Senior GRC Lead

Visa Hunt

Vancouver

On-site

CAD 154,000 - 192,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Brex is seeking a Senior GRC Engineer to join our Governance, Risk, and Compliance team in Vancouver. The role bridges compliance expertise with technical execution, automating security controls and building scalable GRC solutions across the tech stack.

You will work at the intersection of security, engineering, and compliance, translating regulatory requirements into technical controls while expanding into new markets.

Qualifications

  • 5+ years of experience in GRC, IT Governance, or Security Engineering with a strong track record of automating manual compliance workflows.
  • Deep experience with security frameworks such as SOC 2, PCI DSS, ISO 27001, and NIST CSF, specifically within cloud-native environments.
  • Technical proficiency in Python (or similar scripting languages) and experience building integrations using APIs to connect security tools with GRC systems.
  • Builder mindset with the ability to design and implement automated control testing and continuous monitoring.
  • Exceptional cross-functional collaboration and communication skills to translate complex requirements into technical specs.
  • Strong systems thinking to design scalable GRC architectures that grow with the company.
  • Bias for action; self-starter who ships solutions quickly and iterates based on feedback.

Responsibilities

  • Manage and scale IT infrastructure, services and tooling.
  • Work with a diverse group of IT partners to optimize provided services.
  • Implement new services in support of Information Technologies vision.
  • Scale services by implementing configuration as code via Terraform providers or APIs.
  • Operationalize and upskill IT and its partners by producing documentation and leading training sessions.
  • Evangelize best practices both internally and externally facing.

Skills

GRC experience
Automation of compliance workflows
Python
APIs integration
Cross-functional collaboration
Systems thinking
Bias for action

Tools

Terraform

Job description

Why join us

Brex is the intelligent finance platform that enables companies to spend smarter and move faster in more than 200 markets. By combining global corporate cards and banking with intuitive spend management, bill pay, and travel software, Brex enables founders and finance teams to accelerate operations, gain real-time visibility, and control spend effortlessly. Brex’s AI-native automation and world-class service eliminate manual expense and accounting tasks for customers so they can focus on what matters most. Tens of thousands of the world's best companies run on Brex, including DoorDash, Coinbase, Robinhood, Zoom, Plaid, Reddit, and SeatGeek.

Working at Brex allows you to push your limits, challenge the status quo, and collaborate with some of the brightest minds in the industry. We’re committed to building a diverse team and inclusive culture and believe your potential should only be limited by how big you can dream. We make this a reality by empowering you with the tools, resources, and support you need to grow your career.

Engineering

Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It’s an environment where engineering is a craft, and builders become leaders.

What you’ll do

Brex’s Governance, Risk, and Compliance function is at an exciting and pivotal point in our maturity journey and we’re seeking a team member who can seamlessly bridge compliance expertise with technical execution. As a Senior GRC Engineer, you will drive critical GRC processes that mitigate risk, keep us compliant, and build trust with our customers and partners. You'll evolve the technical foundation of our Trust program by automating security controls, building integrations between security tools and GRC platforms, and creating scalable processes that enable Brex to maintain compliance efficiently as we expand into new markets. You'll work at the intersection of security, engineering, and compliance — translating regulatory requirements into technical solutions and building automation that eliminates manual toil.

You’ll leverage your deep understanding of SOC 2, PCI DSS, ISO 27001, AI governance frameworks, and others to both design controls for emerging compliance requirements and mature existing programs through automation and continuous monitoring. You’ll support Trust Assurance, Third Party Risk Management, and other Security Risk Management initiatives. Working with our Engineering, Infrastructure, and Product teams, you’ll translate compliance frameworks into technical controls and build automated systems that help us achieve world-class security as Brex expands.

Your contributions will directly accelerate Brex's maturity. You'll design workflows using Tines, build integrations between security and GRC systems, and create dashboards for security metrics. You'll implement controls across the technology stack, support multiple audits (SOC 2, PCI DSS, SOX/ITGC, FINRA, ISO), and contribute to AI governance framework implementation (ISO 42001, NIST AI RMF, EU AI Act).

You’ll have autonomy to build innovative solutions, collaborating cross-functionally to implement controls that enable growth while communicating technical concepts effectively across the organization.

Where you’ll work

This role will be based in our Vancouver office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We currently require a minimum of three coordinated days in the office per week, Monday, Wednesday and Thursday. As a perk, we also have up to four weeks per year of fully remote work!

Responsibilities
  • Manage and scale IT infrastructure, services and tooling
  • Work with a diverse group of IT partners to optimize our provided services
  • Implement new services in support of Information Technologies vision
  • Scale our services by implementing configuration as code via Terraform providers or APIs
  • Operationalize and upskill IT and its partners by producing documentation and leading training sessions
  • Evangelize best practices both internally and externally facing
Requirements
  • 5+ years of experience in GRC, IT Governance, or Security Engineering with a strong track record of automating manual compliance workflows.
  • Deep experience with security frameworks such as SOC 2, PCI DSS, ISO 27001, and NIST CSF, specifically within cloud-native environments.
  • Technical proficiency in Python (or similar scripting languages) and experience building integrations using APIs to connect security tools with GRC systems. You can read code, design integrations, and understand technical implementations.
  • Builder mindset with the ability to design and implement automated control testing, continuous monitoring, and data-driven security metrics. You see manual processes and immediately think about how to automate them.
  • Exceptional cross-functional collaboration and communication skills. You can translate complex compliance requirements into technical specifications that engineering teams can actually implement and influence stakeholders across technical and non-technical domains.
  • Strong systems thinking. You have the ability to design scalable GRC architectures that grow with the company, rather than just solving for the immediate audit.
  • Bias for action.You’re a self-starter who ships solutions quickly and iterates based on feedback.
Bonus points
  • Previous experience in Fintech or banking environments navigating complex regulatory landscapes.
  • Hands‑on experience with Tines or other SOAR platforms to automate security operations.
  • Familiarity with AI/ML governance frameworks (NIST AI RMF, ISO 42001) or securing agentic systems.
  • Deep knowledge of Cloud Security (AWS/GCP), infrastructure-as-code (Terraform), or DevSecOps practices.
  • Relevant industry certifications such as CISSP, CISA, or CCSP.
  • Experience building metrics dashboards for security visualization and reporting.
  • Active contributions to the GRC or Security community through open‑source projects or public research.
Compensation

The expected salary range for this role is $153,600 - $192,000 CAD. However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package.

Brex LLC is a wholly owned subsidiary of Capital One, N.A.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Operations Engineer
Senior Security Operations Engineer

Brex • British Columbia

Hybrid
CAD 192,000 - 240,000
Up to four weeks fully remote work
Flexible working environment
Senior Software Engineer, Backend
Senior Software Engineer, Backend

EngineersOfAI • Vancouver

Hybrid
CAD 192,000 - 240,000
Up to four weeks of fully remote work per year
Hybrid work environment
Senior Software Engineer, Backend
Senior Software Engineer, Backend

Visa Hunt • Vancouver

Hybrid
CAD 192,000 - 240,000
Hybrid work model
Remote weeks (up to 4 weeks/yr)
Software Engineer II, Backend
Software Engineer II, Backend

Brex • Vancouver

Hybrid
CAD 152,000 - 190,000
Up to four weeks of fully remote work per year
Senior Application Security Engineer (Remote)
Senior Application Security Engineer (Remote)

Brex • Canada

On-site
CAD 272,000 - 341,000
Senior Engineering Manager, Acquisition
Senior Engineering Manager, Acquisition

Visa Hunt • Vancouver

Hybrid
CAD 300,000 - 375,000
Data platforms experience (Snowflake/"
Entrepreneurial spirit
Customer-obsessed culture
Senior Technical Recruiter
Senior Technical Recruiter

Brex • Vancouver

Hybrid
CAD 126,000 - 173,000
Engineering Manager, GTM Engineering
Engineering Manager, GTM Engineering

Brex • British Columbia

Hybrid
CAD 240,000 - 300,000
Up to four weeks of fully remote work per year
Flexible work schedule
Staff Software Engineer, Product Data Platform
Staff Software Engineer, Product Data Platform

Brex • Vancouver

Hybrid
CAD 240,000 - 300,000
Remote work weeks (up to 4 per year)
Hybrid office model
Senior Software Engineer, Full Stack
Senior Software Engineer, Full Stack

Brex • British Columbia

Hybrid
CAD 192,000 - 240,000
Up to four weeks of fully remote work per year
Collaborative office environment