GRC Engineer

Posted 10 Days Ago
Be an Early Applicant
3 Locations
In-Office
125K-160K Annually
Mid level
Fintech • Payments • Financial Services
The Role
Own and operationalize Method's GRC program: maintain audit readiness (SOC 2, PCI-DSS), manage Drata and evidence collection, perform risk/vendor assessments, partner with engineering/legal/finance, support customer security reviews, and improve governance through automation and reporting.
Summary Generated by Built In
Meet Method

Method has built the most modern way to connect to consumer financial accounts. Combining real-time liability connectivity with instant payment execution, Method’s API is designed to make it easy for people to connect their financial accounts to the apps and services they want to use.
We have helped 45+ million users connect 350+ million liability accounts credential-less and processed over $2.5B in payments, helping users save millions in interest. One in every three credit cards in the United States is in the Method ecosystem and leading financial institutions like SoFi, Bilt, Cleo, Sezzle, Figure & Aven rely on our APIs to build magical experiences for millions of consumers.
We’re a team of 50+ people spread across offices in Austin, SF, New York City and Washington D.C! We’re excited to continue the momentum working alongside our investors and advisors from Andreessen Horowitz, Emergence Capital, Y Combinator, Avra, and Ardent. To learn more about us, check out our blog!


About the role

We're hiring a GRC Engineer to help build and operationalize Method's Security and Compliance function. You'll play a critical role in enabling trust for our customers by designing, implementing, and maintaining compliance programs for a modern financial platform used across a wide range of regulated industries.

This is a hands-on role with broad ownership and real impact. You'll own the day-to-day governance, risk, and compliance operations — maintaining audit readiness, responding to enterprise security reviews with confidence, and scaling our compliance footprint as the business grows. That means understanding applicable frameworks, translating requirements into practical and scalable controls, and partnering across the company to embed compliance into our products, systems, and operations.

You'll work closely with Engineering, Finance, Legal, and Go-to-Market teams to ensure our security controls are not only documented but operationalized. You'll have the opportunity to apply your expertise directly, influence technical and business decisions, and grow alongside a fast-moving organization as our compliance and security programs continue to evolve.

What you’ll do
  • Partner cross-functionally to design, implement, and maintain compliance programs, including SOC 2, PCI-DSS, and others as needed.

  • Own and maintain the compliance platform (Drata), including control mapping, evidence collection, continuous monitoring, and audit workflows.

  • Manage control documentation, policies, procedures, and supporting artifacts across multiple compliance frameworks.

  • Perform risk assessments, vendor security reviews, and control gap analyses, and track remediation through to completion.

  • Build and maintain vendor risk management processes, including onboarding evaluations, annual reviews, risk scoring, and data sensitivity assessments.

  • Partner with Finance and Legal to implement structured vendor and customer risk profiling programs.

  • Partner with Security, IT, and Engineering teams to ensure technical and administrative controls align with documented policies and compliance requirements, including hands-on testing.

  • Support Go-To-Market teams with customer security questionnaires, audits, and compliance packaging for sales cycles.

  • Conduct periodic user access reviews and assist with access governance and RBAC validation.

  • Develop and maintain compliance reporting, metrics, and executive-ready summaries.

  • Identify process gaps and implement scalable governance improvements, including automation and tooling to scale with the business.

  • Oversee security awareness training and compliance education initiatives.

  • Participate in incident response activities, providing risk analysis and remediation support as needed.

Who you are
  • 3–5+ years of experience in IT Audit, Governance, Risk & Compliance, and/or Information Security, ideally in a startup or growth-stage environment.

  • Direct experience with SOC 2; PCI-DSS experience strongly preferred.

  • Comfortable working directly with auditors, managing audit timelines, and driving evidence collection across teams.

  • Strong understanding of cloud infrastructure (AWS), identity systems (Okta), and SaaS environments.

  • Able to understand and explain data flows, APIs, and infrastructure controls to both technical and non-technical audiences.

  • Experience with GRC platforms, security questionnaire tools, or compliance automation tooling is a plus.

  • Highly organized and process-oriented, with strong written communication skills.

  • Low ego, collaborative, and pragmatic — someone teammates genuinely want to work with.

Extra awesome
  • Hands-on coding or scripting experience (e.g., automation, tooling, or security-related development).

  • Experience building or scaling a GRC program from the ground up.

  • Security industry qualification (CISSP, CISM, CISA, or similar).

  • Cloud-specific certifications (CCSP, AWS Certified Security Specialty, CCSK, etc.).

--

The annual US base salary range for this role is: $125,000-$160,000

Top Skills

Drata,Aws,Okta,Apis,Scripting
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Austin, , TX
45 Employees
Year Founded: 2021

What We Do

Method Financial empowers real-time data and payment access for consumer liabilities. Using consumer’s consent, Method can securely connect all of a user’s liabilities, retrieve comprehensive data, and enable payment access.

Method’s industry-backed network allows lenders, fintechs, and financial institutions to build personalized lending and financial management experiences supported by comprehensive real-time credit data, evergreen connections and integrated payment rails.

Through a single integration, Method powers access to liabilities held at over 15,000+ FIs in the US, covering 95% of all outstanding consumer liabilities

Similar Jobs

New York Life Insurance Company Logo New York Life Insurance Company

RIA Senior Specialist

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
In-Office or Remote
2 Locations
12000 Employees
52K-65K Annually

Q2 Logo Q2

Financial Analyst

Digital Media • Fintech • Information Technology • Mobile • Payments • Software • Financial Services
Hybrid
2 Locations
2700 Employees

Apex Fintech Solutions Logo Apex Fintech Solutions

Software Engineer

Fintech • Software • Financial Services
Hybrid
Austin, TX, USA
1000 Employees

Pluralsight Logo Pluralsight

Fp&a Manager

Edtech • Information Technology • Software
Hybrid
Westlake, TX, USA
1300 Employees
99K-130K Annually

Similar Companies Hiring

Rain Thumbnail
Web3 • Payments • Infrastructure as a Service (IaaS) • Fintech • Financial Services • Cryptocurrency • Blockchain
New York, NY
80 Employees
Granted Thumbnail
Mobile • Insurance • Healthtech • Financial Services • Artificial Intelligence
New York, New York
23 Employees
Scotch Thumbnail
Software • Retail • Payments • Fintech • eCommerce • Artificial Intelligence • Analytics
US
25 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account