Employment Hero is seeking a Security GRC Engineer to embed governance, risk, and compliance into engineering workflows.
The role focuses on building scalable, automated, and stakeholder-friendly security and risk capabilities.
Responsibilities include integrating GRC into engineering, automating security controls, enhancing stakeholder experience, supporting compliance frameworks, monitoring and measuring risk, driving continuous improvement, and contributing to the GRC handbook.
The position requires hands-on scripting work and a strong GRC automation mindset.
The engineer will work closely with development, DevOps, and product teams to implement shift-left security and GRC-as-Code practices.
Requirements:
Candidates must have a strong GRC automation mindset with hands-on scripting experience.
Experience with Dependabot for compliance and vulnerability management workflows is required.
Familiarity with Jira/Slack integration and automation for audit traceability is necessary.
A strong understanding of ISO 27001 and SOC 2 frameworks is essential.
Candidates should be able to translate technical risk into clear, actionable language.
A focus on scalable and sustainable security governance practices is expected.
Bonus points for experience building or contributing to internal tools or open-source GRC projects, a product or stakeholder-centric view of security and compliance, exposure to security tooling like Vanta or Drata, and experience in fast-paced, product-led tech environments.
Benefits:
Employment Hero offers a remote work environment with flexibility in managing time and impact.
Employees will have access to cutting-edge tools to enhance their work and knowledge.
The company promotes a culture of ambitious, outcome-driven colleagues who encourage high performance.
Employees will own ESOP (employee share options) in a rapidly growing tech company.
A wide range of benefits is provided, including a generous paternity leave policy, subsidized egg freezing, a work-from-home office expense budget, and outstanding learning and development opportunities.