Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
GRC Engineer image - Rise Careers
Job details

GRC Engineer

About OnePay

OnePay is a consumer financial services app with an exceedingly simple mission: to help people achieve financial progress.

Tens of millions of Americans today are unbanked or underbanked, meaning they don’t have enough money in savings to cover a minor emergency. They pay too much in fees, don’t have access to credit at affordable rates, and have little ability to grow their wealth. OnePay’s vision is to create a single app for consumers to save, spend, borrow, and grow their money, bringing our mission to life with simple and accessible banking, credit, and payments products that deliver a best-in-class experience to millions of customers. Our products include:

  • Checking and high-yield savings accounts

  • Domestic and international peer-to-peer payments

  • Credit Builder and credit score monitoring

  • Digital wallet / contactless payment solutions

  • Buy-now-pay-later installment loans at Walmart

Why do we have a right to win? We have the backing of Walmart (a Fortune 1) and Ribbit Capital (a preeminent fintech investor), are deeply embedded with the distribution of the world’s largest omnichannel retailer, and have an industry-leading multi-product value proposition — all in addition to having some of the best people and talent in the industry.

There’s never been a better time to build a category-defining business and there has rarely been a team better positioned for the opportunity. Join us!

The role

As a GRC Engineer, you will be instrumental in the oversight and operation of OnePay's Information Security program, including its third party risk management program. You will have the opportunity to manage and execute OnePay's information security risk management processes, including performing third party due diligence reviews, managing identified security risks, and working on assessments conducted by other independent parties, such as auditors, partners, and vendors. You will also have opportunities to identify control & process gaps and lead efforts to remediate such gaps.

This role is responsible for: 

  • Performing appropriate due diligence on OnePay's third-party vendors and partners’ capabilities around data protection, business continuity, and platform security.

  • Review contractual agreements and documents to ensure they meet internal standards and requirements for information security and privacy. 

  • Engage with both technology and business teams as a consultant for any security-related issues that affect OnePay's product features and offerings. 

  • Identify and track security risks throughout OnePay's environment and drive them to remediation with the appropriate stakeholders. 

  • Assist in audits conducted by external parties by performing internal readiness assessments, facilitating walkthroughs with key stakeholders, gathering relevant evidence, and driving remediation of any gaps identified. 

  • Assist in reviewing OnePay's compliance with privacy requirements and regulations as part of its product operations.

You bring

  • 10+ years of experience in information security, internal and third party risk management, and/or audit management. 

  • Strong knowledge of various industry standard frameworks such as NIST, SOC 2, PCI DSS, HiTrust, etc.

  • Thorough knowledge of enterprise-scale security architecture, cloud security, and business continuity program best practices.

  • The ability to explain security concepts to both technical and non-technical stakeholders.

  • Domain knowledge of multiple disciplines including IT systems, networking, security, and compliance. 

  • Relevant certifications (such as AWS Certified Solutions Architect, CISSP, etc.) are a plus.

What We Offer

  • Competitive salary, stock options, and benefits from Day 1

  • Comprehensive health insurance coverage (health insurance, accident and disability insurance, term life insurance), including mental health support and wellness programs

  • Hybrid work model (Bengaluru office three days a week), various time off programs (vacation, sick, other paid leaves, and paid regional holidays)

  • Monthly transport and work-from-home allowances

  • A high-growth, mission-driven, inclusive culture where your work has real impact

Standard Interview Process

  • Initial Interview with Talent Partner

  • Technical or Hiring Manager Interview

  • Team Interview

  • Executive Interview

  • Offer!

Equal Employment Opportunity

To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@onepay.com.

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About GRC Engineer, OnePay

Join OnePay as a GRC Engineer in Bangalore and become a vital part of a transformative mission to help people achieve financial progress! At OnePay, we understand that many individuals lack access to essential banking services, and our goal is to provide a seamless digital platform where users can save, spend, borrow, and grow their wealth. As a GRC Engineer, you'll take a leading role in managing our Information Security program, focusing specifically on third-party risk management. Your expertise will guide you in executing our security risk management processes, assessing our vendors’ security capabilities, and ensuring compliance with industry standards like NIST and SOC 2. You’ll regularly engage with technical and business teams to address security-related challenges and identify potential risks, driving efforts toward effective remediation. Each day will bring a new challenge—whether it's reviewing contractual agreements, conducting internal audits, or tracking compliance with privacy regulations. With over 10 years of experience in information security or risk management, you’ll bring a wealth of knowledge to the team. Plus, at OnePay, you’ll enjoy a competitive salary, benefits from Day 1, and a hybrid work model. If you're excited about working with a passionate team supported by giants like Walmart, we invite you to join us in this groundbreaking financial venture!

Frequently Asked Questions (FAQs) for GRC Engineer Role at OnePay
What are the key responsibilities of a GRC Engineer at OnePay?

As a GRC Engineer at OnePay, your responsibilities will include overseeing the Information Security program, performing third-party due diligence reviews, and managing identified security risks. You will work closely with technology and business teams to address security-related issues impacting our products and engage in internal audits to assess compliance with privacy and security standards.

Join Rise to see the full answer
What qualifications are required for the GRC Engineer role at OnePay?

To qualify for the GRC Engineer position at OnePay, you should have 10+ years of experience in information security and risk management. A strong grasp of industry standard frameworks, such as NIST and SOC 2, is essential. Additionally, familiarity with enterprise-scale security architecture and relevant certifications like CISSP or AWS Certified Solutions Architect would be advantageous.

Join Rise to see the full answer
How does OnePay support its GRC Engineers in career development?

OnePay is committed to the professional growth of its GRC Engineers. We provide comprehensive health coverage, regular skills training, and opportunities for certifications. Additionally, our hybrid work model fosters work-life balance, allowing you to thrive both professionally and personally.

Join Rise to see the full answer
What working environment can GRC Engineers expect at OnePay?

At OnePay, GRC Engineers can expect a high-growth, mission-driven, and inclusive workplace culture. You will have the opportunity to collaborate with a diverse team and contribute towards innovative financial solutions that have a real impact on people's lives.

Join Rise to see the full answer
What are the performance expectations for a GRC Engineer throughout the year?

Performance expectations for a GRC Engineer at OnePay revolve around effectively managing security risk assessments, ensuring compliance with regulatory standards, and actively collaborating with multiple teams to identify security gaps. Regular communication with stakeholders and timely remediation of identified risks are also crucial aspects of your role.

Join Rise to see the full answer
Common Interview Questions for GRC Engineer
Can you describe your experience with third-party risk management?

When answering this question, provide specific examples of how you've conducted due diligence on vendors, assessed their security capabilities, and managed ongoing risks. Highlight any frameworks you used and how your efforts improved security posture.

Join Rise to see the full answer
What frameworks are you familiar with in information security, and how have you implemented them?

Discuss frameworks like NIST, SOC 2, or PCI DSS that you've worked with. Share concrete examples of how you've integrated these frameworks into your organization's risk management strategy, showcasing the impact of your implementation.

Join Rise to see the full answer
How do you approach communication with non-technical stakeholders regarding security?

Emphasize the importance of simplifying complex security concepts into relatable terms. Discuss past experiences where you successfully educated non-technical stakeholders about security risks and the necessity of compliance, fostering a collaborative environment.

Join Rise to see the full answer
What strategies do you use to identify and mitigate security risks?

Talk about your methodologies for assessing security risks, including risk assessments, threat modeling, and continuous monitoring. Share specific examples of tools or software you've used to track and manage these risks effectively.

Join Rise to see the full answer
How do you ensure compliance with privacy regulations in your role?

Provide your approach to compliance, mentioning the importance of regular audits, continuous training, and staying updated with changing regulations. Share any relevant experiences where your actions led to improved compliance outcomes.

Join Rise to see the full answer
Can you give an example of a time when you identified a significant security gap?

Share a specific case where you detected a security gap. Explain how you discovered it, the steps you took to address it, and what the outcome was, emphasizing your problem-solving skills and ability to work with others for remediation.

Join Rise to see the full answer
What role do audits play in your information security strategy?

Discuss the significance of audits as a tool for risk management. Describe your experiences with both internal and external audits and how they have influenced improvements in your organization's security measures.

Join Rise to see the full answer
How do you stay current with emerging risks and trends in cybersecurity?

Share the resources, websites, webinars, or industry groups you follow to keep informed. Explain how you apply the knowledge gained from these sources to your work, ensuring your strategies remain effective against new threats.

Join Rise to see the full answer
What is your experience with using security tools and software?

Outline the specific security tools and software you've used in your previous roles, focusing on how these tools helped you improve security posture, streamline risk assessments, or automate monitoring processes.

Join Rise to see the full answer
How do you handle conflicts with stakeholders regarding security measures?

Talk about your approach to conflict resolution, emphasizing communication and understanding different perspectives. Provide an example of a conflict you've navigated successfully, showcasing your ability to maintain a collaborative environment.

Join Rise to see the full answer
Similar Jobs
OnePay Remote No location specified
Posted 4 days ago
OnePay Remote No location specified
Posted 4 days ago
Posted 3 days ago
Photo of the Rise User
Varonis Remote No location specified
Posted 2 days ago
Photo of the Rise User
Posted 2 days ago
Photo of the Rise User
AllTrails Remote San Francisco
Posted 4 days ago
Photo of the Rise User
Posted 5 days ago
Photo of the Rise User
Posted 2 days ago
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
March 22, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
54 people applied to Jr SOC Analyst at IBM
Photo of the Rise User
Someone from OH, Cincinnati just viewed Recruiting Coordinator (Contractor) at Anduril Industries
Photo of the Rise User
Someone from OH, Dublin just viewed Field Support Technicians - (Phoenix) at Nordstrom
Photo of the Rise User
Someone from OH, Stow just viewed IT Asset administrator at Ergomed
Photo of the Rise User
Someone from OH, Loveland just viewed Senior Buyer (wholesale) (m/f/d) at ABOUT YOU SE & Co. KG
Photo of the Rise User
Someone from OH, Cincinnati just viewed Summer 2025 Internship: Talent at Hylant
C
Someone from OH, Cincinnati just viewed Senior Instructional Designer at CXG
Photo of the Rise User
Someone from OH, Youngstown just viewed Compliance Specialist, Anti-Corruption Program at ServiceNow
Photo of the Rise User
Someone from OH, Cleveland just viewed Finance Intern - Summer 2025 at Spectrum
Photo of the Rise User
Someone from OH, Cleveland just viewed QC Engineer at QODE
Photo of the Rise User
34 people applied to Cyber Crime Analyst at TEKsystems
Photo of the Rise User
Someone from OH, Cleveland just viewed Getinge is hiring: UI/UX Developer in Streetsboro at Getinge
Photo of the Rise User
Someone from OH, Westerville just viewed Data analyst | Mid at Nord Security
Photo of the Rise User
Someone from OH, North Canton just viewed Researcher-NBC Sports at NBCUniversal
Photo of the Rise User
Someone from OH, North Canton just viewed Researcher-NBC Sports at NBCUniversal
Photo of the Rise User
Someone from OH, Lakewood just viewed Culture and Programs Analyst at City of Philadelphia
Photo of the Rise User
Someone from OH, Olmsted Falls just viewed Customer Service - Representative at Waterway Carwash
M
Someone from OH, Strongsville just viewed Technical Writer (Contract) at Mintlify