Grc Program Manager

AILY LABS
Madrid, Spain
10 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence Cyber Security

Job description

Mission We’re seeking a GRC Program Manager to own a defined set of compliance, risk, and security operations frameworks end-to-end.You won’t spend your time on routine evidence collection or manual audit checklists-we automate that.Instead, you’ll own the complexity: the stakeholder coordination, the conceptual design of how frameworks apply to our environment, and the human judgment calls that automation can’t make.Your scope extends beyond traditional GRC into the program and organizational aspects of Security Operations-ensuring detection, response, and operational processes are governed, measured, and continuously improved.Success means your frameworks run smoothly, auditors get what they need without chasing people, and control owners across the business understand what’s expected of them-because you designed it that way.As a GRC Program Manager, you are the reference person for your assigned frameworks-spanning compliance, risk, and security operations.You own them from interpretation through implementation-designing how controls map to our systems, coordinating across teams to ensure accountability, and managing external auditor relationships.You also own the programmatic and organizational side of Security Operations: how we structure detection and response processes, measure operational effectiveness, and ensure continuous improvement.Routine operational work is handled through AI and automation; your value is in the complexity that requires human judgment.Framework Ownership & Coordination:Own assigned compliance frameworks (e.g., SOC 2, ISO **, GDPR, AI regulations) endto-end-from interpreting requirements and designing control mappings to ensuring audit readinessAct as the single point of accountability for your frameworks: auditors, control owners, and leadership come to you for answersCoordinate cross-functional stakeholders (Engineering, Product, Legal, People) to ensure controls are embedded in their workflows-not bolted on as afterthoughtsManage external auditor relationships, including scoping discussions, audit planning, finding resolution, and certification deliveryAnticipate how regulatory changes affect your frameworks and proactively adapt the control environmentOwn the program structure of Security Operations-defining how detection and incident response processes are organized, governed, and reported onConceptual Design & Judgment:Design how abstract regulatory requirements translate into concrete, testable controls for our specific technology stack and business modelMake judgment calls on control applicability, risk acceptance recommendations, and framework interpretation where guidance is ambiguousDefine the conceptual structure of vendor assessments for your domain-what matters, what doesn’t, and where to draw the lineDesign and maintain the organizational framework for security operations-playbook governance, escalation structures, SLA definitions, and operational metricsAuthor and maintain policies that are enforceable and aligned to how the business actually operates-not compliance theaterStakeholder Enablement & Human Coordination:Enable control owners to be self-sufficient: design clear expectations, provide context on why controls exist, and remove friction from their compliance responsibilitiesCoordinate remediation across teams when gaps are identified-driving accountability without micromanaging executionCommunicate compliance posture and framework status to leadership in business termsResolve ambiguity and competing priorities between business velocity and compliance obligations-finding paths that serve bothAI & Automation Leverage:Design and maintain automated evidence collection, monitoring, and reporting workflow so routine compliance work runs without manual interventionContinuously identify where human effort in your programs can be replaced by automation, AI-assisted review, or platform configurationUse AI tools as a force multiplier for research, gap analysis, policy drafting, and audit preparation-the expectation is that you operate at a level only possible with these toolsYour profile Experience: 4+ years in GRC, compliance, security operations, or audit roles, with demonstrated experience owning at least one compliance framework or security operations program end-to-end (scoping, control design, audit coordination, certification).Must-Have Skills :Deep knowledge of governance frameworks (ISO **, SOC 2) and data privacy regulations (GDPR, CCPA), with the ability to interpret requirements and design practical control implementationsExperience managing external auditor relationships and driving audits to completion independentlyStrong stakeholder management skills-you can coordinate across technical and non-technical teams, hold people accountable, and resolve conflicts without escalationAbility to design control mappings and assessment …#J-*****-Ljbffr

Requirements

Your profile Experience: 4+ years in GRC, compliance, security operations, or audit roles, with demonstrated experience owning at least one compliance framework or security operations program end-to-end (scoping, control design, audit coordination, certification). Must-Have Skills : Deep knowledge of governance frameworks (ISO **, SOC 2) and data privacy regulations (GDPR, CCPA), with the ability to interpret requirements and design practical control implementations Experience managing external auditor relationships and driving audits to completion independently Strong stakeholder management skills-you can coordinate across technical and non-technical teams, hold people accountable, and resolve conflicts without escalation Ability to design control mappings and assessment … #J-**-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:46 min

Core terminology and audiences for interpretable artificial intelligence

Karol Przystalski · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:10 min

Balancing rapid artificial intelligence development with strict compliance regulations

3:21 min

Automating complete quality assurance pipelines with artificial intelligence

Evelyn Haslinger · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:11 min

Addressing security audits and regional data compliance legislation

Videos

See all

Related articles

See all