Remote job
GRC Specialist
Job details
About this role
Role overview Join a remote-first compliance automation team as a GRC Specialist responsible for the depth and breadth of a platform that helps companies achieve and maintain ISO 27001, GDPR, TISAX, and SOC 2. The role spans compliance delivery, platform content, and audit execution, acting as the compliance voice for customers, auditors, and product teams.
Responsibilities - Build and maintain compliance frameworks inside the platform across ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 42001, C5, and additional standards as they are added. - Own internal audits end to end for customers, from kickoff to the final report, running several audits in parallel and keeping each on schedule. - Implement ISO 27001 and adjacent frameworks end to end for clients, closing framework gaps and turning auditor feedback into platform and team improvements. - Own the quality of compliance content, including policies, automated checks, evidence templates, CSM enablement playbooks, and security awareness training. - Partner with product and engineering to convert compliance gaps into structured platform work, and align with CS and founders on customer and roadmap priorities. - Deepen relationships with certification partners and train external auditors on platform workflows.
Requirements - Fluent English required. - Bachelor's degree in computer science, software engineering, or a related technical field, or equivalent hands-on experience. - Three or more years of hands-on information security and GRC experience. - Led at least one successful ISO 27001 certification project as an implementer or auditor at a startup or mid-market company. - Run at least two internal audits to completion. - Hands-on experience with a GRC platform, plus real depth in at least one framework beyond ISO 27001 such as TISAX, SOC 2, GDPR, or NIS 2. - Strong project management skills, sharp written communication, and an autonomous ownership mindset.
Nice to have - Experience mentoring or coaching colleagues in compliance, audit, or GRC contexts. - Startup environment experience. - PECB ISO 27001 Lead Auditor certification or an equivalent credential.
Benefits and work setup - 100% remote role with a virtual office; eligibility from UK, Germany, Austria, Poland, or Serbia. - Local-market salaries at or above market rate, plus a generous equity package. - €1,000 annual personal development budget, home office budget, and co-working access. - 26 days of holiday plus local public holidays, comprehensive health insurance, and latest tech equipment provided. - Annual team retreat and company-wide events.