At Tandem Health we’re reimagining healthcare by putting clinicians first. Our platform - designed by clinicians, for clinicians - is built on deep insight into real-world pain points, with intuitive medical notes and workflows that truly support patient care.
We’re a fast-scaling health-tech company backed by top investors and expanding globally. We move fast, stay curious, and believe building something that matters starts with an extraordinary team. If you're passionate about impact and innovation, we'd love to meet you!
You will lead the engineering behind our governance, risk and compliance (GRC) systems. You will turn security requirements into production controls, evidence pipelines and tests that show whether those controls operate as designed.
The Senior GRC Engineer works across security, software engineering and compliance. On one day you might build a pipeline that collects cloud configuration evidence or write a test that detects a failed control. On another day, you might trace a system change to the policies and requirements it affects.
You will work with the security, compliance, and legal teams to define the most pressing problems and deliver production solutions without detailed technical direction. And, more broadly, you will take initiative to close gaps that you identify in the course of your work.
Build production systems that collect, validate and preserve technical control evidence.
Automate shared security controls when a central implementation is the right solution.
Write tests that show whether controls operate as designed and continue to work over time.
Connect requirements, controls, implementations, tests, evidence, policies and procedures.
Detect missing, stale or incomplete evidence. Route failures to a named owner and keep a traceable record.
Build workflows that identify drift between approved policies and technical implementations.
Prepare reproducible evidence packages for the Compliance team.
Join audits as a technical subject matter expert.
Answer internal questions for go-to-market teams about our compliance and security posture.
Help the Compliance and Legal teams assess how new requirements affect our security controls and systems.
Build, deploy and operate approved GRC automation in our production environment.
Keep the systems maintainable through version control, tests, monitoring and clear operating documentation.
Within your first few months, the first prioritised evidence pipelines and control tests should operate in production. The systems should show where evidence came from, whether it is current and when collection fails. The Compliance team should be able to reproduce selected for key requirements evidence without repeating the original manual work.
Over your first year, the Compliance team should receive complete and traceable technical evidence by the agreed dates. Important evidence and control failures should be visible before an audit. Manual collection and evidence rework should decrease as automation covers more of the highest-priority controls.
You are a senior engineer who is comfortable owning a defined problem from design through production. You can work independently, explain your decisions and ask for help when a dependency or company-level decision blocks progress.
You can:
Build and operate production software, automation or data pipelines.
Work with application programming interfaces, cloud services and structured data from several systems.
Translate security or compliance requirements into technical controls and testable conditions.
Design evidence records with clear provenance, scope, collection time and retention requirements.
Build monitoring that detects failed collection, stale evidence and control failure.
Apply software engineering practices to compliance work, including testing, version control and code review.
Explain technical controls and evidence to engineers, compliance colleagues and auditors.
Make sound engineering decisions when the implementation path is not prescribed.
Balance automation with access control, data minimisation and operational safety.
We care more about demonstrated capability than a particular degree, certification or GRC platform.
Experience with ISO 27001, C5, SOC 2 and other security or quality management assessments.
Experience with controls as code, policy as code or continuous control monitoring.
Experience in healthcare, another regulated environment or a high-growth technology company.
Experience with infrastructure as code, cloud security, identity systems or continuous integration and delivery pipelines.
Experience integrating compliance platforms or integrated management systems with technical data sources.
Experience building evidence systems with access, retention and auditability requirements.
Experience using AI to support control mapping, evidence review or policy analysis with human approval and traceable outputs.
We work best when we spend time together. You will work primarily from our headquarters in central Stockholm.
We review applications continuously. Please apply with your CV in English.
Because Tandem handles sensitive patient data, we conduct a background check before hiring.
Competitive salary and company stock options.
30 days of paid holiday each year.
5,000 SEK wellness allowance, plus 6,000 SEK each year for other health-related initiatives.
Parental leave top-up for new parents.
Private medical insurance.
Mental health support through Mindler.
Pension programme.
Regular social and team activities, including off-sites and seasonal events.
We review our benefits regularly and may change them from time to time.
At Tandem, we move fast, think big, and take ownership. We're a high-performing, diverse team with a shared drive to change the future of healthcare - and we’re just getting started.
Our culture is built on action, ambition, and learning. You'll be trusted to take the lead, challenge yourself, and make an impact from day one. We believe real growth happens when you're stretched, supported, and surrounded by smart, passionate teammates who want to win together.
Even though we’re spread across countries, we come together often in Sweden for team meetings, social events, and offsites - blending global reach with real human connection.
We hire for talent, potential, and attitude - valuing different backgrounds and fresh perspectives. Great ideas come from everywhere, and we’re building a team that reflects the world we want to change.
Tandem handles sensitive patient data and will conduct a background check before hiring any candidate.