
GRC Program Manager
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in Germany.
β’ Oversee the complete execution and accountability of GRC deliverables, timelines, dependencies, and compliance milestones.
β’ Direct third-party audits such as SOC 2 Type II and PCI DSS from initial scoping to final completion.
β’ Manage the collection of evidence, provide guidance to control owners, and spearhead remediation initiatives.
β’ Develop and enhance compliance frameworks to meet evolving global standards, including GDPR.
β’ Perform IT, security, and third-party risk assessments.
β’ Maintain the risk register and monitor risk treatment plans and corrective actions until resolution.
β’ Improve GRC operations utilizing GRC platforms and automation tools.
β’ Collaborate with Engineering and Product teams to integrate security controls, privacy-by-design, and cloud best practices into the development lifecycle and API-first platform.
β’ Assist enterprise sales by responding to security questionnaires, conducting third-party risk reviews, and demonstrating compliance.
β’ Convert technical and regulatory findings into risk dashboards, Key Risk Indicators (KRIs), and updates for leadership.
β’ Proven experience in leading cross-functional projects, aligning technical and business stakeholders, and ensuring team accountability.
β’ Hands-on expertise in spearheading significant compliance audits such as SOC 2, PCI DSS, or ISO 27001 from inception to completion.
β’ Previous experience in SaaS, Fintech, or cloud-native technology environments is highly desirable.
β’ A strong sense of curiosity and a quick-learning ability towards modern cloud, API, and SaaS architectures are essential for candidates transitioning from other sectors.
β’ Demonstrated experience in GRC and security processes, including risk assessments, internal audits, policy formulation, and management of corrective actions.
β’ Solid understanding of SOC 2, PCI DSS, ISO 27001, GDPR, and NIST CSF/RMF.
β’ Capability to translate regulatory requirements into actionable operational steps.
β’ Effective communication skills with both technical experts and business executives.
β’ Proficiency in English for business communication is required.
β’ Basic technical knowledge of scripting, APIs, or system logs/configurations is advantageous.
β’ Familiarity with GRC automation tools such as Vanta, Drata, ServiceNow IRM, or LogicGate is a plus.
β’ Relevant certifications such as CRISC, CISA, CISM, CISSP, CSSP, or ISO/IEC 27001 Lead Auditor are beneficial.
β’ Proficiency in the German language is an added advantage.
β’ Play a mission-critical role supporting global live entertainment brands.
β’ Continuous investment in personnel, products, and long-term vision.
β’ Collaborate with a diverse team of over 160 individuals, including leaders from Google, Slack, and Salesforce.
β’ Join a merit-driven global team operating across six offices.
β’ Experience daily learning, shared achievements, and collective growth.
β’ Opportunity to engage with recognized technology leaders and award-winning professionals.
β’ Benefit from an inclusive workplace dedicated to empowerment, contribution, growth, and thriving.
β’ Work with a profitable, VC-backed company that has secured over $65 million in funding.
Le'Fant LLC
Astreya
Maleda Tech
Del Oro Consulting, Inc.
Get handpicked remote jobs straight to your inbox weekly.