<p>We are seeking an experienced <strong>Lead GRC Automation Analyst</strong> to join an Information Security organization within a highly regulated financial services environment.</p><p>This is a hands-on role for someone who understands Governance, Risk, and Compliance but also knows how to <strong>build and automate processes</strong>. The ideal candidate will be comfortable identifying manual or inefficient GRC processes, designing better workflows, and personally helping implement automation that improves efficiency, accuracy, and audit readiness.</p><p>This person will also support security governance, control testing, audit activities, evidence collection, and compliance initiatives. The role offers an opportunity to help build and mature GRC capabilities while making a measurable impact through automation.</p><p>What You’ll Do</p><ul><li>Lead the <strong>design and implementation of GRC automation</strong> initiatives.</li><li>Identify manual, repetitive, or inefficient compliance processes and develop solutions to streamline or automate them.</li><li>Automate <strong>evidence/artifact gathering, control testing, reporting, and other repeatable GRC processes</strong>.</li><li>Look across the GRC function for opportunities to improve processes, eliminate manual work, and create scalable solutions.</li><li>Support internal audits and regulatory examinations through evidence collection, documentation, and stakeholder coordination.</li><li>Perform control validation and testing and document results.</li><li>Identify control deficiencies, track remediation, and partner with stakeholders to resolve findings.</li><li>Develop and maintain clear process narratives, control documentation, and supporting evidence.</li><li>Work with GRC platforms and related technology to improve workflows and reporting.</li><li>Develop metrics and reporting related to control effectiveness, risk, compliance, and remediation.</li><li>Support policy and standards governance, including reviews and updates.</li><li>Partner with technical and business stakeholders to understand requirements and implement practical solutions.</li><li>Communicate findings, recommendations, and project progress to both technical teams and leadership.</li></ul>
<p>We are seeking an experienced <strong>PCI Technical Engineer</strong> to help build, strengthen, and automate a PCI DSS compliance program within a highly regulated financial services environment.</p><p>This is a hands-on role for someone who understands PCI DSS at a deep level and has <strong>built and matured a PCI program from the ground up</strong>. The ideal candidate will have experience defining PCI scope and boundaries, understanding the Cardholder Data Environment (CDE), establishing and validating controls, supporting audits, remediating findings, and continuously improving the program.</p><p>This role is also focused on <strong>automation and process improvement</strong>. We are looking for someone who is a creator and problem solver—someone who sees a manual process and asks, <em>“How can we make this better and automate it?”</em></p><p>What You’ll Do</p><ul><li>Build, implement, and mature <strong>PCI DSS compliance programs</strong> from the ground up.</li><li>Define and maintain <strong>PCI scope and boundaries</strong>, including identifying systems, applications, networks, processes, and people that fall within PCI requirements.</li><li>Develop a strong understanding of the <strong>Cardholder Data Environment (CDE)</strong> and how payment card data moves through the environment.</li><li>Establish, document, and validate technical and administrative controls required for PCI DSS compliance.</li><li>Lead PCI audit preparation, evidence gathering, auditor coordination, remediation, and ongoing compliance activities.</li><li>Gather and validate technical artifacts and evidence required to demonstrate compliance.</li><li>Identify control gaps and partner with technical teams to develop and implement remediation plans.</li><li>Continuously assess and mature the PCI program as the technology environment and business requirements evolve.</li><li><strong>Automate PCI evidence collection, control validation, reporting, and other repetitive compliance processes.</strong></li><li>Identify opportunities to automate manual GRC and Information Security processes beyond PCI.</li><li>Develop repeatable processes and solutions that improve efficiency, accuracy, and audit readiness.</li><li>Support internal audits and financial services regulatory examinations.</li><li>Document technical processes and controls in a clear and accurate manner.</li><li>Develop metrics and reporting that communicate compliance, control effectiveness, risk, and remediation status to leadership.</li><li>Partner with Information Security, Infrastructure, Application, Risk, Audit, and other technical teams.</li><li>Help establish and maintain security policies, standards, procedures, and controls related to PCI and Information Security.</li></ul>