GRC Specialist

Posted Sep 16

This is a fully remote position, open to applicants in United Kingdom, +4 more countries.

📋 Description

• Develop and uphold compliance frameworks within the Secfix platform, encompassing ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 42001, and C5.

• Manage customer internal audits from initiation to final reporting.

• Oversee multiple audits simultaneously while ensuring they remain on schedule.

• Execute ISO 27001 and related frameworks from start to finish for clients.

• Maintain the quality of compliance materials in the platform, including policies, automated checks, evidence templates, compliance enablement playbooks, and security awareness training.

• Address framework deficiencies and incorporate auditor feedback into team practices and platform enhancements.

• Collaborate with product and engineering teams to convert compliance gaps into organized product tasks.

• Work alongside Customer Success, Product, and Founders to harmonize compliance, customer, and roadmap priorities.

• Cultivate relationships with certification partners.

• Provide training for auditors on the Secfix platform for client audits.

• Engage in the screening, take-home assessment, assessment review, and founder interview phases.


⛳️ Requirements

• Proficient in English.

• Bachelor's degree in computer science, software engineering, or a related technical discipline, or equivalent practical technical experience.

• Over 3 years of practical experience in information security and GRC.

• Successfully led at least one ISO 27001 certification project as an implementer and/or auditor within a startup or mid-market organization.

• Conducted a minimum of two internal audits.

• Practical experience with a GRC platform such as Secfix or a comparable system.

• Extensive knowledge in at least one compliance framework beyond ISO 27001, such as TISAX, SOC 2, GDPR, NIS2, or similar.

• Strong project management capabilities.

• Exceptional written communication skills with the ability to create clear, precise compliance content.

• Capacity to operate as an individual contributor with a strong sense of ownership.

• Experience in mentoring or coaching peers in a compliance, audit, or GRC setting is a plus.

• Experience in a startup environment is advantageous.

• PECB ISO 27001 Lead Auditor certification or a direct equivalent is a bonus.

• Must reside in the UK, Germany, Austria, Poland, or Serbia.

• Must meet visa sponsorship criteria for the respective country of residence.


🏝️ Benefits

• Fully remote work with a virtual office in Gather.

• Competitive local salaries at or above market benchmarks.

• Generous equity offerings.

• Direct access to top-tier mentors.

• €1,000 annual budget for personal development.

• Budget for home office setup.

• Access to co-working facilities.

• 26 days of vacation plus local public holidays.

• Comprehensive health insurance coverage.

• Annual company retreat.

• Company-wide events.

• Provision of the latest technology equipment, including MacBook, monitors, and headphones.

People also viewed

LabConnect1 day ago

Head of IT Governance, Risk, Compliance

US flagTennessee OnlyFull-timeCompliance
ApplyView job
Ripple Effect1 day ago

Compliance Analyst

US flagMaryland OnlyFull-timeCompliance$85.3k – $98.1k/year
ApplyView job
Binance1 day ago

Team Lead – Compliance Monitoring, Assurance & Testing

AE flagUnited Arab Emirates (UAE) OnlyFull-timeCompliance
ApplyView job
biBerk Business Insurance1 day ago

Claims Compliance Analyst – Workers' Compensation

US flagUnited States OnlyFull-timeCompliance$77k – $96.5k/year
ApplyView job
Doppel1 day ago

Director, Governance, Risk & Compliance

US flagUnited States OnlyFull-timeCompliance
ApplyView job
PingWind Inc. (SDVOSB)1 day ago

Risk and Compliance Analyst

US flagUnited States OnlyFull-timeCompliance
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers