- Company Name
- FanDuel
- Job Title
- GRC Engineer
- Job Description
-
**Job Title:** GRC Engineer
**Role Summary:**
Engineer scalable automation and integrations for Governance, Risk, and Compliance (GRC) programs across Third-Party Risk Management (TPRM), Identity Governance & Administration (IGA), Technology Risk, and Business Continuity/Disaster Recovery (BCDR). Embed GRC practices into technical systems while balancing compliance rigor with operational efficiency in fast-paced environments.
**Expectations:**
5-7+ years of technical experience in Security Engineering or GRC domains. Demonstrated ability to solve complex challenges via code, collaborate across technical teams, and adapt to evolving regulations and technologies.
**Key Responsibilities:**
- Engineer automation to streamline GRC processes (vendor risk assessments, access recertifications, resilience testing).
- Implement integrations between GRC platforms, IAM systems, and enterprise tools (e.g., APIs, OneTrust, Tines).
- Build and maintain policy-as-code frameworks (e.g., Rego/OPA, Terraform Sentinel) to enforce compliance in workflows.
- Automate control testing, monitoring, and assurance reporting for regulatory frameworks (SOX, SOC 2, GDPR, etc.).
- Collaborate with infrastructure, application, and cloud engineering teams to embed GRC requirements.
- Document and share knowledge on GRC tooling and automated workflows.
**Required Skills:**
- Proficiency in Python, JavaScript, PowerShell, SQL, and API integration.
- Experience with GRC domains (TPRM, IGA, BCDR) and associated tools (OneTrust, Zilla, Riskonnect).
- Familiarity with AWS infrastructure and integration patterns.
- Strong understanding of regulatory frameworks (SOX, SOC 2, PCI, GDPR, ISO 27001, NIST CSF).
**Required Education & Certifications:**
- Bachelor’s degree in computer science, engineering, or equivalent.
- Preferred certifications: CISA, CISSP, or CISM.
- Experience with automation/orchestration tools (e.g., Tines) and policy-as-code platforms.