Senior GRC Engineer
AI in this role
Lead governance, risk, and compliance engineering by building automated control evidence pipelines and managing security compliance systems.
At Tandem Health we’re reimagining healthcare by putting clinicians first. Our platform - designed by clinicians, for clinicians - is built on deep insight into real-world pain points, with intuitive medical notes and workflows that truly support patient care.
We’re a fast-scaling health-tech company backed by top investors and expanding globally. We move fast, stay curious, and believe building something that matters starts with an extraordinary team. If you're passionate about impact and innovation, we'd love to meet you!
About the role
You will lead the engineering behind our governance, risk and compliance (GRC) systems. You will turn security requirements into production controls, evidence pipelines and tests that show whether those controls operate as designed.
The Senior GRC Engineer works across security, software engineering and compliance. On one day you might build a pipeline that collects cloud configuration evidence or write a test that detects a failed control. On another day, you might trace a system change to the policies and requirements it affects.
You will work with the security, compliance, and legal teams to define the most pressing problems and deliver production solutions without detailed technical direction. And, more broadly, you will take initiative to close gaps that you identify in the course of your work.
What you will do
Build production systems that collect, validate and preserve technical control evidence.
Automate shared security controls when a central implementation is the right solution.
Write tests that show whether controls operate as designed and continue to work over time.
Connect requirements, controls, implementations, tests, evidence, policies and procedures.
Detect missing, stale or incomplete evidence. Route failures to a named owner and keep a traceable record.
Build workflows that identify drift between approved policies and technical implementations.
Prepare reproducible evidence packages for the Compliance team.
Join audits as a technical subject matter expert.
Answer internal questions for go-to-market teams about our compliance and security posture.
Help the Compliance and Legal teams assess how new requirements affect our security controls and systems.
Build, deploy and operate approved GRC automation in our production environment.
Keep the systems maintainable through version control, tests, monitoring and clear operating documentation.
What success looks like
Within your first few months, the first prioritised evidence pipelines and control tests should operate in production. The systems should show where evidence came from, whether it is current and when collection fails. The Compliance team should be able to reproduce selected for key requirements evidence without repeating the original manual work.
Over your first year, the Compliance team should receive complete and traceable technical evidence by the agreed dates. Important evidence and control failures should be visible before an audit. Manual collection and evidence rework should decrease as automation covers more of the highest-priority controls.
What you bring
You are a senior engineer who is comfortable owning a defined problem from design through production. You can work independently, explain your decisions and ask for help when a dependency or company-level decision blocks progress.
You can:
Build and operate production software, automation or data pipelines.
Work with application programming interfaces, cloud services and structured data from several systems.
Translate security or compliance requirements into technical controls and testable conditions.
Design evidence records with clear provenance, scope, collection time and retention requirements.
Build monitoring that detects failed collection, stale evidence and control failure.
Apply software engineering practices to compliance work, including testing, version control and code review.
Explain technical controls and evidence to engineers, compliance colleagues and auditors.
Make sound engineering decisions when the implementation path is not prescribed.
Balance automation with access control, data minimisation and operational safety.
We care more about demonstrated capability than a particular degree, certification or GRC platform.
Bonus points
Experience with ISO 27001, C5, SOC 2 and other security or quality management assessments.
Experience with controls as code, policy as code or continuous control monitoring.
Experience in healthcare, another regulated environment or a high-growth technology company.
Experience with infrastructure as code, cloud security, identity systems or continuous integration and delivery pipelines.
Experience integrating compliance platforms or integrated management systems with technical data sources.
Experience building evidence systems with access, retention and auditability requirements.
Experience using AI to support control mapping, evidence review or policy analysis with human approval and traceable outputs.
Location
We work best when we spend time together. You will work primarily from our headquarters in central Stockholm.
How to apply
We review applications continuously. Please apply with your CV in English.
Because Tandem handles sensitive patient data, we conduct a background check before hiring.
Benefits
Competitive salary and company stock options.
30 days of paid holiday each year.
5,000 SEK wellness allowance, plus 6,000 SEK each year for other health-related initiatives.
Parental leave top-up for new parents.
Private medical insurance.
Mental health support through Mindler.
Pension programme.
Regular social and team activities, including off-sites and seasonal events.
We review our benefits regularly and may change them from time to time.
At Tandem, we move fast, think big, and take ownership. We're a high-performing, diverse team with a shared drive to change the future of healthcare - and we’re just getting started.
Our culture is built on action, ambition, and learning. You'll be trusted to take the lead, challenge yourself, and make an impact from day one. We believe real growth happens when you're stretched, supported, and surrounded by smart, passionate teammates who want to win together.
Even though we’re spread across countries, we come together often in Sweden for team meetings, social events, and offsites - blending global reach with real human connection.
We hire for talent, potential, and attitude - valuing different backgrounds and fresh perspectives. Great ideas come from everywhere, and we’re building a team that reflects the world we want to change.
Tandem handles sensitive patient data and will conduct a background check before hiring any candidate.
How we rate this
Senior GRC Engineer at Tandem Health rates 0 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- Tell me about a project where grc was part of your work. What did you do?
- Tell me about a project where compliance was part of your work. What did you do?
- Tell me about a project where automation was part of your work. What did you do?
- Tell me about a project where audit was part of your work. What did you do?
- Tell me about a project where security controls was part of your work. What did you do?
Adapt your resume
- List these exact terms on your resume: Grc, Compliance, Automation, Audit, and Security Controls. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new AI jobs by email
One email a week with the new AI jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Software Engineering roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step