GRC Engineer - Platform Team
ABOUT THE ROLE
Taktile empowers financial institutions to transform into truly AI-native organizations. We’re growing rapidly with enterprise customers across banks and insurance companies, and we’re looking for a GRC Engineer.
Operating in highly regulated markets means trust isn't a feature for us, it's the foundation of every customer relationship. As we scale into larger enterprise and fintech accounts, a strong, demonstrable security and compliance posture is what lets us win and keep that trust.
As our GRC Engineer on the Platform Team, you'll own the controls, evidence, and processes that keep Taktile secure, compliant, and continuously audit-ready. You'll be the engineering-minded backbone of our compliance program, turning frameworks like SOC 2, ISO 27001, GDPR, and the EU AI Act into automated, continuously-monitored controls rather than one-off, point-in-time checklists.
This is a cross-functional, high-leverage role. You'll partner with Security, Engineering, Product, and IT to close the gap between policy and control implementation, and with Sales, Legal, Support, and Leadership to make compliance a competitive advantage rather than a bottleneck.
The ideal candidate pairs deep framework knowledge with the technical ability to automate it; fielding a complex customer security questionnaire in the morning and scripting AWS evidence collection in the afternoon.
WHAT YOU'LL DO
- Own continuous compliance end-to-end ; SOC 2, ISO 27001, and customer security reviews, keeping us audit-ready year-round rather than scrambling at renewal time.
- Manage and evolve the compliance roadmap, prioritizing initiatives against business and customer needs; own Vanta end-to-end, including tasks, documentation, integrations, and automated evidence collection.
- Lead quarterly access reviews across all systems in collaboration with IT and Engineering, ensuring findings are tracked through to remediation.
- Run vendor risk reviews and DPIAs for new tools (...