1

Grc Lead Jobs (NOW HIRING)

Senior GRC Lead

New York, NY · On-site +1

$125K - $171K/yr

As a Senior GRC Engineer, you will drive critical GRC processes that mitigate risk, keep us compliant, and build trust with our customers and partners. You'll evolve the technical foundation of our ...

Senior GRC Lead

Seattle, WA · On-site +1

$130K - $178K/yr

As a Senior GRC Engineer, you will drive critical GRC processes that mitigate risk, keep us compliant, and build trust with our customers and partners. You'll evolve the technical foundation of our ...

... SOD, GRC Tools (Access Risk Management, Access Risk Analysis and EAM), IDM Tool. Experience in BOBJ 4.x security, BODS Security, Solution Manager Security. Ability to manage multiple tasks of ...

... SOD, GRC Tools (Access Risk Management, Access Risk Analysis and EAM), IDM Tool. Experience in BOBJ 4.x security, BODS Security, Solution Manager Security. Ability to manage multiple tasks of ...

OR

$130K - $175K/yr

This is a hands-on role with meaningful ownership-from managing day-to-day controls and strengthening core compliance processes to partnering closely with our Head of Security and GRC lead to ...

New

GRC Lead Package Solution Consultant - Oracle Financials. This specialty recognizes the subject matter expert for guidance related to audits and other controls reviews using Oracle GRC. Additional ...

GRC Engineer

Palo Alto, CA · On-site

$130K - $170K/yr

GRC Engineer Why Zania Every enterprise spends millions of dollars on Governance, Risk, and ... Lead onboarding and deployment for enterprise customers from scoping and configuration through to a ...

Be Seen First

Cyber GRC Analyst

Phoenix, AZ · Remote

$65K - $90K/yr

If you want to grow toward a GRC program lead or compliance manager role, this is a direct path. You're Different • You've never understood being able to come in just to "punch the clock" -- you ...

Lead discussions related to Segregation of Duties (SoD), access risks, mitigation controls, and governance processes. Review and assess SAP GRC Access Control processes including Access Risk Analysis ...

RK&K is seeking a GRC Program Lead to establish, operationalize, and scale the firm's IT governance, risk, and compliance functions. This role provides centralized ownership of compliance efforts ...

GRC Program Lead

Baltimore, MD · On-site

$93K - $131K/yr

RK&K is seeking a GRC Program Lead to establish, operationalize, and scale the firm's IT governance, risk, and compliance functions. This role provides centralized ownership of compliance efforts ...

GRC Program Lead

Baltimore, MD · On-site

$93K - $131K/yr

RK&K is seeking a GRC Program Lead to establish, operationalize, and scale the firm's IT governance, risk, and compliance functions. This role provides centralized ownership of compliance efforts ...

next page

Showing results 1-20

Grc Lead information

What are some common challenges a GRC Lead might face when implementing new compliance frameworks across an organization?

A GRC Lead often encounters challenges such as resistance to change from staff, aligning diverse departmental processes with new compliance requirements, and ensuring consistent communication across teams. Balancing the need for thorough documentation with operational efficiency can also prove difficult. Successfully overcoming these obstacles requires strong interpersonal skills, a strategic approach to change management, and the ability to educate and motivate stakeholders at all levels of the organization.

What are the key skills and qualifications needed to thrive as a GRC Lead, and why are they important?

To thrive as a GRC Lead, you need expertise in governance, risk management, and compliance frameworks, often supported by a relevant degree and certifications such as CISA, CRISC, or CISSP. Familiarity with GRC platforms like RSA Archer, ServiceNow GRC, or MetricStream is typically required. Strong analytical thinking, leadership, and communication skills distinguish top performers in this role. These capabilities are crucial for ensuring organizational compliance, minimizing risks, and effectively aligning security strategies with business goals.

What are GRC Leads?

GRC Leads are professionals responsible for overseeing Governance, Risk, and Compliance (GRC) programs within an organization. They ensure that the company adheres to legal, regulatory, and internal policy requirements while managing risks and maintaining effective controls. GRC Leads coordinate across departments to implement frameworks, conduct risk assessments, and drive compliance initiatives. Their role is crucial in protecting the organization from legal and reputational risks and ensuring operational integrity.

What is the difference between Grc Lead vs Grc Analyst?

AspectGrc LeadGrc Analyst
CredentialsCertifications like CISA, CRISC often preferredSimilar certifications, often entry to mid-level
Work EnvironmentLeads teams, manages projects, strategic planningPerforms analysis, audits, and reporting tasks
Employer & Industry UsageUsed in large organizations for governance, risk, complianceCommon in security and compliance departments
Search & Comparison IntentOften searched for career progression or role differencesOften searched for entry-level or role clarification

The Grc Lead typically oversees GRC teams, manages strategic initiatives, and requires advanced certifications. The Grc Analyst focuses on conducting audits, analyzing risks, and supporting compliance activities. While both roles require similar certifications, the Lead has more managerial responsibilities, whereas the Analyst is more hands-on with analysis and reporting.

More about Grc Lead jobs
What cities are hiring for Grc Lead jobs? Cities with the most Grc Lead job openings:
What states have the most Grc Lead jobs? States with the most job openings for Grc Lead jobs include:
Infographic showing various Grc Lead job openings in the United States as of June 2026, with employment types broken down into 1% As Needed, 84% Full Time, 12% Part Time, and 3% Contract. Highlights an 77% Physical, 9% Hybrid, and 14% Remote job distribution.
Senior GRC Lead

Senior GRC Lead

Brex

New York, NY • On-site, Remote

$125K - $171K/yr

Other

Posted 26 days ago


Job description

Engineering

Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level - from architecture to deployment. It's an environment where engineering is a craft, and builders become leaders.

What you'll do

Brex's Governance, Risk, and Compliance function is at an exciting and pivotal point in our maturity journey and we're seeking a team member who can seamlessly bridge compliance expertise with technical execution. As a Senior GRC Engineer, you will drive critical GRC processes that mitigate risk, keep us compliant, and build trust with our customers and partners. You'll evolve the technical foundation of our Trust program by automating security controls, building integrations between security tools and GRC platforms, and creating scalable processes that enable Brex to maintain compliance efficiently as we expand into new markets. You'll work at the intersection of security, engineering, and compliance - translating regulatory requirements into technical solutions and building automation that eliminates manual toil.

You'll leverage your deep understanding of SOC 2, PCI DSS, ISO 27001, AI governance frameworks, and others to both design controls for emerging compliance requirements and mature existing programs through automation and continuous monitoring. You'll support Trust Assurance, Third Party Risk Management, and other Security Risk Management initiatives. Working with our Engineering, Infrastructure, and Product teams, you'll translate compliance frameworks into technical controls and build automated systems that help us achieve world-class security as Brex expands.

Your contributions will directly accelerate Brex's maturity. You'll design workflows using Tines, build integrations between security and GRC systems, and create dashboards for security metrics. You'll implement controls across the technology stack, support multiple audits (SOC 2, PCI DSS, SOX/ITGC, FINRA, ISO), and contribute to AI governance framework implementation (ISO 42001, NIST AI RMF, EU AI Act).

You'll have autonomy to build innovative solutions, collaborating cross-functionally to implement controls that enable growth while communicating technical concepts effectively across the organization.

Where you'll work

This role will be based in our New York office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We currently require a minimum of three coordinated days in the office per week, Monday, Wednesday and Thursday. As a perk, we also have up to four weeks per year of fully remote work!

Responsibilities

  • Manage and scale IT infrastructure, services and tooling
  • Work with a diverse group of  IT partners to optimize our provided services
  • Implement new services in support of Information Technologies vision
  • Scale our services by implementing configuration as code via Terraform providers or APIs
  • Operationalize and upskill IT and its partners by producing documentation and leading training sessions
  • Evangelize best practices both internally and externally facing

Requirements

  • 5+ years of experience in GRC, IT Governance, or Security Engineering with a strong track record of automating manual compliance workflows.
  • Deep experience with security frameworks such as SOC 2, PCI DSS, ISO 27001, and NIST CSF, specifically within cloud-native environments.
  • Technical proficiency in Python (or similar scripting languages) and experience building integrations using APIs to connect security tools with GRC systems. You can read code, design integrations, and understand technical implementations.
  • Builder mindset with the ability to design and implement automated control testing, continuous monitoring, and data-driven security metrics. You see manual processes and immediately think about how to automate them.
  • Exceptional cross-functional collaboration and communication skills. You can translate complex compliance requirements into technical specifications that engineering teams can actually implement and influence stakeholders across technical and non-technical domains.
  • Strong systems thinking. You have the ability to design scalable GRC architectures that grow with the company, rather than just solving for the immediate audit.
  • Bias for action. You're a self-starter who ships solutions quickly and iterates based on feedback. 

Bonus points

  • Previous experience in Fintech or banking environments navigating complex regulatory landscapes.
  • Hands-on experience with Tines or other SOAR platforms to automate security operations.
  • Familiarity with AI/ML governance frameworks (NIST AI RMF, ISO 42001) or securing agentic systems.
  • Deep knowledge of Cloud Security (AWS/GCP), infrastructure-as-code (Terraform), or DevSecOps practices.
  • Relevant industry certifications such as CISSP, CISA, or CCSP.
  • Experience building metrics dashboards for security visualization and reporting.
  • Active contributions to the GRC or Security community through open-source projects or public research.

Compensation

The expected salary range for this role is $153,600 - $192,000. However, the starting base pay will depend on a number of factors including the candidate's location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package.

Brex LLC is a wholly owned subsidiary of Capital One, N.A.