> Markdown version of [/jobs/ext/2488809-grc-engineer](https://www.wearedevelopers.com/jobs/ext/2488809-grc-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Engineer - **Company:** Peak6 - **Location:** Belfast, UK (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cyber Security, Database Queries, Query Languages, Identity and Access Management, Issue Tracking Systems, Information Technology Audit, Python (Programming Language), PCI Data Security Standards, Security Information and Event Management, SQL Databases, Scripting, Cloud Platform System, RSA Archer Platform, Data Pipelines, Api Management, Servicenow - **Published:** August 27, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=1e673a5a321a3045 ## About the Role Required: * 2-5+ years of experience in GRC, information security compliance, IT audit, or a closely related field * Hands-on experience with SOC 2 audits (as a practitioner preparing evidence, not just an auditor) * Working knowledge of NIST CSF and ISO 27001 (or similar frameworks like PCI DSS, HITRUST) * Experience with a GRC automation platform (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC, or similar) * Comfort working with API integrations to ingest data for compliance monitoring and control building * Working proficiency in SQL or similar query languages to analyze and validate compliance data * Experience drafting and maintaining information security policies and procedures * Strong written and verbal communication skills, able to translate technical findings for both auditors and executives * Ability to manage multiple concurrent audits/assessments and shifting priorities Preferred: * Experience in fintech, financial services, or another regulated industry * Familiarity with vendor/third-party risk management programs and DDQ response processes * Exposure to cloud environments (AWS, Azure, or GCP) and common security tooling (IAM, SIEM, ticketing systems) * Scripting ability (Python, or similar) for light automation of GRC workflows * Relevant certifications: CISA, CISSP, CRISC, ISO 27001 Lead Implementer/Auditor, or similar ## Description Apex Fintech Solutions is looking for a GRC Engineer to help build, scale, and operate our governance, risk, and compliance program. This is a hands-on, technically minded role that blends traditional GRC responsibilities, including audits, risk management, policy, and due diligence, with engineering-oriented skills like API integrations, data querying, and control automation. You'll be a key player in maintaining our compliance posture across frameworks like SOC 2, NIST CSF, and ISO 27001, while also helping modernize how we monitor and evidence controls using platforms like Anecdotes. This role suits someone who is equally comfortable talking to auditors as they are writing a query to pull evidence out of a data pipeline. What You'll Do Audits & Framework Management * Own or co-own preparation for and execution of SOC 2 (Type I/II) audits, working directly with external auditors to scope, evidence, and remediate findings * Lead or support NIST CSF assessments and gap analyses, translating results into actionable remediation plans * Support alignment and readiness activities for ISO 27001 and other relevant frameworks (e.g., PCI DSS, GLBA, state/federal financial regulations as applicable) * Maintain a unified control framework that maps overlapping requirements across multiple standards to reduce duplicate effort Compliance Monitoring & Governance * Build and maintain continuous compliance monitoring using GRC platforms such as Anecdotes (or equivalent tools like Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC) * Configure and manage automated evidence collection via API integrations with cloud, identity, ticketing, and infrastructure systems * Design and implement controls that consume ingested data, ensuring accuracy, freshness, and appropriate alerting on control drift or failures * Query and analyze compliance and security data (SQL or platform-native query languages) to validate control effectiveness and produce audit-ready evidence * Maintain the organization's control library, risk register, and policy/procedure repository Risk Management * Support enterprise risk assessments, including identification, scoring, tracking, and remediation of risks * Maintain third-party/vendor risk management processes, including vendor risk assessments and ongoing monitoring * Partner with security, engineering, and business teams to ensure risks are understood, owned, and addressed on a reasonable timeline Due Diligence & Customer Trust * Respond to Due Diligence Questionnaires (DDQs), RFPs, and customer security questionnaires with accurate, timely, and well-documented answers * Maintain a trust center / security documentation repository to streamline recurring due diligence requests * Act as a subject matter resource for prospects, customers, and partners on Apex's security and compliance posture Policies & Procedures * Draft, maintain, and periodically review information security and compliance policies and procedures * Ensure policies remain aligned with current frameworks, regulatory obligations, and actual operational practice * Support policy attestation, training, and awareness campaigns Other GRC Functions * Support internal and external audit logistics, evidence requests, and stakeholder coordination * Contribute to metrics and reporting for leadership and the board on compliance and risk posture * Continuously look for opportunities to automate manual GRC workflows ## Related Videos - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [Robots are coming into the wild! Full-Stack Robotics Engineers, be ready!](https://www.wearedevelopers.com/videos/479-robots-are-coming-into-the-wild-full-stack-robotics-engineers-be-ready) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1520-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)