Enter a job title or keyword

GRC Engineer


Job Location:

Belfast - UK

Monthly Salary: Not provided by the employer
Posted: 29 September 2026 (Yesterday)
Application Deadline: 27 December 2026
Vacancies: 1 Vacancy

Job Summary

WHO WE ARE

Apex Fintech Solutions (Apex) powers innovation and the future of digital wealth management by building tech-forward solutions that help simplify automate and facilitate access to financial markets for all. Our robust suite of fintech software enables us to support clients such as Stash Betterment SoFi Webull and eToro amongst many others; collectively Apex powers access to the stock market for over 22 million end customers.

At Apex we are changing how the securities industry operates by reinventing the status quo which was manual slow and accessible only by the ultra-wealthy. Were digitizing and democratizing systems so that everyone has an opportunity to invest.

When youre at Apex you drive this change. Youre part of a global team with a clear vision: to be the trusted technology that powers the digital economy. Our offices in Austin Dallas Chicago New York Portland Belfast and Manila are home to over 1000 employees.

Together were shaping the future of financial innovation. Embrace change. Solve big. Win together. And be G.R.E.A.T. grit results empathy accountability and teamwork with Apex.

Were proud to be recognized for the innovative work we do the purpose-driven nature of our work and the collaborative culture weve created. Here are just a few of the many awards weve recently received:

Best Places to Work

- Presented by BuiltIn

WealthTech of the Year

2025- Presented by US FinTech Awards

The Worlds Top 250 Fintech Companies

2024- Presented by CNBC

ABOUT THIS ROLE

Apex Fintech Solutions is looking for a GRC Engineer to help build scale and operate our governance risk and compliance program. This is a hands-on technically minded role that blends traditional GRC responsibilities including audits risk management policy and due diligence with engineering-oriented skills like API integrations data querying and control automation.

Youll be a key player in maintaining our compliance posture across frameworks like SOC 2 NIST CSF and ISO 27001 while also helping modernize how we monitor and evidence controls using platforms like Anecdotes. This role suits someone who is equally comfortable talking to auditors as they are writing a query to pull evidence out of a data pipeline.

What Youll Do

Audits & Framework Management

  • Own or co-own preparation for and execution of SOC 2 (Type I/II) audits working directly with external auditors to scope evidence and remediate findings
  • Lead or support NIST CSF assessments and gap analyses translating results into actionable remediation plans
  • Support alignment and readiness activities for ISO 27001 and other relevant frameworks (e.g. PCI DSS GLBA state/federal financial regulations as applicable)
  • Maintain a unified control framework that maps overlapping requirements across multiple standards to reduce duplicate effort

Compliance Monitoring & Governance

  • Build and maintain continuous compliance monitoring using GRC platforms such as Anecdotes (or equivalent tools like Vanta Drata Secureframe OneTrust ServiceNow GRC)
  • Configure and manage automated evidence collection via API integrations with cloud identity ticketing and infrastructure systems
  • Design and implement controls that consume ingested data ensuring accuracy freshness and appropriate alerting on control drift or failures
  • Query and analyze compliance and security data (SQL or platform-native query languages) to validate control effectiveness and produce audit-ready evidence
  • Maintain the organizations control library risk register and policy/procedure repository

Risk Management

  • Support enterprise risk assessments including identification scoring tracking and remediation of risks
  • Maintain third-party/vendor risk management processes including vendor risk assessments and ongoing monitoring
  • Partner with security engineering and business teams to ensure risks are understood owned and addressed on a reasonable timeline

Due Diligence & Customer Trust

  • Respond to Due Diligence Questionnaires (DDQs) RFPs and customer security questionnaires with accurate timely and well-documented answers
  • Maintain a trust center / security documentation repository to streamline recurring due diligence requests
  • Act as a subject matter resource for prospects customers and partners on Apexs security and compliance posture

Policies & Procedures

  • Draft maintain and periodically review information security and compliance policies and procedures
  • Ensure policies remain aligned with current frameworks regulatory obligations and actual operational practice
  • Support policy attestation training and awareness campaigns

Other GRC Functions

  • Support internal and external audit logistics evidence requests and stakeholder coordination
  • Contribute to metrics and reporting for leadership and the board on compliance and risk posture
  • Continuously look for opportunities to automate manual GRC workflows
What Were Looking For

Required:

  • 25 years of experience in GRC information security compliance IT audit or a closely related field
  • Hands-on experience with SOC 2 audits (as a practitioner preparing evidence not just an auditor)
  • Working knowledge of NIST CSF and ISO 27001 (or similar frameworks like PCI DSS HITRUST)
  • Experience with a GRC automation platform (Anecdotes Vanta Drata Secureframe OneTrust ServiceNow GRC or similar)
  • Comfort working with API integrations to ingest data for compliance monitoring and control building
  • Working proficiency in SQL or similar query languages to analyze and validate compliance data
  • Experience drafting and maintaining information security policies and procedures
  • Strong written and verbal communication skills able to translate technical findings for both auditors and executives
  • Ability to manage multiple concurrent audits/assessments and shifting priorities

Preferred:

  • Experience in fintech financial services or another regulated industry
  • Familiarity with vendor/third-party risk management programs and DDQ response processes
  • Exposure to cloud environments (AWS Azure or GCP) and common security tooling (IAM SIEM ticketing systems)
  • Scripting ability (Python or similar) for light automation of GRC workflows
  • Relevant certifications: CISA CISSP CRISC ISO 27001 Lead Implementer/Auditor or similar

Please note this job description is not designed to cover or contain a comprehensive listing of activities duties or responsibilities required of the employee for this job. Duties responsibilities and activities may change at any time with or without notice.

Our Rewards

We offer a robust package of employee perks and benefits including a market-leading salary with an annual bonus 28 days of annual leave plus 10 Northern Ireland national holidays a training and development budget and a pension matched up to 7%. Our benefits also cover private health insurance for medical dental and optical care and life insurance. We emphasize work-life balance with flexible working hours parental leave a modern city center office and a hybrid work schedule that allows for greater flexibility by partially working from home. Additional perks include monthly catered lunches unlimited drinks and snacks hackathon events poker tournaments and a charitable matching gift program.

EEO Statement

Apex Fintech Solutions is an equal opportunity employer that does not discriminate on the basis of race color religion sex (including pregnancy sexual orientation and gender identity) national origin age disability veteran status marital status or any other protected characteristic. Our hiring practices ensure that all qualified applicants receive fair consideration without regard to these characteristics.

Disability Statement

Apex Fintech Solutions is committed to creating an inclusive and accessible workplace for all candidates including those with disabilities. We are dedicated to ensuring equal employment opportunities and providing reasonable accommodations to qualified individuals with disabilities. If you require reasonable accommodations to participate in the application or interview process please submit your request via the Candidate Accommodation Requests Form. We will work with you to provide the necessary accommodations to ensure your full participation in our hiring process.


Required Experience:

IC


About Company

Company Logo

PEAK6 doesn't do anything the traditional way. Mainly because we're not your typical investment firm. We follow opportunities, not the status quo.

View Profile View Profile