This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As a Staff Trust, Risk, and Compliance Engineer you will operate at the center of Rapid7’s Information Security organization, and have an opportunity to architect security and compliance systems, improve operations for a public company security program, and elevate how risk and compliance enable the business at scale. In this role you will shape the long-term direction of Rapid7’s global compliance and risk programs. You’ll ensure our Information Security program is not only compliant, but intentionally designed, deeply integrated, and resilient — capable of evolving alongside Rapid7’s technology, products, and growth.
Job Responsibility:
Design and drive end-to-end Trust, Risk, and Compliance programs across multiple complex regulatory and compliance regimes
Architect and evolve Rapid7’s TRC technology ecosystem, connecting applicability, assessment, implementation, operation, and meaningful reporting
Improve TRC maturity at scale, reducing uncertainty and friction while strengthening risk management outcomes
Operate autonomously across most situations, managing timelines, dependencies, and escalations without being chased
Run multiple complex initiatives in parallel with broad, cross-functional scope
Partner with senior leaders across Information Security, Engineering, Platform, IT, Enterprise Applications, and the business to shape direction and outcomes
Apply deep engineering judgment to navigate and integrate Rapid7’s technical stack, including AWS, Okta, commercial GRC platforms, Tableau, Terraform and Rapid7 products (such as InsightCloudSec, Surface Command, and InsightVM), and other security tooling
Leverage APIs, automation, scripting (e.g., Python), data, and AI-driven approaches to modernize how TRC operates
Integrate with productivity and collaboration tools (e.g., Slack, Google Workspace, Atlassian Portfolio) to deliver a seamless Trust, Risk, and Compliance experience
Influence how Rapid7 employees (“Moose”) think about security and compliance — shifting left, embedding controls early, and avoiding reactive cleanup
Resolve ambiguous, cross-functional problems repeatedly, operating with manager-level judgment and systems-level thinking
Requirements:
Extensive experience (typically 10+ years) building bridge-layers between complex business requirements and technical operations
Deep understanding of managing complex lifecycles—whether in Trust, Risk, and Compliance (NIST, ISO) or other highly regulated, high-scale technical fields
A proven track record of designing systems that don't just "work" but scale
A design-thinking–led microservices architecture that allows the TRC stack to adapt and evolve organically
Strong engineering mindset applied to governance, risk, and compliance challenges