6 дней назад
Lead Engineer - Product GRC (SaaS - Technical Compliance & Automation)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Lead Engineer - Product GRC (SaaS - Technical Compliance & Automation) (SaaS, Technical Compliance & Automation): Building scalable governance, risk, and compliance programs for SaaS products and cloud environments with an accent on automation, control monitoring, and audit readiness. Focus on embedding policy-as-code and compliance checks into the software development lifecycle, automating evidence collection and risk assessments, and validating security controls across product architecture.
Location: Budapest or remote within Hungary; candidates may work from the office, remotely long term, or in a hybrid arrangement.
Company
provides cloud, digital, and AI technologies for customer and employee experience orchestration, serving more than 8,000 organizations in over 100 countries.
What you will do
- Own the SaaS product GRC roadmap across governance, risk, compliance, and regulatory requirements.
- Design scalable compliance workflows, policies, standards, and risk frameworks for cloud and product operations.
- Automate evidence collection, control testing, compliance monitoring, risk assessments, and remediation tracking using GRC and workflow tools.
- Embed compliance checks, policy-as-code, and continuous control monitoring into the software development lifecycle.
- Validate product and cloud architecture, access management, data protection, logging, and other technical controls.
- Act as the technical subject matter expert for audits and certifications, while mentoring GRC and security analysts.
Requirements
- Bachelor’s or Master’s degree in Information Security, Risk Management, Computer Science, or a related field.
- 8–12 years of experience in information security, GRC, or product and technology compliance.
- Hands-on experience operating compliance programs in SaaS, technology, or multi-tenant platform environments.
- Knowledge of security and risk concepts, including access management, data protection, encryption, and technical control validation.
- Experience with GRC platforms and compliance tools, plus strong communication, analytical, and stakeholder management skills.
- Ability to work cross-functionally with security, engineering, product, legal, privacy, and data protection teams.
Nice to have
- CISSP, CISM, CRISC, CISA, ISO 27001 Lead Auditor or Implementer certification.
- AWS Security Specialty, Azure Security Engineer Associate, or CCSP certification.
- Familiarity with Python, DevOps, and DevSecOps practices.
Culture & Benefits
- Flexible office-based, remote, or hybrid work options for Hungary-based employees.
- Professional growth through mentorship, learning programs, leadership development, education support, and language courses.
- Health insurance, life insurance, cafeteria benefits, gym access, and additional time off.
- Paid volunteer time, August Free Fridays, well-being resources, and an open, inclusive community.
- Work on AI-powered technology used by organizations worldwide.
Hiring process
- Application review by Talent Acquisition and the hiring team.
- Zoom interview followed by meetings with the hiring manager and interview team.
- Usually no more than five interviews, followed by final steps and a response from the team.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →