
GRC Specialist, German-speaking
Posted 7 hours ago

Posted 7 hours ago
This is a fully remote position, open to applicants in Germany, +4 more countries.
β’ Develop and sustain compliance frameworks within the Secfix platform.
β’ Manage internal audits for clients from initiation to the delivery of the final report.
β’ Ensure multiple audits are progressing as scheduled.
β’ Implement ISO 27001 and related frameworks comprehensively for clients.
β’ Maintain the quality of compliance content within the platform.
β’ Develop policies, automated checks, evidence templates, Compliance Enable playbooks, and security awareness training materials.
β’ Address framework deficiencies and integrate auditor feedback into team practices and platform enhancements.
β’ Collaborate with product and engineering teams to translate compliance deficiencies into organized product initiatives.
β’ Work alongside Customer Success, Product, and Founders to synchronize compliance, customer needs, and roadmap priorities.
β’ Foster relationships with certification partners.
β’ Provide training to auditors on the Secfix platform for client audits.
β’ Enhance Secfix's compliance capabilities as the company expands into additional frameworks and mid-market clients.
β’ Proficient in German (C1/C2) and fluent in English.
β’ Bachelor's degree in computer science, software engineering, or a related technical discipline, or equivalent practical technical experience.
β’ Over 3 years of relevant experience in information security and Governance, Risk, and Compliance (GRC).
β’ Successfully led at least one ISO 27001 certification project as either an implementer or auditor in a startup or mid-market environment.
β’ Conducted a minimum of two internal audits.
β’ Practical experience with a GRC platform such as Secfix or similar.
β’ In-depth knowledge of at least one framework beyond ISO 27001, such as TISAX, SOC 2, GDPR, NIS2, or similar.
β’ Strong project management capabilities.
β’ Exceptional written communication skills, particularly in creating clear and precise compliance documentation.
β’ A strong sense of ownership and the ability to function as an individual contributor.
β’ Experience in mentoring or coaching peers in a compliance, audit, or GRC setting is a plus.
β’ Familiarity with a startup environment is advantageous.
β’ PECB ISO 27001 Lead Auditor certification or an equivalent qualification is a plus.
β’ Fully remote work with a virtual office in Gather.
β’ Competitive local salaries that meet or exceed market standards.
β’ Generous equity package.
β’ Direct access to top-tier mentors.
β’ β¬1,000 annual budget for personal development.
β’ Home office budget.
β’ Access to co-working spaces.
β’ 26 days of vacation in addition to local public holidays.
β’ Comprehensive health insurance coverage.
β’ Annual company retreat.
β’ Company-wide events.
β’ Provision of the latest technology, including MacBook, monitors, and headphones.
Freudenberg Group
Mercor
Lifelancer
Doppel
Get handpicked remote jobs straight to your inbox weekly.