About the job
About Us:
At Ouro, we are a pioneering force in the global financial services and technology landscape, committed to delivering innovative solutions that empower consumers around the world. Our extensive portfolio includes prepaid, debit, cross-border payments, and loyalty solutions tailored for both consumers and enterprise partners.
Our flagship service, Netspend, offers prepaid and debit account solutions that seamlessly connect customers to secure, convenient access to global payment networks, enabling them to manage their finances and make everyday purchases effortlessly. With an expansive retail network across the U. S., customers can easily purchase and reload Netspend products at over 130,000 locations nationwide.
Since our inception in 1999 by industry visionaries, Ouro has processed billions of dollars in transaction volume while serving millions of satisfied customers globally. Our headquarters is located in Austin, Texas, with a dedicated team of employees worldwide.
Job Overview:
We are seeking a highly skilled Governance, Risk, and Compliance (GRC) Engineer to enhance our GRC initiatives. This individual contributor role combines traditional GRC responsibilities with hands-on technical expertise, ensuring that risk assessments, architectural reviews, and control validations align with real-world engineering practices.
The ideal candidate will possess extensive experience in cloud and application architectures, a strong understanding of security controls and frameworks, and the ability to translate business requirements into effective risk mitigation strategies. This role will closely collaborate with teams in Product Engineering, Cloud/Infrastructure, Security Engineering, and Audit/Compliance.
Key Responsibilities:
Lead technical risk assessments for applications, cloud services, third-party integrations, and internal systems.
Evaluate control effectiveness against established frameworks such as NIST CSF, ISO 27001, SOC 2, PCI-DSS, and internal policies.
Develop and maintain comprehensive risk registers and mitigation plans.
Validate logging coverage, access controls, encryption configurations, and identity/security controls across cloud and infrastructure environments.
Policy and Compliance Engineering:
Contribute to the formulation and upkeep of security policies, technical standards, and architectural principles.
