GRC Specialist
Core
Own compliance frameworks, internal audits, and content quality for Secfix's platform to help customers achieve ISO 27001, GDPR, TISAX, SOC 2, and other certifications.
Role type
GRC Specialist (Individual Contributor)
Builds
Compliance frameworks, audit reports, platform content (policies, templates, playbooks), and product improvements based on compliance gaps.
Domain
Cybersecurity, Governance, Risk, and Compliance (GRC) in the European market.
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
ISO 27001 implementation and auditing, internal audit execution, GRC platform usage, project management, technical writing, stakeholder collaboration, framework gap analysis, auditor training.
Preferred skills
Mentoring/coaching in GRC, startup environment experience, PECB ISO 27001 Lead Auditor certification.
Technologies
Secfix, GRC platforms, ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 42001, C5.
Responsibilities
Build and maintain compliance frameworks in the platform; own internal audits from kickoff to final report; implement ISO 27001 and adjacent frameworks for customers; create compliance content (policies, templates, playbooks); close framework gaps and incorporate auditor feedback; partner with product/engineering to translate gaps into product work; train auditors on the platform.
Seniority
Mid-level, hands-on IC