The role positioning felt misleading. The title and job description framed this as a GRC/Control function, but during the interview process it became clear the team was actually looking for a much more engineering-oriented profile focused on automation and technical implementation.
There seemed to be a clear mismatch between the technical expectations of the role and the compensation band typically associated with a control/risk function. In practice, many of the responsibilities discussed aligned more closely with security engineering or platform/security automation work, while still being positioned and compensated as a control function role.
The interview process also gave the impression that expectations around the role were not fully aligned internally, particularly regarding how technical and engineering-focused the position actually was. Conversations around automation and implementation often lacked clarity despite being central to the role.
I would strongly suggest making the technical expectations and engineering overlap much more explicit in the title and job description, as this would help candidates better assess fit before entering the process.