Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
GRC Engineer - Risk and Assurance image - Rise Careers
Job details

GRC Engineer - Risk and Assurance

About OnePay

OnePay is a consumer financial services app with an exceedingly simple mission: to help people achieve financial progress.

Tens of millions of Americans today are unbanked or underbanked, meaning they don’t have enough money in savings to cover a minor emergency. They pay too much in fees, don’t have access to credit at affordable rates, and have little ability to grow their wealth. OnePay’s vision is to create a single app for consumers to save, spend, borrow, and grow their money, bringing our mission to life with simple and accessible banking, credit, and payments products that deliver a best-in-class experience to millions of customers. Our products include:

  • Checking and high-yield savings accounts

  • Domestic and international peer-to-peer payments

  • Credit Builder and credit score monitoring

  • Digital wallet / contactless payment solutions

  • Buy-now-pay-later installment loans at Walmart

Why do we have a right to win? We have the backing of Walmart (a Fortune 1) and Ribbit Capital (a preeminent fintech investor), are deeply embedded with the distribution of the world’s largest omnichannel retailer, and have an industry-leading multi-product value proposition — all in addition to having some of the best people and talent in the industry.

There’s never been a better time to build a category-defining business and there has rarely been a team better positioned for the opportunity. Join us!

The role

As our GRC Engineer in Risk and Assurance at OnePay, you will support the Security team with a focus on third-party risk management (TPRM), while also contributing to vulnerability and patch management, reviewing cloud security findings, data governance and privacy, and audit support. It’s a hybrid security role for someone eager to wear multiple security-related hats and grow alongside a seasoned team! You will:

  • Drive  and support the third-party risk management (TPRM) process

  • Collaborate on vendor assessments and contract reviews tied to business deals

  • Assist with vulnerability and patch management operations and process implementation

  • Support the review of cloud security findings and remediation workflows

  • Assist in the implementation of new systems and applications from a security perspective

  • Help build the data governance and privacy program in conjunction with legal and business stakeholders

  • Contribute to security compliance activities and internal & external audits

You bring

  • 6+ years of experience in security governance, cloud and application security assessments, risk management, and/or third party risk.

  • Strong knowledge of various industry standard frameworks such as NIST, FFIEC, SOC 2, PCI DSS, HiTrust, etc.

  • Thorough knowledge of enterprise-scale security architecture, cloud security, and application security best practices.

  • Domain knowledge of multiple disciplines including IT systems, networking, security, and compliance.

  • Familiarity with containerization technologies (e.g., Docker, Kubernetes) and CI/CD pipelines.

  • Excellent written and verbal communication skills, with the ability to convey technical concepts to both technical and non-technical audiences.

  • Strong analytical and problem-solving skills with the ability to work independently and as part of a team.

  • Relevant certifications such as AWS Certified Security Specialty, Certified Information Systems Security Professional (CISSP), or Certified Cloud Security Professional (CCSP) are a plus.

Pay Transparency

The estimated annual base salary for this position ranges from $143,000 to $175,000. Pay is generally based upon the level, complexity, responsibility, location and job duties/requirements of the specific position. We then source candidates with the requisite skills, expertise, education, training, and experience.  If you are selected for an interview, please feel welcome to speak to a Talent Partner about our compensation philosophy and other available benefits.

What it’s like working @ One

  • Competitive cash

  • Benefits effective on day one

  • Early access to a high potential, high growth fintech

  • Generous stock option packages in an early-stage startup

  • Remote friendly (anywhere in the US) and office friendly - you pick the schedule

  • Flexible time off programs - vacation, sick, paid parental leave, and paid caregiver leave

  • 401(k) plan with match

Standard Interview Process

  • Initial Interview with Talent Partner

  • Technical or Hiring Manager Interview

  • Team Interview

  • Executive Interview

  • Offer!

Equal Employment Opportunity

To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@onepay.com.

Average salary estimate

$159000 / YEARLY (est.)
min
max
$143000K
$175000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About GRC Engineer - Risk and Assurance, OnePay

At OnePay, we're on a mission to transform financial services for millions of Americans who are unbanked or underbanked, and we're looking for a passionate GRC Engineer - Risk and Assurance to join our dynamic team! Imagine being at the forefront of innovative solutions that help people save, spend, borrow, and grow their money. This role is pivotal as you'll support our Security team by focusing on third-party risk management, vulnerability and patch management, and cloud security assessments. We want someone who's excited to wear multiple hats and grow with us in this hybrid security role. Your contributions will significantly impact our operational success as you drive the TPRM process, collaborate on vendor assessments, and assist in building our data governance and privacy frameworks. With your expertise in security governance and cloud security best practices, you will help us ensure that our groundbreaking products are secure, compliant, and trustworthy. At OnePay, we believe in empowering our employees, and with competitive cash compensation, generous stock options, and a flexible work environment, we aim to attract the best talent in the industry. If you're looking for a career that not only challenges you but also offers room for growth within an exciting fintech startup, then we invite you to join us on this journey!

Frequently Asked Questions (FAQs) for GRC Engineer - Risk and Assurance Role at OnePay
What are the main responsibilities of the GRC Engineer - Risk and Assurance at OnePay?

As a GRC Engineer - Risk and Assurance at OnePay, your primary responsibilities will include supporting the security team with third-party risk management, collaborating on vendor assessments, assisting with vulnerability and patch management, reviewing cloud security findings, and contributing to data governance and privacy programs. Your role is crucial in ensuring compliance and security for our innovative financial services.

Join Rise to see the full answer
What qualifications are required for the GRC Engineer - Risk and Assurance position at OnePay?

The GRC Engineer - Risk and Assurance position at OnePay requires at least 6 years of experience in security governance, risk management, and cloud security assessments. Ideal candidates should have strong knowledge of industry frameworks like NIST and SOC 2, familiarity with containerization technologies, and excellent analytical skills. Relevant security certifications will be an advantage!

Join Rise to see the full answer
How does OnePay support its GRC Engineer - Risk and Assurance team in professional growth?

At OnePay, we prioritize the professional development of our GRC Engineer - Risk and Assurance team by offering supportive mentorship, opportunities for further training, and a flexible work environment that encourages continuous learning. You'll have access to leadership activities, internal audits, and collaboration with talented professionals, all of which contribute to your growth.

Join Rise to see the full answer
What security frameworks should a GRC Engineer - Risk and Assurance at OnePay be familiar with?

A GRC Engineer - Risk and Assurance at OnePay should be well-versed in various security frameworks including NIST, FFIEC, SOC 2, PCI DSS, and HiTrust. This knowledge is crucial for evaluating compliance and helping OnePay maintain industry-leading security standards across our financial products.

Join Rise to see the full answer
Is remote work available for the GRC Engineer - Risk and Assurance position at OnePay?

Yes! OnePay offers a remote-friendly environment for the GRC Engineer - Risk and Assurance position, allowing you to choose a work location that suits you best within the U.S. We offer a balanced work-life approach with flexible scheduling to ensure our employees can thrive both personally and professionally.

Join Rise to see the full answer
Common Interview Questions for GRC Engineer - Risk and Assurance
Can you describe your experience with third-party risk management as a GRC Engineer?

In answering this question, you should leverage examples from your past roles. Discuss specific projects where you've assessed third-party risks, detailing the frameworks and processes you used. Highlight collaboration with vendors and your contributions towards successful risk mitigation strategies.

Join Rise to see the full answer
How would you handle a security vulnerability discovered in a cloud application?

Illustrate your response process by outlining steps such as triaging the vulnerability, assessing its impact, collaborating with the development team for remediation, and communicating with relevant stakeholders. Showcase your understanding of urgency and effective communication.

Join Rise to see the full answer
Which security frameworks do you have experience with, and how have you applied them?

Mention specific frameworks like NIST or SOC 2 that you’ve worked with, providing concrete examples of how you've implemented them in previous roles. Focus on their relevance to compliance and risk management and how they contributed to the overall security posture.

Join Rise to see the full answer
What tools and technologies have you used for vulnerability and patch management?

Discuss tools such as Qualys, Nessus, or Rapid7 that you have utilized in your roles. Explain how these tools helped you identify vulnerabilities and manage patch processes effectively, reinforcing your technical competence and hands-on experience.

Join Rise to see the full answer
How do you ensure effective communication between technical and non-technical teams?

Showcase your ability to tailor communication based on your audience. Share examples of reports or presentations you have created for non-technical stakeholders, ensuring clarity while maintaining the technical integrity of the information.

Join Rise to see the full answer
Can you provide an example of how you've contributed to an audit process?

Discuss specific audits you have participated in, your role in gathering necessary documentation, and how you addressed auditor inquiries. Highlight your attention to detail and proactive approach in ensuring compliance with security and data privacy regulations.

Join Rise to see the full answer
What strategies do you employ for data governance?

Talk about the frameworks or methodologies you use to create a data governance strategy. Mention collaboration with legal and business stakeholders and any past experience where you helped design or implement effective governance policies.

Join Rise to see the full answer
What motivates you to work in risk management and assurance?

Provide a personal perspective on your passion for risk management. Discuss how your interest in technological security, problem-solving, and helping organizations succeed drives your career choice in this field.

Join Rise to see the full answer
How do you stay updated on the latest security threats and trends?

Share your strategies for professional growth, such as attending conferences, participating in webinars, reading industry publications, or following thought leaders in the cybersecurity space. This showcases your commitment to continuous improvement.

Join Rise to see the full answer
Why do you wish to join OnePay as a GRC Engineer - Risk and Assurance?

Express your enthusiasm for OnePay’s mission to improve financial services while identifying aspects of the company that align with your values and career objectives. Highlight your eagerness to contribute to the innovative financial products that have a meaningful impact on consumers.

Join Rise to see the full answer
Similar Jobs
OnePay Remote No location specified
Posted 6 days ago

OnePay seeks an experienced Corporate Security Engineer to lead the design and optimization of corporate security infrastructure in a mission-driven environment.

Posted 7 days ago

As a Software Engineer at OnePay, contribute to enabling seamless financial experiences for users as part of a fast-paced, mission-driven team.

Photo of the Rise User
Posted 3 days ago

Join Optimiza as an Advanced Technologies Specialist to lead the exploration and implementation of cutting-edge technologies for exceptional client solutions.

Take the lead as a Senior Manager in Technology Operations at Marqeta, where you'll shape the IT strategy and manage a talented team to drive technological innovation.

Photo of the Rise User
Posted yesterday

Visa seeks a passionate Sr. Cybersecurity Engineer to enhance IAM processes using AI and automation in a hybrid work environment.

Photo of the Rise User
Posted 10 days ago

Join Analog Devices as a Cloud Architecture Leader and oversee the strategic design and management of cloud infrastructure.

Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Diversity of Opinions

Join Amplify as a System Administrator to enhance project management through expertise in Jira and Smartsheet.

Photo of the Rise User

Join Scientific Research Corporation as a Network Engineer and contribute to crucial network solutions for Navy networks and government clients.

Photo of the Rise User
Posted 12 days ago

Join Mindera as an experienced Cloud Engineer, working with a talented team to enhance infrastructure and DevOps practices while enjoying a flexible work culture.

Fortune Brands Hybrid 520 Lake Cook Road, Deerfield, ILLINOIS
Posted 10 days ago

Seeking a skilled Lead Applications Analyst for HR Technologies to join Fortune Brands Innovations and enhance their HR systems integration.

MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 12, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Columbus just viewed Scrum Master at Sysco Costa Rica
Photo of the Rise User
54 people applied to Cybersecurity Intern at Dewberry
X
Someone from OH, Cincinnati just viewed Senior Java Engineer (Remote) at Xenon7
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior, Software Engineer- Java at Walmart
Photo of the Rise User
Someone from OH, Cincinnati just viewed Java, Javascript, Python, NodeJS Software Engineer at Walmart
Photo of the Rise User
6 people applied to Security Analyst at ANS
Photo of the Rise User
52 people applied to Security Analyst Jr at DEUNA
Photo of the Rise User
Someone from OH, Pickerington just viewed Senior Business Analyst (Salesforce) at Protolabs
H
Someone from OH, Akron just viewed Brand Marketing Manager at Huntington
R
Someone from OH, Hamilton just viewed Forklift Operator Warehouse at Ryder
Photo of the Rise User
Someone from OH, Cincinnati just viewed Ad Ops Specialist, Display at System1
Photo of the Rise User
Someone from OH, Cincinnati just viewed FQHC Billing & Collections Manager at OhioGuidestone
Photo of the Rise User
Someone from OH, Cleveland just viewed Enrollment Specialist- Remote at Adtalem Global Education
o
Someone from OH, Dayton just viewed Marketing and Communications Specialist at osu
Photo of the Rise User
Someone from OH, Columbus just viewed Construction Coordinator at Meijer
Photo of the Rise User
Someone from OH, Steubenville just viewed Legal & Compliance Internship at Smiths Group
Photo of the Rise User
Someone from OH, Warren just viewed Senior Front-End Developer at Worldly
Photo of the Rise User
Someone from OH, Tiffin just viewed Game Operations Specialist at Genius Sports
u
Someone from OH, Loveland just viewed Customer Service Agent - Part Time at uhaul
Photo of the Rise User
Someone from OH, Cleveland just viewed HR Manager at Shearer's Foods
Photo of the Rise User
Someone from OH, Columbus just viewed Mid Level, System Administrator - (ETS) at Delivery Hero
Photo of the Rise User
Someone from OH, Mason just viewed Inside Sales Co-Op at VEGA Americas