
GRC Specialist
Posted Sep 16

Posted Sep 16
This is a fully remote position, open to applicants in United Kingdom, +4 more countries.
• Develop and uphold compliance frameworks within the Secfix platform, encompassing ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 42001, and C5.
• Manage customer internal audits from initiation to final reporting.
• Oversee multiple audits simultaneously while ensuring they remain on schedule.
• Execute ISO 27001 and related frameworks from start to finish for clients.
• Maintain the quality of compliance materials in the platform, including policies, automated checks, evidence templates, compliance enablement playbooks, and security awareness training.
• Address framework deficiencies and incorporate auditor feedback into team practices and platform enhancements.
• Collaborate with product and engineering teams to convert compliance gaps into organized product tasks.
• Work alongside Customer Success, Product, and Founders to harmonize compliance, customer, and roadmap priorities.
• Cultivate relationships with certification partners.
• Provide training for auditors on the Secfix platform for client audits.
• Engage in the screening, take-home assessment, assessment review, and founder interview phases.
• Proficient in English.
• Bachelor's degree in computer science, software engineering, or a related technical discipline, or equivalent practical technical experience.
• Over 3 years of practical experience in information security and GRC.
• Successfully led at least one ISO 27001 certification project as an implementer and/or auditor within a startup or mid-market organization.
• Conducted a minimum of two internal audits.
• Practical experience with a GRC platform such as Secfix or a comparable system.
• Extensive knowledge in at least one compliance framework beyond ISO 27001, such as TISAX, SOC 2, GDPR, NIS2, or similar.
• Strong project management capabilities.
• Exceptional written communication skills with the ability to create clear, precise compliance content.
• Capacity to operate as an individual contributor with a strong sense of ownership.
• Experience in mentoring or coaching peers in a compliance, audit, or GRC setting is a plus.
• Experience in a startup environment is advantageous.
• PECB ISO 27001 Lead Auditor certification or a direct equivalent is a bonus.
• Must reside in the UK, Germany, Austria, Poland, or Serbia.
• Must meet visa sponsorship criteria for the respective country of residence.
• Fully remote work with a virtual office in Gather.
• Competitive local salaries at or above market benchmarks.
• Generous equity offerings.
• Direct access to top-tier mentors.
• €1,000 annual budget for personal development.
• Budget for home office setup.
• Access to co-working facilities.
• 26 days of vacation plus local public holidays.
• Comprehensive health insurance coverage.
• Annual company retreat.
• Company-wide events.
• Provision of the latest technology equipment, including MacBook, monitors, and headphones.
LabConnect
Ripple Effect
Binance
biBerk Business Insurance
Get handpicked remote jobs straight to your inbox weekly.