Назад
Company hidden
2 дня назад

Senior GRC Content Engineer (Cybersecurity)

Формат работы
remote (Global)
Тип работы
fulltime
Грейд
senior
Английский
c1
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior GRC Content Engineer (Cybersecurity): Researching, designing, and developing hands-on GRC training rooms, modules, and learning paths covering ISO 27001, EU cyber regulation, risk management, audits, third-party risk, and crisis management with an accent on interactive, scenario-driven learning. Focus on building lab environments, creating realistic compliance exercises, tracking regulatory change, and maintaining technical accuracy across the GRC content portfolio.

Location: Fully remote, work from anywhere, with at least 4 hours of overlap with the UK timezone between 8am and 6pm

Company

hirify.global is an online cybersecurity training platform that provides gamified security exercises and challenges.

What you will do

  • Research, design, and develop GRC training rooms, modules, and learning paths.
  • Create hands-on exercises including risk registers, Statement of Applicability labs, audit simulations, due-diligence questionnaire challenges, regulator-notification drills, and tabletop scenarios.
  • Own technical accuracy across ISO 27001/ISMS, NIS2, DORA, the Cyber Resilience Act, risk management, and audit readiness.
  • Build and maintain lab environments using open-source GRC tools such as Eramba and interactive widgets.
  • Shape the GRC content roadmap using customer requests, demand signals, and competitive research.
  • Track regulatory and framework changes, guide contributors, and collaborate with platform, design, Sales, and Customer Success teams.

Requirements

  • At least 5 years of hands-on GRC or information security experience.
  • Implementation-level experience with ISO/IEC 27001:2022, including scoping, risk assessment and treatment, Statement of Applicability, and internal or certification audits.
  • Working knowledge of NIS2, DORA, and the Cyber Resilience Act, including practical operationalisation.
  • Strong experience with risk management, audit evidence workflows, third-party risk, vendor due diligence, SOC 2 reports, and contractual security requirements.
  • Solid understanding of networks, systems, cloud, and common attack patterns, plus the ability to collaborate with technical content engineers.
  • Excellent written English is required.

Nice to have

  • Instructional design, training delivery, tabletop exercise, or crisis simulation experience.
  • Exposure to SOC 2 Type 2, PCI-DSS, HIPAA, CMMC, Cyber Essentials, or GRC platforms such as Drata, Vanta, OneTrust, ServiceNow GRC, or AuditBoard.
  • Experience using AI tools in GRC workflows, with a clear understanding of where human sign-off is required.
  • Python or Bash scripting, CTF experience, or gamified content design.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, CGRC, ISO/IEC 27001 Lead Implementer or Lead Auditor, or CIPP/E.

Culture & Benefits

  • 100% remote work with flexible working hours.
  • Dedicated work laptop and required accessories.
  • £2,500 personal development and training budget.
  • Paid annual company retreat and branded swag pack.
  • Health insurance where public healthcare is unavailable.
  • Enhanced maternity and paternity benefits, plus 401k or pension support.

Hiring process

  • 30-minute introductory call.
  • Take-home exercise to design a hands-on GRC learning activity.
  • Technical interview with the GRC squad lead followed by a 30-minute final call with a co-founder.
  • Visa sponsorship is not available.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →