HQ - GRC Lead
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are looking for a GRC Lead to own and scale our Governance, Risk, and Compliance function within a fast-growing product company. This is a key role responsible for ensuring compliance with SOX, ISO 27001, and GDPR, while enabling the business to move fast in a secure and controlled way. You will act as the main driver of our compliance strategy, working cross-functionally with Engineering, Security, Legal, Finance, and Product teams. What you will do Own and lead the company’s GRC strategy across SOX, ISO 27001, and GDPR Design, implement, and maintain SOX control frameworks, including documentation, testing, and audit readiness Build and manage the Information Security Management System (ISMS) aligned with ISO 27001 Ensure GDPR compliance across all data processing activities, including data mapping, DPIAs, and privacy controls Lead internal and external audits, acting as the primary point of contact for auditors Identify compliance gaps and drive remediation plans with technical and non-technical teams Develop governance policies, procedures, and risk management frameworks Partner closely with Engineering and Security teams to embed controls into systems and SDLC processes Monitor regulatory and compliance changes and translate them into actionable requirements, #LI-ML3We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us. Inscribirse en esta oferta Recibir ofertas similares por correo electrónico Al crear una alerta, aceptas nuestros Términos y condiciones y PolÃtica de privacidad, y el uso de cookies.
Requirements
8+ years of experience in GRC, Risk, Compliance, or IT Audit roles Strong hands-on experience with SOX compliance programs (design, testing, audit coordination) Solid knowledge of ISO 27001 and experience managing or supporting ISMS implementation Practical experience with GDPR in a product or corporate environment Experience working with internal and external auditors Strong stakeholder management and communication skills across technical and non-technical teams Ability to translate regulatory requirements into scalable business processes Fluent English Nice to have Experience in SaaS or product-led companies Experience in Big 4 (Deloitte, EY, PwC, KPMG) or similar audit environments Familiarity with cloud environments (AWS, GCP, Azure) Security certifications (CISA, CISM, ISO 27001 Lead Implementer/Auditor)
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Fully Remote Software Engineer Jobs
Top HR Tech Conferences in 2024
Best Companies to work for in London: Top 25 Companies in 2023