GRC Engineer

GRC Engineer

Full-Time 59400 - 72600 £ / year (est.) Home office (partial)
A

At a Glance

  • Tasks: Join us as a GRC Engineer to shape compliance and risk management in fintech.
  • Company: Apex Fintech Solutions, a leader in digital wealth management.
  • Benefits: Enjoy competitive salary, flexible hours, health insurance, and generous leave.
  • Other info: Collaborative culture with opportunities for growth and fun team events.
  • Why this job: Make a real impact in the fintech industry while driving innovation.
  • Qualifications: 2-5 years in GRC or IT audit, with hands-on SOC 2 experience.

The predicted salary is between 59400 - 72600 £ per year.

Apex Fintech Solutions is looking for a GRC Engineer to help build, scale, and operate our governance, risk, and compliance program. This is a hands-on, technically minded role that blends traditional GRC responsibilities, including audits, risk management, policy, and due diligence, with engineering-oriented skills like API integrations, data querying, and control automation. You'll be a key player in maintaining our compliance posture across frameworks like SOC 2, NIST CSF, and ISO 27001, while also helping modernize how we monitor and evidence controls using platforms like Anecdotes.

What You'll Do

  • Audits & Framework Management: Own or co-own preparation for and execution of SOC 2 (Type I/II) audits, working directly with external auditors to scope, evidence, and remediate findings. Lead or support NIST CSF assessments and gap analyses, translating results into actionable remediation plans. Support alignment and readiness activities for ISO 27001 and other relevant frameworks (e.g., PCI DSS, GLBA, state/federal financial regulations as applicable). Maintain a unified control framework that maps overlapping requirements across multiple standards to reduce duplicate effort.
  • Compliance Monitoring & Governance: Build and maintain continuous compliance monitoring using GRC platforms such as Anecdotes (or equivalent tools like Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC). Configure and manage automated evidence collection via API integrations with cloud, identity, ticketing, and infrastructure systems. Design and implement controls that consume ingested data, ensuring accuracy, freshness, and appropriate alerting on control drift or failures. Query and analyze compliance and security data (SQL or platform-native query languages) to validate control effectiveness and produce audit-ready evidence. Maintain the organization's control library, risk register, and policy/procedure repository.
  • Risk Management: Support enterprise risk assessments, including identification, scoring, tracking, and remediation of risks. Maintain third-party/vendor risk management processes, including vendor risk assessments and ongoing monitoring. Partner with security, engineering, and business teams to ensure risks are understood, owned, and addressed on a reasonable timeline.
  • Due Diligence & Customer Trust: Respond to Due Diligence Questionnaires (DDQs), RFPs, and customer security questionnaires with accurate, timely, and well-documented answers. Maintain a trust center/security documentation repository to streamline recurring due diligence requests. Act as a subject matter resource for prospects, customers, and partners on Apex's security and compliance posture.
  • Policies & Procedures: Draft, maintain, and periodically review information security and compliance policies and procedures. Ensure policies remain aligned with current frameworks, regulatory obligations, and actual operational practice. Support policy attestation, training, and awareness campaigns.
  • Other GRC Functions: Support internal and external audit logistics, evidence requests, and stakeholder coordination. Contribute to metrics and reporting for leadership and the board on compliance and risk posture. Continuously look for opportunities to automate manual GRC workflows.

What We're Looking For

  • Required: 2–5+ years of experience in GRC, information security compliance, IT audit, or a closely related field. Hands-on experience with SOC 2 audits (as a practitioner preparing evidence, not just an auditor). Working knowledge of NIST CSF and ISO 27001 (or similar frameworks like PCI DSS, HITRUST). Experience with a GRC automation platform (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC, or similar). Comfort working with API integrations to ingest data for compliance monitoring and control building. Working proficiency in SQL or similar query languages to analyze and validate compliance data. Experience drafting and maintaining information security policies and procedures. Strong written and verbal communication skills, able to translate technical findings for both auditors and executives. Ability to manage multiple concurrent audits/assessments and shifting priorities.
  • Preferred: Experience in fintech, financial services, or another regulated industry. Familiarity with vendor/third-party risk management programs and DDQ response processes. Exposure to cloud environments (AWS, Azure, or GCP) and common security tooling (IAM, SIEM, ticketing systems). Scripting ability (Python, or similar) for light automation of GRC workflows. Relevant certifications: CISA, CISSP, CRISC, ISO 27001 Lead Implementer/Auditor, or similar.

Our Rewards

We offer a robust package of employee perks and benefits, including a market-leading salary with an annual bonus, 28 days of annual leave plus 10 Northern Ireland national holidays, a training and development budget, and a pension matched up to 7%. Our benefits also cover private health insurance for medical, dental, and optical care, and life insurance. We emphasize work-life balance with flexible working hours, parental leave, a modern city centre office, and a hybrid work schedule that allows for greater flexibility by partially working from home. Additional perks include monthly catered lunches, unlimited drinks and snacks, hackathon events, poker tournaments, and a charitable matching gift program.

EEO Statement

Apex Fintech Solutions is an equal opportunity employer that does not discriminate on the basis of race, color, religion, sex (including pregnancy, sexual orientation, and gender identity), national origin, age, disability, veteran status, marital status, or any other protected characteristic. Our hiring practices ensure that all qualified applicants receive fair consideration without regard to these characteristics.

Disability Statement

Apex Fintech Solutions is committed to creating an inclusive and accessible workplace for all candidates, including those with disabilities. We are dedicated to ensuring equal employment opportunities and providing reasonable accommodations to qualified individuals with disabilities. If you require reasonable accommodations to participate in the application or interview process, please submit your request via the Candidate Accommodation Requests Form. We will work with you to provide the necessary accommodations to ensure your full participation in our hiring process.

GRC Engineer employer: Apex Fintech Solutions LLC

Apex Fintech Solutions is an exceptional employer, offering a dynamic work environment that fosters innovation and collaboration. With a strong commitment to employee growth, we provide extensive training and development opportunities, alongside a competitive salary and comprehensive benefits package, including flexible working hours and a hybrid work schedule. Our vibrant office culture in Belfast encourages teamwork and creativity, making it an ideal place for those looking to make a meaningful impact in the fintech industry.

A

Contact Details:

Apex Fintech Solutions LLC Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land GRC Engineer

✨Join Compliance Communities

Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!

✨Attend Industry Conferences

Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.

✨Leverage Your University Career Services

If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.

✨Showcase Your Knowledge Online

Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Apex Fintech Solutions LLC looking for candidates who are engaged and informed.

We think you need these skills to ace GRC Engineer

GRC (Governance, Risk, Compliance)
SOC 2 Audits
NIST CSF
ISO 27001
API Integrations
Data Querying (SQL)
Control Automation

Some tips for your application 🫡

Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!

Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.

Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!

Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Apex Fintech Solutions LLC. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!

How to prepare for a job interview at Apex Fintech Solutions LLC

✨Master the Regulations

Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!

✨Show Your Analytical Skills

Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!

✨Know Your Tools

Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!

✨Align with Company Culture

Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Apex Fintech Solutions LLC’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!