GRC Engineer

2 hours, 24 minutes ago
Full-time
Mid Level
Cybersecurity
Qonto

Qonto

Qonto provides a comprehensive financial management solution for small and medium-sized enterprises and freelancers, offering services such as business accounts, invoicing, bookkeeping, expense management, and financing, all supported by dedicated cust...

Banks
1K-5K
Founded 2016
$703M raised

Description

  • Own and deliver external and internal audits and certifications end-to-end with minimal findings.
  • Lead compliance efforts for frameworks including ISO 27001, PCI DSS, DORA, DSP2, and PDP.
  • Build tooling and automation to reduce manual evidence collection and reporting.
  • Maintain the documentary corpus and control mapping for upcoming regulations.
  • Translate compliance requirements into clear, actionable requests for technical teams.
  • Prepare and defend Qonto’s compliance positions with auditors using pragmatic, risk-based arguments.
  • Work closely with Internal Control, external auditors, and Security engineering teams.
  • Support continuous compliance by shifting processes from point-in-time checks to automated workflows.

Requirements

  • Proven experience owning security compliance frameworks and audits end-to-end in regulated environments.
  • Experience with security certifications such as ISO 27001 or PCI DSS.
  • Hands-on experience building tools, scripts, or integrations to automate repetitive compliance tasks and evidence collection.
  • Ability to constructively challenge interpretations and defend risk-based compliance positions with external auditors.
  • Strong project management skills with the ability to manage multiple stakeholders, deadlines, and an audit calendar.
  • Ability to quickly understand technical contexts and collaborate effectively with engineers.
  • Curiosity and a growth mindset, with motivation to work across multiple regulatory frameworks.
  • Experience in highly regulated fintech or similar environments is preferred.

Benefits

  • Remote full-time role with locations in Paris, Barcelona, Berlin, or Milan.
  • Opportunity for broad multi-framework exposure across ISO 27001, PCI DSS, DSP2, PDP, and DORA.
  • High learning and growth potential in a fast-paced, regulated fintech environment.
  • Work on automation-focused compliance rather than purely manual spreadsheet-based processes.
  • Collaborate closely with security leaders and experienced external auditors.
  • On average, the hiring process lasts 20 working days.
  • Qonto provides unlimited access to AI tools for employees.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior DevSecOps Engineer

GoReel 51-200 Software Development

Senior DevSecOps at a European iGaming solution provider to secure, automate, and stabilize cloud infrastructure while embedding security across product delivery with development, platform, and security teams.

API Gateway AWS Bash Cloudflare DevSecOps DNS Encryption GitHub Actions Go Kubernetes OpenID Connect Python SAML SIEM SOC Terraform TLS WAF
3 hours, 3 minutes ago

Sr. Security Software Engineer, Internal Identity & Access Management

Pinterest 5K-10K Internet Software & Services

Pinterest is hiring an experienced software engineer for its Internal Identity & Access Management team to build and maintain critical infrastructure for identity and access controls across production systems.

AWS C++ Envoy Go Kubernetes OAuth Puppet Python React SAML Terraform TypeScript
6 hours, 47 minutes ago

Security Engineer - Product & Production Infrastructure

Wiz 251-1K IT Services

Wiz is seeking a Security Engineer for Product & Production Infrastructure to secure its cloud-native products, CI/CD, and production environments while helping shape defensive practices across the company.

AWS Azure CI/CD GCP Go Helm Kubernetes Python Rust Terraform
7 hours, 23 minutes ago

Security Engineer

Yuno 51-200 Payment Processing Software

Yuno is hiring a Security Engineer to strengthen security across its cloud, CI/CD, and containerized payment infrastructure as the company scales globally.

AWS CloudFormation GCP Kubernetes Python Serverless SIEM Terraform WAF
10 hours, 48 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers