GRC or Security community through open-source projects or public research.

Compensation

The expected salary range for this role is $153,600 - $192,000. However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package.

Please be aware, job-seekers may be at risk of targeting by malicious actors looking for personal data. Brex recruiters will only reach out via LinkedIn or email with a brex.com domain. Any outreach claiming to be from Brex via other sources should be ignored.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • AWS
  • Python
  • Terraform
  • GCP
  • SOC 2
  • ISO 27001
  • PCI DSS
  • CISA
  • CISSP
  • API
  • DevSecOps
  • CCSP
  • SOX
  • FINRA
  • NIST CSF
  • Tines

Возможные вопросы на собеседовании

Проверка технического подхода к автоматизации, что является ключевым требованием вакансии.

Опишите ваш опыт использования Python или API для автоматизации конкретного процесса комплаенса, который ранее выполнялся вручную.

Brex активно внедряет ИИ, и знание этих фреймворков указано как важное преимущество.

Как бы вы подошли к внедрению NIST AI RMF или ISO 42001 в облачной инфраструктуре Brex?

Вакансия предполагает работу на стыке отделов; важно уметь доносить ценность GRC до разработчиков.

Как вы убеждаете инженерные команды внедрять контроли безопасности, которые могут замедлить их темп разработки?

Проверка опыта работы с современными инструментами автоматизации безопасности.

Есть ли у вас опыт работы с Tines или другими SOAR-платформами для создания рабочих процессов безопасности?

Оценка способности кандидата проектировать системы на перспективу, а не только для прохождения текущего аудита.

Расскажите о случае, когда вам пришлось проектировать архитектуру GRC с учетом будущего масштабирования компании на новые рынки.

Похожие вакансии

J
JETLYN
210 000 ₽ – 260 000 ₽

Специалист по защите информации (Mobile Security Engineer)

SeniorУдалённоРоссия
iOS · Cryptography · Jailbreak · HTTPS · REST API · gRPC · TCP · UDP · HTTP · Protobuf · JSON · Avro · MessagePack · Reverse Engineering
+14 навыков
AG
Atom group
4 000 $ – 5 000 $

Senior Information Security (ИБ)

SeniorУдалённоБеларусь
Information Security · DevSecOps · SDLC · Risk Management · Security Policy · DevOps
+6 навыков
S
SDOdev
380 000 ₽ – 500 000 ₽

Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)

SeniorУдалённоРоссия
Android · iOS · TCP/IP · HTTPS · Cryptography · MITM · Frida · Objection · Apktool · Jadx · Hopper · Smali · Hermes · Swift · Dart · Objective-C · C++ · Reverse Engineering · Cybersecurity
+19 навыков
NDA
Не указана

Senior AppSecOps Engineer

SeniorУдалённоБеларусь
AppSec · C++ · Go · Java · SAST · SCA · Svace · CodeScoring · Jira · GitLab · GCC · Make · Linux Kernel
+13 навыков
I
Innostaff
Не указана

Сеньор AppSecOps-инженер

SeniorУдалённоБеларусь
AppSecOps · DevSecOps · SAST · DAST · SCA · CI/CD · Cybersecurity · Kubernetes · Docker
+9 навыков
MW
MTS Web Services
250 000 ₽ – 300 000 ₽

Старший эксперт SIEM

SeniorВ офисеРоссия
SIEM · SoC · Linux · Windows · macOS · CCNA · LPIC-1 · Cybersecurity · Incident Response · Network Security
+10 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

B
brex
Страна
США
Зарплата
153 600 $ – 192 000 $