2 дня назад
Senior GRC Content Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior GRC Content Engineer (Cybersecurity): Researching, designing, and developing hands-on GRC training rooms, modules, and learning paths covering ISO 27001, EU cyber regulation, risk management, audits, third-party risk, and crisis management with an accent on interactive, scenario-driven learning. Focus on building lab environments, creating realistic compliance exercises, tracking regulatory change, and maintaining technical accuracy across the GRC content portfolio.
Location: Fully remote, work from anywhere, with at least 4 hours of overlap with the UK timezone between 8am and 6pm
Company
is an online cybersecurity training platform that provides gamified security exercises and challenges.
What you will do
- Research, design, and develop GRC training rooms, modules, and learning paths.
- Create hands-on exercises including risk registers, Statement of Applicability labs, audit simulations, due-diligence questionnaire challenges, regulator-notification drills, and tabletop scenarios.
- Own technical accuracy across ISO 27001/ISMS, NIS2, DORA, the Cyber Resilience Act, risk management, and audit readiness.
- Build and maintain lab environments using open-source GRC tools such as Eramba and interactive widgets.
- Shape the GRC content roadmap using customer requests, demand signals, and competitive research.
- Track regulatory and framework changes, guide contributors, and collaborate with platform, design, Sales, and Customer Success teams.
Requirements
- At least 5 years of hands-on GRC or information security experience.
- Implementation-level experience with ISO/IEC 27001:2022, including scoping, risk assessment and treatment, Statement of Applicability, and internal or certification audits.
- Working knowledge of NIS2, DORA, and the Cyber Resilience Act, including practical operationalisation.
- Strong experience with risk management, audit evidence workflows, third-party risk, vendor due diligence, SOC 2 reports, and contractual security requirements.
- Solid understanding of networks, systems, cloud, and common attack patterns, plus the ability to collaborate with technical content engineers.
- Excellent written English is required.
Nice to have
- Instructional design, training delivery, tabletop exercise, or crisis simulation experience.
- Exposure to SOC 2 Type 2, PCI-DSS, HIPAA, CMMC, Cyber Essentials, or GRC platforms such as Drata, Vanta, OneTrust, ServiceNow GRC, or AuditBoard.
- Experience using AI tools in GRC workflows, with a clear understanding of where human sign-off is required.
- Python or Bash scripting, CTF experience, or gamified content design.
- Relevant certifications such as CISSP, CISM, CISA, CRISC, CGRC, ISO/IEC 27001 Lead Implementer or Lead Auditor, or CIPP/E.
Culture & Benefits
- 100% remote work with flexible working hours.
- Dedicated work laptop and required accessories.
- £2,500 personal development and training budget.
- Paid annual company retreat and branded swag pack.
- Health insurance where public healthcare is unavailable.
- Enhanced maternity and paternity benefits, plus 401k or pension support.
Hiring process
- 30-minute introductory call.
- Take-home exercise to design a hands-on GRC learning activity.
- Technical interview with the GRC squad lead followed by a 30-minute final call with a co-founder.
- Visa sponsorship is not available.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →