GRC Engineer

GRC Engineer

Full-Time No working from home possible
P

WHO WE ARE


Apex Fintech Solutions (Apex) powers innovation and the future of digital wealth management by building tech-forward solutions that help simplify, automate, and facilitate access to financial markets for all. Our robust suite of fintech software enables us to support clients such as Stash, Betterment, SoFi, Webull, and eToro, amongst many others; collectively, Apex powers access to the stock market for over 22+ million end customers.


At Apex, we are changing how the securities industry operates by reinventing the status quo, which was manual, slow, and accessible only by the ultra-wealthy. We're digitizing and democratizing systems so that everyone has an opportunity to invest.


When you're at Apex, you drive this change. You're part of a global team with a clear vision: to be the trusted technology that powers the digital economy. Our offices in Austin, Dallas, Chicago, New York, Portland, Belfast, and Manila are home to over 1,000 employees.


Together, we're shaping the future of financial innovation. Embrace change. Solve big. Win together. And be G.R.E.A.T. - grit, results, empathy, accountability, and teamwork - with Apex.


We're proud to be recognized for the innovative work we do, the purpose-driven nature of our work, and the collaborative culture we've created. Here are just a few of the many awards we've recently received:



  • Best Places to Work

  • 2026, 2025, 2024, 2023 - Presented by BuiltIn

  • WealthTech of the Year

  • 2025 - Presented by US FinTech Awards

  • The World's Top 250 Fintech Companies

  • 2024 - Presented by CNBC


ABOUT THIS ROLE


Apex Fintech Solutions is looking for a GRC Engineer to help build, scale, and operate our governance, risk, and compliance program. This is a hands‑on, technically minded role that blends traditional GRC responsibilities, including audits, risk management, policy, and due diligence, with engineering‑oriented skills like API integrations, data querying, and control automation.


You'll be a key player in maintaining our compliance posture across frameworks like SOC 2, NIST CSF, and ISO 27001, while also helping modernize how we monitor and evidence controls using platforms like Anecdotes. This role suits someone who is equally comfortable talking to auditors as they are writing a query to pull evidence out of a data pipeline.


What You’ll Do


Audits & Framework Management


Own or co‑own preparation for and execution of SOC 2 (Type I/II) audits, working directly with external auditors to scope, evidence, and remediate findings


Lead or support NIST CSF assessments and gap analyses, translating results into actionable remediation plans


Support alignment and readiness activities for ISO 27001 and other relevant frameworks (e.g., PCI DSS, GLBA, state/federal financial regulations as applicable)


Maintain a unified control framework that maps overlapping requirements across multiple standards to reduce duplicate effort


Compliance Monitoring & Governance


Build and maintain continuous compliance monitoring using GRC platforms such as Anecdotes (or equivalent tools like Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC)


Configure and manage automated evidence collection via API integrations with cloud, identity, ticketing, and infrastructure systems


Design and implement controls that consume ingested data, ensuring accuracy, freshness, and appropriate alerting on control drift or failures


Query and analyze compliance and security data (SQL or platform‑native query languages) to validate control effectiveness and produce audit‑ready evidence


Maintain the organization’s control library, risk register, and policy/procedure repository


Risk Management


Support enterprise risk assessments, including identification, scoring, tracking, and remediation of risks


Maintain third‑party/vendor risk management processes, including vendor risk assessments and ongoing monitoring


Partner with security, engineering, and business teams to ensure risks are understood, owned, and addressed on a reasonable timeline


Due Diligence & Customer Trust


Respond to Due Diligence Questionnaires (DDQs), RFPs, and customer security questionnaires with accurate, timely, and well‑documented answers


Maintain a trust center / security documentation repository to streamline recurring due diligence requests


Act as a subject matter resource for prospects, customers, and partners on Apex's security and compliance posture


Policies & Procedures


Draft, maintain, and periodically review information security and compliance policies and procedures


Ensure policies remain aligned with current frameworks, regulatory obligations, and actual operational practice


Support policy attestation, training, and awareness campaigns


Other GRC Functions


Support internal and external audit logistics, evidence requests, and stakeholder coordination


Contribute to metrics and reporting for leadership and the board on compliance and risk posture


Continuously look for opportunities to automate manual GRC workflows


What We’re Looking For


Requi

#J-18808-Ljbffr

P

Contact Details:

peak6group Recruitment Team