10 дней назад
GRC Specialist (Cybersecurity Compliance)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
GRC Specialist (Cybersecurity Compliance): Building and maintaining compliance frameworks and audit content for a security compliance automation platform with an accent on ISO 27001, TISAX, SOC 2, GDPR, and related standards. Focus on leading customer audits, translating compliance gaps into product work, and improving policies, evidence templates, and compliance playbooks.
Location: Remote from the UK, Germany, Austria, Poland or Serbia
Company
automates security compliance for modern companies, supporting ISO 27001, GDPR, TISAX, SOC 2, and related frameworks through its platform.
What you will do
- Build and maintain compliance frameworks in the platform, including ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 42001, and C5.
- Lead customer internal audits end to end, from kickoff through final reporting, while managing several audits and schedules in parallel.
- Implement ISO 27001 and adjacent frameworks for customers and close framework gaps using auditor feedback.
- Create and maintain compliance content, including policies, automated checks, evidence templates, enablement playbooks, and security awareness training.
- Partner with product, engineering, customer success, and founders to translate compliance gaps into structured product improvements.
- Develop relationships with certification partners and train auditors to use the platform during customer audits.
Requirements
- English: fluent proficiency required.
- 3+ years of hands-on information security and GRC experience.
- At least one successful ISO 27001 certification project led as an implementer or auditor at a startup or mid-market company.
- Experience running at least two internal audits and using a GRC platform such as or a similar tool.
- Strong expertise in at least one framework beyond ISO 27001, such as TISAX, SOC 2, GDPR, or NIS2.
- Strong project management, written communication, ownership, and prioritization skills, plus a technical bachelor's degree or equivalent hands-on experience.
Nice to have
- Mentoring or coaching experience in compliance, audit, or GRC.
- Experience working in a startup environment.
- PECB ISO 27001 Lead Auditor certification or an equivalent qualification.
Culture & Benefits
- 100% remote work with a virtual office and access to coworking spaces.
- Local salaries at or above market rates, plus an equity package.
- €1,000 annual personal development budget and access to mentors.
- 26 days of holiday plus local public holidays and comprehensive health coverage.
- Home office budget, latest technical equipment, annual retreat, and company-wide events.
Hiring process
- Screening call with the Talent team.
- Take-home assessment followed by a 1.5-hour assessment review and interview with the CS Lead and CEO.
- Final 45-minute founder interview with the CTO and CISO.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
10 дней назад
BS Information Security Specialist (GRC Analyst)
12 дней назад
Security Program Manager (AI)
11 дней назад
Security Assurance Analyst (Cybersecurity)
45 000 - 55 000GBP
11 дней назад
Lead Security Analyst - GRC (Cybersecurity)
172 500 - 215 625$
12 дней назад
DPO & Compliance Officer (Cybersecurity)
12 дней назад