Remotery

GRC Manager

Posted 3 days ago

This is a fully remote position, open to applicants in Greece.

📋 Description

• Take ownership of the complete lifecycle for ISO 27001, SOC 2 Type II, C5, PCI-DSS, and Cyber Essentials certifications, including scoping, evidence management, audit coordination, response management, and remediation tracking.

• Manage the GDPR operational compliance framework, encompassing the DPIA process, governance for LIA and TIA, RoPA maintenance, breach response documentation, and cross-border transfer mechanisms in partnership with the DPO.

• Sustain active compliance frameworks for DORA, NIS2, HIPAA, CCPA/CPRA, and the EU Data Act, ensuring current obligation tracking and client assurance documentation are maintained.

• Oversee end-to-end governance for breach and incident response, including process management, regulatory notification decision support, Art. 33/34 documentation, and the regulatory notification register.

• Foster control owner accountability without direct authority by translating regulatory obligations into business impacts, managing evidence deadlines, and escalating issues when necessary.

• Administer the ISMS evidence library and manage the relationship with the certification body for ISO 27001 and C5.

• Coordinate readiness for SOC 2 Type II, including TSC scoping, evidence collection, auditor engagement, report distribution, and drafting management responses.

• Maintain the RoPA, conduct DPIAs and LIAs, and oversee governance of data subject rights under GDPR.

• Track and implement obligations under DORA, NIS2, HIPAA, CCPA/CPRA, EU Data Act, and Cyber Resilience Act as active regulatory requirements rather than just awareness items.

• Collaborate with Legal on the execution of BAAs and documentation of PHI obligations for healthcare accounts.

• Manage the compliance deliverable tracker, ensuring evidence collection is completed independently without oversight.

• Simplify regulatory obligations into clear business impacts and ensure timely responses from technical and product stakeholders who do not report directly to this role.

• Oversee the complete coordination of client compliance audits, including the preparation of evidence packs, management responses, and remediation of findings.

• Maintain and manage the GRC automation platform, including uploading evidence and monitoring the status of controls.


⛳️ Requirements

• 4 to 8 years of experience in the GRC field, primarily within regulated B2B technology or SaaS environments.

• ISO 27001 Lead Auditor or Lead Implementer certification is mandatory.

• Proven experience managing the entire SOC 2 Type II process: scoping, evidence coordination, auditor management, and crafting management responses, beyond mere participation.

• In-depth understanding of GDPR requirements, including DPIA, RoPA, data subject rights, and cross-border transfer mechanisms (SCCs, BCRs). This is not a legal position, but fluency in regulations is essential.

• Current working knowledge of DORA and NIS2 as active compliance obligations; familiarity with HIPAA BAA coordination and tracking of US state privacy laws (CCPA/CPRA) is highly advantageous.

• Experience with GRC automation platforms at an operational level, rather than just as a user.

• Soft and Behavioral Skills

• Maintains a personal compliance tracker, independently closes loops, and meets deadlines without requiring follow-up.

• Converts regulatory obligations into understandable business impacts and prompts timely responses from technical teams and product stakeholders without formal authority.

• Treats business pushback as the beginning of a process rather than an endpoint, documenting, escalating, and tracking issues to resolution.

• Comfortable being the compliance expert during audits: composed, prepared, and responsible for management responses.

• Functions with minimal supervision in a small, high-output team where operational errors or deadline delays cannot be absorbed by a larger department.


🏝️ Benefits

• Fixed compensation;

• Long-term employment with vacation days;

• Opportunities for professional development (courses, training, etc.);

• Participation in innovative technology products that are making a global impact in the service industry;

• Work alongside skilled and enjoyable colleagues;

• Provision of Apple equipment.

People also viewed

BeOne Medicines1 day ago

Regional Clinical Compliance Manager

IT flagItaly OnlyFull-timeCompliance€59.2k – €74k/year
ApplyView job
TD SYNNEX1 day ago

Compliance Analyst

PL flagPoland OnlyFull-timeCompliance
ApplyView job
TestPros, Inc.1 day ago

Assessment Specialist – Closed Captioning, FCC Compliance

US flagVirginia OnlyPart-timeCompliance$40 – $70/hour
ApplyView job
Wyn1 day ago

Compliance Operations Manager

DE flagGermany OnlyPart-timeCompliance
ApplyView job
Biomatch1 day ago

Director, Quality Systems – Digital Compliance

DE flagGermany OnlyFull-timeCompliance€170k – €200k/year
ApplyView job
Meridian Bioscience Inc.1 day ago

Senior SW Compliance Specialist – Regulatory Affairs, Design Assurance

US flagUnited States OnlyFull-timeCompliance
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers