Staff Trust & Assurance Engineer
Core
Design, operate, and attest cybersecurity controls for external auditors, regulators, and B2B customers in a cloud-native fintech environment.
Role type
Staff Trust & Assurance Engineer (GRC)
Builds
SOC 2, PCI DSS, and SOX compliance programs; customer trust portals; AI-driven evidence automation.
Domain
Fintech / Cybersecurity Compliance / GRC
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SOC 2 Type II program ownership, PCI DSS self-attestation, IT general controls (SOX), GLBA Safeguards Rule implementation, SEC Regulation S-K Item 106 disclosures, third-party risk management, policy-as-code, compliance-as-code, CI/CD workflows, IAM policy modification, cloud infrastructure knowledge, external auditor management.
Preferred skills
SOX IT general controls in pre-IPO/public companies, AI/LLM-driven GRC automation (custom agents, MCP servers), IPO readiness experience, ISO 27001/42001/FedRAMP/CMMC/NIST 800-53 familiarity.
Technologies
Git, CI/CD, Infrastructure-as-Code, IAM, Cloud Infrastructure, AI/LLM frameworks, MCP servers.
Responsibilities
Own SOC 2 Type II program end-to-end (scoping, design, evidence, walkthroughs, auditor management); Maintain PCI DSS self-attestation and scope analysis; Serve as cybersecurity control owner for IT general controls supporting SOX; Operationalize GLBA Safeguards Rule technical controls; Source and steward cybersecurity content for SEC Regulation S-K Item 106 disclosures; Own customer and vendor security questionnaire pipeline and trust portal; Design and operate internal cybersecurity control testing and continuous monitoring; Build policy-as-code, compliance-as-code, and AI-driven evidence automation; Serve as primary cybersecurity audit contact for SOC 2, PCI, and customer assessments.
Seniority
Staff, hands-on IC with strategic ownership