Назад
Company hidden
3 дня назад

Security and Compliance Manager (GRC)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
CR
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security and Compliance Manager (GRC): Running Ataccama’s security compliance program, audits, risk management, ISMS, customer assurance, and compliance workflows with an accent on SOC 2, ISO 27001, regulatory frameworks, and enterprise security requirements. Focus on maintaining scalable GRC processes, coordinating remediation across technical teams, reviewing customer security terms, and managing compliance specialists.

Location: Prague, Czech Republic; hybrid work setup

Company

hirify.global develops hirify.global ONE, an agentic data trust platform for data quality, governance, cataloging, lineage, observability, and reference data management.

What you will do

  • Run the security compliance program, audit calendar, control framework, risk management process, and executive reporting.
  • Coordinate SOC 1, SOC 2 Type II, ISO 27001:2022, and customer-driven audits from evidence collection through remediation.
  • Maintain the ISMS policy and standards library against GDPR, NIS2/ZoKB, the EU AI Act, CRA, and customer frameworks.
  • Review security terms, schedules, addenda, RFx requests, and customer security questionnaires with Legal, Sales, and Customer Success.
  • Build scalable GRC workflows, support vendor risk and incident response activities, and help automate compliance operations.
  • Supervise, mentor, allocate work for, and hire compliance specialists and interns.

Requirements

  • 3+ years of experience in information security, GRC, IT audit, or compliance.
  • Hands-on experience with ISO 27001, SOC 2, NIST CSF, and at least one customer-driven framework such as GxP, DORA, FFIEC, NERC CIP, or PCI DSS.
  • Working knowledge of GDPR, NIS2/ZoKB, the EU AI Act, CRA, data privacy, and cybersecurity regulations.
  • Technical fluency with cloud SaaS environments, AWS, Azure, Kubernetes, CI/CD, vulnerabilities, identity and access management, and common security threats.
  • Strong written and verbal English communication skills required. Czech is a plus.
  • Experience supervising or mentoring specialists or interns, including hiring; relevant security or privacy certifications are a plus.

Culture & Benefits

  • Flexible working hours and hybrid work setup.
  • 25 days of vacation, 2 sick days, and the option to request additional flexible time off.
  • Global Family Support Program and mental health support package.
  • Flexible employee benefits platform, including a Multisport card.
  • Conference tickets, online courses, Udemy access, paid AI tools, and company equipment.
  • Long-Term Incentive Program, referral program, company bikes and scooters, and shared cards for Prague Zoo and Botanical Garden.

Hiring process

  • Applications and interview-related activities may be supported by AI-assisted tools, including Metaview and Lever Talent Fit.
  • Final hiring decisions are made by Talent Acquisition Partners and Hiring Managers.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →