As a GRC Specialist at Chargeblast, you will make sure our security posture aligns with our business objectives, regulatory requirements, and industry best practices. You will own day-to-day risk assessments, audit readiness (SOC 2, PCI DSS), and the policies that keep a payments company trustworthy and, at the senior end, help shape our enterprise risk strategy and translate cyber risk into business terms for leadership.
Daily Duties & Responsibilities
- Conduct end-to-end risk assessments, maintain the enterprise risk register, and evaluate third-party / vendor risk; propose practical mitigations.
- Implement and audit security controls against established frameworks (NIST CSF, ISO 27001) and identify compliance gaps before auditors do.
- Lead internal audits and act as a primary point of contact for external auditors for SOC 2 and PCI DSS engagements; collect evidence and track remediation to closure.
- Write and maintain comprehensive security policies, standards, and guidelines, ensuring they reflect how teams actually operate.
- Align security controls with department-level business processes and partner with Engineering and Operations on remediation.
- (Senior) Help design the enterprise risk management strategy, quantify risk (e.g., FAIR methodology), and communicate risk in financial and operational terms to executive leadership.
Required Qualifications
- 1 – 3 years of experience in GRC, IT audit, security compliance, or a closely related field.
- Working knowledge of at least one major framework (NIST CSF, ISO 27001) and experience mapping controls to policies.
- Hands-on experience supporting or leading audits such as SOC 2 or PCI DSS, including evidence collection and remediation tracking.
- Strong written communication able to draft clear policies and explain risk to both technical and non-technical audiences.
- Solid understanding of how IT and security support core business operations.
Preferred Skills
- Experience in fintech, payments, or another regulated industry.
- Ability to conduct independent third-party/vendor risk reviews and adapt processes to specific situations.
- Experience driving a security-awareness culture and securing buy-in for policy enforcement.
- Familiarity with GRC tooling and evidence-automation platforms.
Good to Have (Technical & Certifications)
Technical — Good to Have
- Experience selecting, customizing, and integrating frameworks across a global business.
- Risk quantification experience (e.g., FAIR) and reporting risk to the Head of Security
- Exposure to additional regimes such as PCI-DSS, ISO27001.
Certifications — Good to Have
- Any relevant certification.
Working Conditions
- Full-Remote work (US timezone)
- Standard full-time schedule with flexible hours. Security Operations roles participate in a shared on-call rotation for incident response.
- Primarily computer-based work in a fast-paced startup environment. You will collaborate asynchronously across Engineering, DevOps, Legal, and business teams.