Назад
Company hidden
17 часов назад

Information Security Governance Specialist (SaaS)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Information Security Governance Specialist (SaaS): Managing compliance programs and customer security assurance for a brand management platform with an accent on automation and AI integration. Focus on transforming manual GRC processes into continuous monitoring systems using LLMs and GRC platforms.

Location: Hybrid (London Area), requires office attendance once per week

Company

hirify.global is a brand management platform that helps leading brands maintain trust and consistency.

What you will do

  • Manage customer security assurance, including questionnaires, due diligence, and audit inquiries.
  • Drive operations and continuous improvement for compliance programs including ISO 27001, SOC 2, and TISAX.
  • Act as the subject matter expert during security audits to ensure the control environment remains effective.
  • Implement automation and AI into the Vanta-based GRC program for continuous evidence collection and control monitoring.
  • Scale vendor risk management through automated security assessments and targeted human reviews.
  • Enhance the security awareness program to build practical knowledge across the organization.

Requirements

  • 5+ years of experience in information security governance, GRC, or technology risk within a SaaS or cloud environment.
  • Proven expertise as a subject matter expert in SOC 2 and/or ISO 27001 audits.
  • Hands-on experience with modern GRC platforms such as Vanta or Conveyor.
  • Must be based in the London area and able to work in a hybrid format (office once per week).
  • English: Fluent proficiency required.

Nice to have

  • Experience with additional frameworks such as TISAX or Microsoft SSPA.
  • Relevant certifications like CISA, CISM, CISSP, or CIPP.
  • German language skills.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →