Skip to main content
Taktile

GRC Engineer - Platform Team

RemoteRomania, United Kingdom, Germany only
Published
Role
Security
Experience
Mid
Employment
Full-time
Company size
Startup
Salary not disclosed
Check eligibility

Open to RO, GB, DE only. Set where you work from to check your eligibility.

No BS summary

As our GRC Engineer on the Platform Team, you'll own the controls, evidence, and processes that keep Taktile secure, compliant, and continuously audit-ready. You'll be the engineering-minded backbone of our compliance program, turning frameworks like SOC 2, ISO 27001, GDPR, and the EU AI Act into automated, continuously-monitored controls rather than one-off, point-in-time checklists.This is a cross-functional, high-leverage role. You'll partner with Security, Engineering, Product, and IT to close the gap between policy and control implementation, and with Sales, Legal, Support, and Leadership to make compliance a competitive advantage rather than a bottleneck. The ideal candidate pairs deep framework knowledge with the technical ability to automate it; fielding a complex customer security questionnaire in the morning and scripting AWS evidence collection in the afternoon.

Core skills

SOC 2ISO 27001GRC

Required skills

GDPRAWS APIsVantaDrataSecureframeNIST CSFCIS ControlsDPA

Optional skills

DORAEU AI Actfintech regulatoryengineering-led automationNIST CSFCIS ControlsGDPRDPA

What you'll do

  • Own continuous compliance end-to-end ; SOC 2, ISO 27001, and customer security reviews, keeping us audit-ready year-round rather than scrambling at renewal time.
  • Manage and evolve the compliance roadmap, prioritizing initiatives against business and customer needs; own Vanta end-to-end, including tasks, documentation, integrations, and automated evidence collection.
  • Lead quarterly access reviews across all systems in collaboration with IT and Engineering, ensuring findings are tracked through to remediation.
  • Run vendor risk reviews and DPIAs for new tools (especially AI tooling) and help teams adopt new software quickly without compromising our risk posture.
  • Serve as the technical voice on customer security questionnaires and DPAs, working alongside Sales and Legal to keep deals moving.
  • Define and report compliance and risk KPIs to leadership, giving them a clear, ongoing view of our posture and where investment is needed.
  • Partner with the Security Architect to identify and close gaps between written policy and actual control implementation.

What they require

  • 4+ years in GRC, security compliance, or audit readiness at a SaaS company, ideally in a regulated environment (Finance, Insurance, Healthcare).
  • Has owned a SOC 2 program end-to-end (must-have), ideally ISO 27001 too, from gap analysis through audit and maintenance; familiar with GDPR, PCI DSS, and the EU AI Act.
  • Deep experience running Vanta (or Drata/Secureframe) as a continuous compliance backbone, not a point-in-time checklist.
  • Technically hands-on: comfortable scripting against AWS APIs to automate evidence collection, with a solid grasp of software development and security concepts.
  • A strong writer and communicator who can turn around a 200-row security questionnaire quickly and accurately, and translate fluently between compliance and technical teams.
  • Experience with customer trust programs (Trust Center, FAQs, security whitepapers).
  • DORA / EU AI Act / fintech regulatory exposure.
  • Has shipped engineering-led automation (not just dashboards).
  • Familiarity with NIST CSF, CIS Controls, or GDPR/DPAs.

Benefits

  • Work with colleagues that lift you up, challenge you, celebrate you and help you grow.
  • Make an impact and meaningfully shape an early-stage company.
  • Experience a truly flat hierarchy and communicate directly with founding team members.
  • Learn from experienced mentors and achieve tremendous personal and professional growth.
  • Get to know and leverage our network of leading tech investors and advisors around the globe.
  • Receive a top-of-market equity and cash compensation package.
  • Get access to a self-development budget you can use to e.g. attend conferences, buy books or take classes.
  • Use the equipment of your choice including meaningful home office set-up.

Taktile enables financial institutions to transform into AI-native organizations that are increasingly powered by autonomous agents. With our modular Agentic Decision Platform, customers combine AI agents, rules, relevant context, and human oversight to safely automate and optimize their decisions—approving more customers, reimbursing claims instantly, stopping fraud before it spreads, and financing every business worth funding. Founded in 2020, Taktile powers millions of decisions daily for institutions including Mercury, Monzo, Faire, and Pleo. With offices in New York, Berlin, London, São Paulo, and Iași, the company has raised $184M from Growth Equity at Goldman Sachs Alternatives, Index Ventures, Tiger Global, Balderton Capital, and Y Combinator. Learn more at taktile.com.

🇺🇸 United StatesFinancial ServicesStartup
Salary not disclosed