Logo for Velera

GRC Engineer - REMOTE

Role overview

Qualifications

  • Bachelors Degree in Computer Science, Cybersecurity, Management Information Systems (MIS), or equivalent experience
  • Exceptional background in database administration with deep knowledge of technical database compliance rules (PCI-DSS)
  • 10 + years as subject matter expert formerly in DBA roles and/or GRC Engineer
  • Strong program management skills in large complex organizations

Responsibilities

  • Embed security checks directly into development workflows and Infrastructure-as-Code (IaC)
  • Design, write, and maintain executable policies using Azure Policy and Open Policy Agent (OPA)
  • Build and maintain automated pipelines that continuously audit cloud environments
  • Develop scripts to automatically gather evidence for SOC, NIST, and PCI audits

About the company

Velera logo

Velera

Financial Services

Born in 2020, Velera Foundation is a non-profit 501c(3) R&D foundation dedicated to researching, publishing, and developing technologies that allow information to move efficiently, adaptively, and meaningfully. Our solutions empower people, organizations, and communities to interact intelligently, collaboratively, and creatively. Velera bridges advanced research and real-world technology, designing systems that align with how humans naturally process, share, and realize information.

Company details

IndustryFinancial Services
Company size2 - 10

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Join the People Helping People

Velera is the nation’s premier payments credit union service organization (CUSO) and an integrated fintech solutions provider. The company serves more than 4,000 financial institutions throughout North America, operating with velocity to help our clients keep pace with the rapid momentum of change and fuel growth in the new era of financial services. Our purpose: We accelerate partners’ success through innovative financial technology solutions and inspired service.

The Opportunity

We are seeking a GRC Engineer to lead the transformation of our Technology Compliance program. In this role, you will replace manual audit testing with Compliance-as-Code (CaC), Policy-as-Code (PaC), and Continuous Control Monitoring (CCM) by embedding controls into the CI/CD pipelines to ensure systems remain continuously secure and compliant in our Azure cloud ecosystem. Leveraging your expertise, you will focus heavily on automating technical controls for data persistence layers, ensuring our infrastructure remains continuously compliant with SOC 1/2, NIST and PCI-DSS throughout a complex ecosystem.

A Day in the Life

  • Compliance-as-Code: Embed security checks directly into development workflows and Infrastructure-as-Code (IaC) to block non-compliant deployments before they reach production.
  • Policy-as-Code (PaC) Engineering: Design, write, and maintain executable policies using Azure Policy, Open Policy Agent (OPA), or Rego to prevent non-compliant infrastructure deployments.
  • Continuous Control Monitoring (CCM): Build and maintain automated pipelines that continuously audit cloud environments, specialized database clusters, and storage systems against compliance baselines.
  • Database & Data Compliance: Design automated controls for database security, focusing on data-at-rest encryption, automated key rotation, data masking, database activity monitoring (DAM), and secure access controls (IAM/PIM).
  • CI/CD Security Integration: Inject automated compliance and configuration checks directly into our DevOps deployment pipelines to catch configuration drifts before code reaches production.
  • Audit Evidence Automation: Develop Python, PowerShell, or Go scripts to automatically gather, aggregate, and store point-in-time evidence for SOC, NIST, and PCI audits.
  • Remediation Automation: Solution to automatically remediate any potential control failures including Attestations
  • Risk Assessments: Identify, document, and quantify technical security risks, threats, and vulnerabilities, translating them into business-impact metrics for leadership.
  • Perform all other duties as assigned.

Qualifications

  • Bachelors Degree in Computer Science, Cybersecurity, Management Information Systems (MIS), or equivalent experience
  • Exceptional background in database administration with deep knowledge of technical database compliance rules (PCI-DSS) requirements and knowledgable in Security GRC practices.
  • 10 + years as subject matter expert formerly in DBA roles and/or GRC Engineer
  • Strong program management skills in large complex organizations.
  • Propose solutions and implement effectively with minimal oversight.
  • Capable of building strong relationships with Security, Engineering, Product and other key stakeholders.
  • Ability to demonstrate GRC Engineering practices and use of AI solutions.
  • Previous GRC tooling for control automation experience highly desired.

  

About Velera

At Velera, inclusion isn’t an initiative – it’s how we work. Guided by a people‑helping‑people philosophy, we cultivate a culture where every employee feels valued, respected and empowered to do their best work. We’re committed to building a diverse workforce and fostering meaningful connection across our teams. Through a remote‑first, flexible environment, we prioritize psychological safety, wellbeing and belonging so individuals and teams can collaborate to thrive. Together, we’re shaping a new era of secure, innovative solutions for the clients and communities we serve. Learn more about what it’s like to work at Velera.

Pay Equity

$110,100.00 - $143,100.00

Actual Pay will be adjusted based on experience and other job-related factors permitted by law.

Great Work/Life Benefits!

  • Competitive wages

  • Medical with telemedicine

  • Dental and Vision

  • Basic and Optional Life Insurance

  • Paid Time Off (PTO)

  • Maternity, Parental, Family Care

  • Community Volunteer Time Off

  • 12 Paid Holidays

  • Company Paid Disability Insurance

  • 401k (with employer match)

  • Health Savings Accounts (HSA) with company provided contributions

  • Flexible Spending Accounts (FSA)

  • Supplemental Insurance

  • Mental Health and Well-being: Employee Assistance Program (EAP)

  • Tuition Reimbursement

  • Wellness program

  • Benefits are subject to generally applicable eligibility, waiting period, contribution, and other requirements and conditions

Velera is an Equal Opportunity Employer. We consider applicants without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, or membership in any other group protected by federal, state or local law.

Velera is an Equal Opportunity Employer that complies with the laws and regulations set forth in the following "EEO is the Law" Poster. Velera will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the legal duty to furnish information.

Velera is an E-Verify Employer. Review the E-Verify Poster here.  For information regarding your Right To Work, please click here.

This role is currently not eligible for sponsorship.

As an ongoing commitment to reasonably accommodate individuals with disabilities please contact a recruiter at recruiters@velera.com for assistance.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Velera

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.