Search...

GRC Engineer

FrankieOne logo
FrankieOne

FrankieOne is a RegTech company that provides a unified connection to KYC, KYB, AML, and fraud tools. Its platform helps banks, fintechs, and financial-services companies onboard customers, manage risk, and monitor transactions.

Distributed
About FrankieOne

FrankieOne provides a unified API, customizable decision engine, and single customer view for customer onboarding, identity and business verification, AML, fraud protection, biometrics, risk-based onboarding, and transaction monitoring. The company connects customers to hundreds of global vendors and data sources, enabling organizations to configure and activate checks and verifications with minimal development work. Its customers include banks, fintechs, and other highly regulated financial-services companies.

View jobs by FrankieOne

Skills

About the Role

You will engineer automated evidence collection, continuous control monitoring, security metrics pipelines, and third-party risk workflows. You will maintain compliance with ISO 27001 and SOC 2, conduct risk assessments, manage audit evidence and risk registers, support security audits and incident response, and improve security controls and processes.

Requirements

  • At least 3 years of information-security experience with an emphasis on risk and compliance
  • 2+ years of experience conducting ISO 27001 and SOC 2 audits and handling audit responses
  • Understanding of ISO 27001, SOC 2, NIST, PCI, GDPR, and regulatory compliance requirements
  • Knowledge of identity and access management, encryption, backups, secure software development life cycle, and vulnerability management
  • Familiarity with GRC tools and practices, such as Drata and Vanta
  • Experience managing risk and compliance projects
  • Experience managing third-party audits, compiling evidence, and organising audit responses
  • Familiarity with GRC platform APIs and integrations across cloud, security, and ITSM tooling
  • Experience automating manual compliance processes into repeatable, auditable workflows
  • Experience working in remote teams for offshore clients

Responsibilities

  • Maintain continuous compliance with relevant standards, including ISO 27001 and SOC 2
  • Conduct security risk assessments across the organisation and for third parties
  • Maintain audit evidence, project plans, risk registers, and continuous-improvement registers
  • Support external security audits, customer assessments, and internal assessments
  • Assist with management reviews, reporting, policy management, and the security-awareness program
  • Support information-security incident and breach response
  • Advise on process and control enhancements
  • Manage security standards, policies, and practices annually
  • Respond to business-unit inquiries about operational compliance
  • Collaborate across the business to ensure compliance with ISO 27001, SOC 2, and company policies
  • Automate control monitoring and testing through scripts or integrations
  • Automate vendor risk assessments, evidence intake, risk scoring, reassessment scheduling, and risk-register integration

Benefits

  • Fully remote work