> Markdown version of [/jobs/ext/2093970-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2093970-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** Preply Inc. - **Location:** Barcelona, Spain - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing Security, Cyber Security, Data Retention, PCI Data Security Standards - **Published:** August 16, 2026 - **Apply:** https://www.jobleads.com/es/job/e059d6200f72cb6c5dfd9ad3320fe41ac ## About the Role * 5+ years in GRC, risk management, compliance, or cybersecurity - preferably in a tech or SaaS environment. * A flexible background, which could include: + Engineering or technical roles with exposure to platform risk/security. + Legal or compliance roles, ideally with a specialization in cybersecurity or privacy. + Hybrid profiles (e.g., lawyers with CISSP, or engineers with compliance experience). * A proven track record in: + SOC 2 implementation (must-have). + Experience with frameworks/standards such as ISO 27001, ISO 27701, PCI DSS, or similar + Experience with regulations such as GDPR, CCPA, COPPA, EU AI Act, or similar. + Risk assessments and KRIs. + Cross-functional collaboration and stakeholder management. Core Competencies * Strong understanding of cloud security and modern SaaS risk landscapes. * Ability to translate regulatory requirements into practical, business-friendly policies. * Effective communicator with experience in running cross-functional sessions. * Practical experience applying AI tools in day-to-day work. * Experience with GRC/compliance automation tooling is a plus. ## Description You'll report to Director of Security and work closely with a small, high-impact Cybersecurity team. The role will be central to maintaining and expanding our risk management program, sustaining compliance with industry standards (especially SOC 2 Type 2), and building scalable governance processes to reduce identified risks. You'll work cross-functionally with Legal, Engineering, Security, Product, Finance, and company leadership. The ideal candidate brings deep risk and compliance expertise, thrives in ambiguity, and is energized by building secure, scalable systems that support business growth., * Maintain and continuously improve the risk management framework. Manage and continuously improve Preply's risk management framework, defining risk management approaches and overseeing the implementation of mitigation actions across the business. * Lead risk assessments. Run enterprise risk assessments, surfacing both technical and non-technical risks, and track Key Risk Indicators (KRIs) and other data-driven risk metrics to report to leadership. * Manage third-party risk. Maintain a third-party risk management program and perform periodic vendor reviews to ensure suppliers meet Preply's security bar. * Help shape governance and policy. Participate in developing and maintaining security, AI, and compliance policies in collaboration with Legal, Security, and Data teams, embedding governance checks into everyday business operations. * Drive SOC 2 and beyond. Support compliance initiatives for SOC 2 Type 2, with potential expansion to ISO 27001, ensuring controls are documented, tested, and audit-ready. * Support privacy initiatives. Contribute to data retention policies and guidelines for how different departments handle personal data. * Be the cross-functional bridge. Support coordination between Cybersecurity, Legal, and Engineering - translating regulatory requirements (GDPR, CCPA, etc.) into actionable policies, and supporting internal/external audits, policy reviews, and compliance syncs. * Champion security culture. Drive security awareness and compliance culture across the company. * Automate GRC operations. Identify opportunities to use AI tools to automate and streamline risk and compliance workflows (e.g. evidence collection, control monitoring, reporting). ## Related Videos - [Beyond the Hype: Building Trustworthy and Reliable LLM Applications with Guardrails](https://www.wearedevelopers.com/videos/1594-beyond-the-hype-building-trustworthy-and-reliable-llm-applications-with-guardrails) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Architecting the Future: Leveraging AI, Cloud, and Data for Business Success](https://www.wearedevelopers.com/videos/1096-architecting-the-future-leveraging-ai-cloud-and-data-for-business-success) - [Rethinking Recruiting: What you didn’t know about Responsible AI](https://www.wearedevelopers.com/videos/1090-rethinking-recruiting-what-you-didn-t-know-about-responsible-ai) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [The Prompt Engineer ✍️](https://www.wearedevelopers.com/magazine/216-the-prompt-engineer)