Brex

Senior GRC Lead

Brex
hybrid senior full-time $153,600 - $192,000 San Francisco, California, United States
Apply →

First indexed 18 Apr 2026

Description

Join Brex, the intelligent finance platform that enables companies to spend smarter and move faster in more than 200 markets. As a Senior GRC Lead, you will drive critical GRC processes that mitigate risk, keep us compliant, and build trust with our customers and partners.

You'll evolve the technical foundation of our Trust program by automating security controls, building integrations between security tools and GRC platforms, and creating scalable processes that enable Brex to maintain compliance efficiently as we expand into new markets.

You'll work at the intersection of security, engineering, and compliance , translating regulatory requirements into technical solutions and building automation that eliminates manual toil.

You'll leverage your deep understanding of SOC 2, PCI DSS, ISO 27001, AI governance frameworks, and others to both design controls for emerging compliance requirements and mature existing programs through automation and continuous monitoring.

You’ll support Trust Assurance, Third Party Risk Management, and other Security Risk Management initiatives.

Working with our Engineering, Infrastructure, and Product teams, you'll translate compliance frameworks into technical controls and build automated systems that help us achieve world-class security as Brex expands.

Your contributions will directly accelerate Brex's maturity.

You'll design workflows using Tines, build integrations between security and GRC systems, and create dashboards for security metrics.

You'll implement controls across the technology stack, support multiple audits (SOC 2, PCI DSS, SOX/ITGC, FINRA, ISO), and contribute to AI governance framework implementation (ISO 42001, NIST AI RMF, EU AI Act).

You'll have autonomy to build innovative solutions, collaborating cross-functionally to implement controls that enable growth while communicating technical concepts effectively across the organization.

This role will be based in our San Francisco office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home.

Responsibilities:

Manage and scale IT infrastructure, services and tooling

Work with a diverse group of IT partners to optimize our provided services

Implement new services in support of Information Technologies vision

Scale our services by implementing configuration as code via Terraform providers or APIs

Operationalize and upskill IT and its partners by producing documentation and leading training sessions

Evangelize best practices both internally and externally facing

Requirements:

5+ years of experience in GRC, IT Governance, or Security Engineering with a strong track record of automating manual compliance workflows.

Deep experience with security frameworks such as SOC 2, PCI DSS, ISO 27001, and NIST CSF, specifically within cloud-native environments.

Technical proficiency in Python (or similar scripting languages) and experience building integrations using APIs to connect security tools with GRC systems.

Builder mindset with the ability to design and implement automated control testing, continuous monitoring, and data-driven security metrics.

Exceptional cross-functional collaboration and communication skills.

Strong systems thinking.

Bias for action.

Bonus points:

Previous experience in Fintech or banking environments navigating complex regulatory landscapes.

Hands-on experience with Tines or other SOAR platforms to automate security operations.

Familiarity with AI/ML governance frameworks (NIST AI RMF, ISO 42001) or securing agentic systems.

Deep knowledge of Cloud Security (AWS/GCP), infrastructure-as-code (Terraform), or DevSecOps practices.

Relevant industry certifications such as CISSP, CISA, or CCSP.

Experience building metrics dashboards for security visualization and reporting.

Active contributions to the GRC or Security community through open-source projects or public research.

Compensation: The expected salary range for this role is $153,600 - $192,000.

This listing is enriched and indexed by YubHub. To apply, use the employer's original posting: https://job-boards.greenhouse.io/brex/jobs/8378792002