
Senior GRC Content Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants anywhere in the world.
• Conduct research, design, and create GRC training environments, modules, and learning pathways.
• Develop practical exercises for risk registers, Statement of Applicability labs, audit simulations, DDQ challenges, regulator notification drills, and branching tabletop scenarios.
• Serve as a subject-matter expert in ISO 27001/ISMS, EU regulations (NIS2, DORA, CRA), risk management, and audit preparedness.
• Ensure technical accuracy throughout the GRC portfolio in collaboration with the squad lead.
• Establish and maintain lab environments utilizing open-source GRC tools like Eramba and TryHackMe interactive widgets.
• Collaborate with platform and design teams as necessary.
• Strategize and outline segments of the GRC content roadmap.
• Utilize customer feedback, demand signals, and competitive analysis to refine scoping decisions.
• Monitor regulatory updates and ensure that released content remains relevant.
• Mentor and evaluate contractors and other content engineers.
• Partner with Content Engineering leadership to enhance content creation processes.
• Work with Sales/CS to align content with the needs of enterprise customers.
• Minimum of 5+ years of practical experience in GRC / information security.
• Hands-on, implementation-level knowledge of ISO/IEC 27001 (2022 control set), including scoping, risk assessment and treatment, Statement of Applicability, and both internal and certification audits.
• Familiarity with NIS2, specifically Articles 20/21/23, DORA, and an understanding of the Cyber Resilience Act.
• Strong foundation in risk management practices, including qualitative assessment techniques, risk registers, controls, control types, risk treatment, and residual risk sign-off.
• Experience managing audit and evidence workflows.
• Knowledge of third-party/vendor risk, due-diligence questionnaires, SOC 2 reports, and contractual security obligations.
• Comprehensive understanding of technical security aspects, including networks, systems, cloud environments, and common attack vectors.
• Exceptional written English skills.
• Ability to research and integrate regulations, framework updates, enforcement trends, and competitor offerings.
• Creative mindset focused on learner engagement.
• Comfort in navigating ambiguity.
• Preferred: experience in instructional design or training delivery.
• Preferred: involvement in tabletop exercises or crisis simulations.
• Preferred: exposure to SOC 2 Type 2, PCI-DSS, HIPAA, CMMC, or Cyber Essentials.
• Preferred: familiarity with Drata, Vanta, OneTrust, ServiceNow GRC, or AuditBoard.
• Preferred: use of AI tools within GRC workflows.
• Preferred: skills in Python or Bash scripting.
• Preferred: experience in designing CTF or gamified content.
• Certifications such as CISSP, CISM, CISA, CRISC, CGRC, ISO/IEC 27001 Lead Implementer/Lead Auditor, or CIPP/E are valued.
• Currently, we are not able to offer sponsorship.
• 100% Remote - Work from anywhere in a fully digital environment!
• Flexi Time - Set your own hours as long as you maintain at least 4 hours of overlap with the UK timezone (between 8am - 6pm).
• A dedicated work laptop plus any accessories you need to excel.
• Branded swag bundle.
• £2,500 training budget for certifications and more.
• Annual company retreat, fully funded by us.
• Health Insurance - provided if you are in a country without public healthcare.
• Enhanced Maternity & Paternity benefits in addition to statutory requirements.
• 401k / Pension plan.
Reach plc
Avocado Green Brands
InnoData
Paires
Get handpicked remote jobs straight to your inbox weekly.