We are looking for a GRC Specialist to support our Governance, Risk, and Compliance (GRC) program, reporting directly to the CISO.
This is a hands‑on, execution‑focused role responsible for maintaining and scaling our compliance posture, reducing audit friction, addressing vendor risk, and supporting the integration of newly acquired companies into our security and compliance frameworks.
You will work closely with Security Engineering, IT, Legal, Privacy, Sales/Revenue, Procurement, Product, HR, and other business stakeholders to ensure security controls, compliance activities, and risk management processes are practical, effective, and aligned with business needs.
The day‑to‑day:
Lead audit preparation and ongoing compliance maintenance for frameworks such as SOC 2 / SOC 3, ISO 27001, ISO 27701, ISO 22301, NIST, and GDPR, including evidence collection, gap tracking, and remediation coordination.
Own and execute vendor and third‑party security assessments, helping reduce backlog and improve risk visibility across suppliers and partners.
Respond to customer security questionnaires and audits, partnering with Sales and Security teams to support deal velocity and customer trust.
Support the integration of newly acquired companies into our security, risk, and compliance programs, including gap assessments and remediation planning.
Maintain and improve the ISMS, governance processes, policies, standards, and procedures.
Act as a central point of contact for internal security and compliance inquiries from business and technical teams.
Support the administration and continuous improvement of GRC and compliance tooling, including workflows, evidence management, and reporting.
Contribute to the Security Awareness Program and cross‑organizational education efforts.
The perks:
Hybrid, flexible work environment.
Extended private health (including mental) insurance.
Personal and professional development programs.
Occasional Cross company long weekends.
Requirements: Ideally, were looking for:
1-2 years hands‑on experience in GRC, information security, audit, or compliance, with a strong focus on execution and coordination.
Practical experience working with ISO 27001, SOC 2, GDPR, and/or NIST CSF, including audits and ongoing compliance activities.
Solid understanding of risk management, control design, and governance processes in a SaaS or cloud environment.
Experience performing vendor / third‑party risk assessments and driving remediation.
Strong ability to work cross‑functionally with technical and non‑technical stakeholders.
Clear, concise written and verbal communication skills in English, including customer‑facing documentation.
Strong organizational skills and attention to detail, with the ability to manage multiple parallel workstreams.
These would also be nice
Relevant certifications such as CISA, CISM, CRISC, or ISO 27001 Lead Auditor / Implementer.
Experience with privacy governance, DPIAs/PIAs, and collaboration with legal and privacy teams.
Familiarity with cloud and SaaS environments, particularly AWS.
Experience with GRC platforms or compliance automation tools.
This position is open to all candidates.