6 дней назад
GRC Specialist (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
GRC Specialist (Cybersecurity): Building and maintaining compliance frameworks and audit content for the Secfix platform, with an accent on ISO 27001 implementation, internal audits, and customer compliance delivery. Focus on managing multiple audits, translating compliance gaps into product improvements, and creating precise policies, evidence templates, and enablement materials.
Location: Remote from the UK, Germany, Austria, Poland or Serbia; EMEA remote
Company
automates security compliance for companies working with frameworks including ISO 27001, GDPR, TISAX and SOC 2.
What you will do
- Build and maintain compliance frameworks in the platform, including ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 42001 and C5.
- Lead customer internal audits from kickoff through final reporting and keep multiple audits on schedule.
- Implement ISO 27001 and related frameworks for customers end to end.
- Create and maintain policies, automated checks, evidence templates, compliance playbooks and security awareness training.
- Translate compliance gaps and auditor feedback into improvements for product, engineering and team practices.
- Collaborate with customer success, product, founders and certification partners, including training auditors on the platform.
Requirements
- German at C1/C2 level and fluent English are required.
- 3+ years of hands-on information security and GRC experience.
- At least one successful ISO 27001 certification project led as an implementer or auditor in a startup or mid-market company.
- Experience running at least two internal audits and using or a similar GRC platform.
- Deep experience with at least one framework beyond ISO 27001, such as TISAX, SOC 2, GDPR or NIS2.
- Strong project management, written communication, ownership and prioritization skills, plus a technical bachelor's degree or equivalent hands-on experience.
Nice to have
- Experience mentoring or coaching colleagues in compliance, audit or GRC.
- Startup experience.
- PECB ISO 27001 Lead Auditor certification or equivalent.
Culture & Benefits
- 100% remote work with a virtual office in Gather.
- Local salaries at or above market rates, plus an equity package.
- €1,000 annual personal development budget, home office budget and access to co-working spaces.
- 26 days of holiday plus local public holidays and comprehensive health coverage.
- Annual retreats, company events and the latest technology equipment.
Hiring process
- Screening call with the Talent team.
- Take-home assessment followed by a 1.5-hour assessment review and interview with the CS Lead and CEO.
- 45-minute final founder interview with the Co-Founders, CTO and CISO.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 дней назад
Senior Information Security Specialist (Cybersecurity)
120 000 - 160 000$
6 дней назад
BS Information Security Specialist (GRC Analyst)
7 дней назад
Security Assurance Analyst (Cybersecurity)
45 000 - 55 000GBP
8 дней назад
DPO & Compliance Officer (Cybersecurity)
12 дней назад
Head of Information Security (Cybersecurity)
12 дней назад