
GRC Manager
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Greece.
• Take ownership of the complete lifecycle for ISO 27001, SOC 2 Type II, C5, PCI-DSS, and Cyber Essentials certifications, including scoping, evidence management, audit coordination, response management, and remediation tracking.
• Manage the GDPR operational compliance framework, encompassing the DPIA process, governance for LIA and TIA, RoPA maintenance, breach response documentation, and cross-border transfer mechanisms in partnership with the DPO.
• Sustain active compliance frameworks for DORA, NIS2, HIPAA, CCPA/CPRA, and the EU Data Act, ensuring current obligation tracking and client assurance documentation are maintained.
• Oversee end-to-end governance for breach and incident response, including process management, regulatory notification decision support, Art. 33/34 documentation, and the regulatory notification register.
• Foster control owner accountability without direct authority by translating regulatory obligations into business impacts, managing evidence deadlines, and escalating issues when necessary.
• Administer the ISMS evidence library and manage the relationship with the certification body for ISO 27001 and C5.
• Coordinate readiness for SOC 2 Type II, including TSC scoping, evidence collection, auditor engagement, report distribution, and drafting management responses.
• Maintain the RoPA, conduct DPIAs and LIAs, and oversee governance of data subject rights under GDPR.
• Track and implement obligations under DORA, NIS2, HIPAA, CCPA/CPRA, EU Data Act, and Cyber Resilience Act as active regulatory requirements rather than just awareness items.
• Collaborate with Legal on the execution of BAAs and documentation of PHI obligations for healthcare accounts.
• Manage the compliance deliverable tracker, ensuring evidence collection is completed independently without oversight.
• Simplify regulatory obligations into clear business impacts and ensure timely responses from technical and product stakeholders who do not report directly to this role.
• Oversee the complete coordination of client compliance audits, including the preparation of evidence packs, management responses, and remediation of findings.
• Maintain and manage the GRC automation platform, including uploading evidence and monitoring the status of controls.
• 4 to 8 years of experience in the GRC field, primarily within regulated B2B technology or SaaS environments.
• ISO 27001 Lead Auditor or Lead Implementer certification is mandatory.
• Proven experience managing the entire SOC 2 Type II process: scoping, evidence coordination, auditor management, and crafting management responses, beyond mere participation.
• In-depth understanding of GDPR requirements, including DPIA, RoPA, data subject rights, and cross-border transfer mechanisms (SCCs, BCRs). This is not a legal position, but fluency in regulations is essential.
• Current working knowledge of DORA and NIS2 as active compliance obligations; familiarity with HIPAA BAA coordination and tracking of US state privacy laws (CCPA/CPRA) is highly advantageous.
• Experience with GRC automation platforms at an operational level, rather than just as a user.
• Soft and Behavioral Skills
• Maintains a personal compliance tracker, independently closes loops, and meets deadlines without requiring follow-up.
• Converts regulatory obligations into understandable business impacts and prompts timely responses from technical teams and product stakeholders without formal authority.
• Treats business pushback as the beginning of a process rather than an endpoint, documenting, escalating, and tracking issues to resolution.
• Comfortable being the compliance expert during audits: composed, prepared, and responsible for management responses.
• Functions with minimal supervision in a small, high-output team where operational errors or deadline delays cannot be absorbed by a larger department.
• Fixed compensation;
• Long-term employment with vacation days;
• Opportunities for professional development (courses, training, etc.);
• Participation in innovative technology products that are making a global impact in the service industry;
• Work alongside skilled and enjoyable colleagues;
• Provision of Apple equipment.
BeOne Medicines
TestPros, Inc.
Get handpicked remote jobs straight to your inbox weekly.