Remote job
Senior GRC Content Engineer
Job details
About this role
Role overview A senior content engineering role focused on building the first Governance, Risk and Compliance learning path for a fast-growing cybersecurity training platform, and laying the groundwork for future GRC content. The position pairs deep practitioner-level GRC expertise with a creative, teaching-oriented mindset, working in a small squad alongside another senior GRC practitioner to design interactive, scenario-driven learning rather than traditional compliance training. Coverage areas include EU cyber regulation such as NIS2, DORA and the Cyber Resilience Act, ISO 27001 and ISMS implementation, audit readiness, third-party risk and cyber crisis management.
Responsibilities - Research, design and build learning paths and rooms covering ISO 27001, ISMS operations, EU cyber regulation, audit readiness, third-party risk and crisis management. - Translate real practitioner experience — risk assessments, running an ISMS, facing auditors, drafting regulator notifications — into engaging, scenario-based exercises. - Define how AI is used inside content, including where automation is appropriate and where human sign-off must remain. - Collaborate with squad members on instructional design, scenario writing and product thinking for each room. - Maintain technical accuracy of regulatory, audit and risk content while keeping it accessible for learners at different stages.
Requirements - 5+ years of hands-on GRC or information security experience in roles such as GRC Analyst or Manager, Information Security Officer, ISMS Owner, Compliance Manager, Internal Auditor or Security & Compliance Consultant. - Practical, implementation-level experience with ISO/IEC 27001 (2022 control set), including scoping, risk assessment and treatment, statement of applicability and audit response. - Demonstrable ISMS operation, certification or surveillance audit experience, and real use of risk registers translated into working controls. - Working knowledge of EU cyber regulation including NIS2, DORA and the Cyber Resilience Act, plus third-party risk and incident or breach notification processes. - Ability to design interactive, scenario-driven learning content that goes beyond traditional compliance training. - Comfortable working in a modern, AI-conscious environment rather than legacy spreadsheet-driven processes.
Nice to have - Scripting or light programming in Python or Bash for building exercises and widgets. - Background in CTF or gamified content design. - Certifications such as CISSP, CISM, CISA, CRISC, CGRC, ISO/IEC 27001 Lead Implementer or Lead Auditor, or CIPP/E — practical experience is weighted more heavily.
Benefits and work setup - Fully remote role with flexible hours and a 4-hour overlap with UK business hours. - Dedicated work laptop and accessories, plus a welcome swag pack. - £2,500 personal development budget for certifications and training. - Annual fully paid company retreat. - Health insurance where public healthcare is unavailable, enhanced parental leave and a workplace pension or 401k. - Note: visa sponsorship is not available for this role.