Grc Manager
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The Senior CGRC Operations Analyst owns Omilia’s regulatory compliance programmes and certification portfolio end to end. This is a delivery role, not an advisory one: the person in it runs the ISMS, manages certification body relationships, drives data protection governance, and coordinates evidence across SOC 2, ISO **, and adjacent frameworks. Omilia operates under EU law with enterprise clients in regulated industries around the world. The Senior CGRC Operations Analyst is the operational backbone that keeps those relationships defensible and those certifications current.AccountabilitiesOwn the full lifecycle of ISO **, SOC 2 Type II, C5, PCI-DSS, and Cyber Essentials certifications: scoping, evidence library, audit coordination, management responses, and remediation trackingOwn the GDPR operational compliance framework: DPIA process, LIA and TIA governance, RoPA maintenance, breach response documentation, and cross-border transfer mechanisms in collaboration with the DPOMaintain active compliance frameworks for DORA, NIS2, HIPAA, CCPA/CPRA, and the EU Data Act, maintaining current obligation tracking and client assurance artefactsOwn breach and incident response governance end to end: process, regulatory notification decision support, Art. *** documentation, and the regulatory notification registerDrive control owner accountability without direct authority: translate regulatory obligation into business consequence, manage evidence deadlines, escalate where necessaryKey ResponsibilitiesManage the ISMS evidence library, own the certification body relationship for ISO *** and C5Coordinate SOC 2 Type II readiness: TSC scoping, evidence collection, auditor engagement, report distribution, and management response draftingMaintain the RoPA, conduct DPIAs and LIAs, and manage data subject rights governance under GDPRTrack and implement obligations under DORA, NIS2, HIPAA, CCPA/CPRA, EU Data Act, and Cyber Resilience Act as live regulatory requirements, not awareness itemsCoordinate BAA execution and PHI obligation documentation with Legal for healthcare accountsRun the compliance deliverable tracker; close loops on evidence collection without being managedTranslate regulatory obligations into plain-language business impact and secure timely responses from technical and product stakeholders who do not report to this roleManage the end-to-end coordination of client compliance audits: evidence packs, management responses, findings remediationMaintain and administer the CGRC automation platform, including uploading evidence and monitoring control statusRequirementsTechnical and Professional Skills4 to 8 years in the CGRC field, with the majority in regulated B2B technology or SaaS environmentsISO *** Lead Auditor or Lead Implementer credential (mandatory)Demonstrated end-to-end SOC 2 Type II ownership: scoping, evidence coordination, auditor management, and management response, not just participationGDPR practitioner depth: DPIA, RoPA, data subject rights, cross-border transfer mechanisms (SCCs, BCRs). Not a legal role, but Regulation-level fluency is requiredActive working knowledge of DORA and NIS2 as live compliance obligations; familiarity with HIPAA BAA coordination and US state privacy law tracking (CCPA/CPRA) is a strong advantageExperience with a CGRC automation platform at an operational level, not just as a userSoft and Behavioural SkillsRuns a personal compliance tracker, closes loops independently, and does not require follow-up to meet deadlinesTranslates regulatory obligation into business consequence in plain language and drives timely response from technical teams and product stakeholders without formal authorityTreats business pushback as the beginning of a process, not the end: documents, escalates, and tracks to resolutionComfortable being the compliance practitioner in the room during an audit: composed, prepared, and accountable for management responsesOperates with minimal supervision in a small, high-output team where there is no large department to absorb operational errors or deadline slippageFormal RequirementsDegree in Law, Business, Information Systems, or equivalent professional experienceBusiness fluency in English (written and spoken) is mandatoryNo formal travel requirement; occasional travel to Greece for client audits or certification body engagements may ariseBenefitsFixed compensation;Long-term employment with the working days vacation;Development in professional growth (courses, training, etc);Being part of successful cutting-edge technology products that are making a global impact in the service industry;Proficient and fun-to-work-with colleagues;Apple gearOmilia is proud to be an equal opportunity employer and is dedicated to fostering a diverse and inclusive workplace. We believe that embracing diversity in all its forms enriches our workplace and drives our collective success. We are committed to creating an environment where everyone feels welcomed, valued, and empowered to contribute their unique perspectives without regard to factors such as race, color, religion, gender, gender identity or expression, sexual orientation, national origin, heredity, disability, age, or veteran status, all eligible candidates will be given consideration for employment.#J-***-Ljbffr
Requirements
Technical and Professional Skills 4 to 8 years in the CGRC field, with the majority in regulated B2B technology or SaaS environments ISO ***** Lead Auditor or Lead Implementer credential (mandatory) Demonstrated end-to-end SOC 2 Type II ownership: scoping, evidence coordination, auditor management, and management response, not just participation GDPR practitioner depth: DPIA, RoPA, data subject rights, cross-border transfer mechanisms (SCCs, BCRs). Not a legal role, but Regulation-level fluency is required Active working knowledge of DORA and NIS2 as live compliance obligations; familiarity with HIPAA BAA coordination and US state privacy law tracking (CCPA/CPRA) is a strong advantage Experience with a CGRC automation platform at an operational level, not just as a user Soft and Behavioural Skills Runs a personal compliance tracker, closes loops independently, and does not require follow-up to meet deadlines Translates regulatory obligation into business consequence in plain language and drives timely response from technical teams and product stakeholders without formal authority Treats business pushback as the beginning of a process, not the end: documents, escalates, and tracks to resolution Comfortable being the compliance practitioner in the room during an audit: composed, prepared, and accountable for management responses Operates with minimal supervision in a small, high-output team where there is no large department to absorb operational errors or deadline slippage Formal Requirements Degree in Law, Business, Information Systems, or equivalent professional experience Business fluency in English (written and spoken) is mandatory No formal travel requirement; occasional travel to Greece for client audits or certification body engagements may arise
Benefits & conditions
Fixed compensation; Long-term employment with the working days vacation; Development in professional growth (courses, training, etc); Being part of successful cutting-edge technology products that are making a global impact in the service industry; Proficient and fun-to-work-with colleagues; Apple gear Omilia is proud to be an equal opportunity employer and is dedicated to fostering a diverse and inclusive workplace. We believe that embracing diversity in all its forms enriches our workplace and drives our collective success. We are committed to creating an environment where everyone feels welcomed, valued, and empowered to contribute their unique perspectives without regard to factors such as race, color, religion, gender, gender identity or expression, sexual orientation, national origin, heredity, disability, age, or veteran status, all eligible candidates will be given consideration for employment. #J-*****-Ljbffr
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Fully Remote Software Engineer Jobs
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
UK Business Culture and Etiquette