GRC Engineer
Job Description
<div class="content-intro"><p><strong>Our Global Structure</strong></p> <p><br>Deliveroo is now part of DoorDash, bringing together teams with even greater reach, scale, and ambition. Depending on your role, you may collaborate with teammates, systems, and leaders across DoorDash and Wolt. Together, we’re unlocking new possibilities as one global team.</p></div><h3><strong>About the Team</strong></h3> <p>At Deliveroo we’re striving to build London’s best and most admired Security Engineering organisation as part of our global team based across North America and Europe.</p> <p>Our London based Security Engineering team is looking for a <em>Senior GRC Engineer. </em>You will be a part of our inclusive, collaborative global team responsible.</p> <p>This is a London based position reporting directly to the Security Compliance Manager based in London.</p> <h3><strong>About the Role</strong></h3> <p>We're hiring a <em>Senior GRC Engineer</em><strong> </strong>to help take DoorDash's compliance program from something people run to something the platform runs on its own. You'll take primary ownership of how regulatory and framework change gets tracked, interpreted, and turned into real controls - one part of a broader GRC function that spans audit, policy, and risk. Day to day, that means less time updating spreadsheets and more time writing the automation, integrations, and control logic that let audit evidence collect itself. </p> <p>You'll also lead major external audits from start to finish and help shape the policies and control standards the rest of the program is built on.</p> <p>This is a hands-on role for someone who already has deep audit and assurance experience, wants to spend more time building than briefing and can move a program forward, and change how people work, without needing the title to make it happen.</p> <h3><strong>You’re excited about this opportunity because you will…</strong></h3> <ul> <li>Build the regulatory and framework change-management process that keeps DoorDash ahead of new obligations, instead of reacting to them.</li> <li>Move manual, point-in-time compliance work onto Compliance-as-Code foundations: policy-as-code, automated control testing, and continuous evidence collection wired into CI/CD, so audit readiness holds up between audits, not just during them.</li> <li>Design and run agentic workflows for evidence analysis, control testing, and audit response preparation, with a human in the loop where assurance demands it.</li> <li>Partner directly with engineering and architecture teams to design controls into new systems at build time and translate that technical work into the narratives auditors actually need.</li> <li>Partner with the Security Compliance Manager to shape and mature the global compliance program. </li> <li>Design, implement and validate security controls relevant to DoorDash’s regulatory environment, not just document them.</li> <li>Support development and refinement of security policies, standards, and guidance. </li> <li>Mentor other members of the compliance team and help set the technical bar the rest of the function grows into.</li> <li>Ensure policies are actionable, testable, and aligned to real-world controls. </li> </ul> <h3><strong>We’re excited about you because you have…</strong></h3> <ul> <li>6+ years of experience in security compliance, GRC or technology risk, with a strong track record in high-growth, technology-driven and regulated environments. </li> <li>Hands-on experience building large language models and agent workflows with daily use of