We’re hiring a GRC Analyst / Product Owner & Framework Engineer for a young, successful and fast-growing, security and compliance software company building a modern platform used by security teams.
Dedicated to simplifying security standards such as SOC 2, ISO 27001, and others. We are seeking a Compliance Product Owner who can develop, refine, and maintain their control mapping library, support new compliance frameworks, and enhance automation features. This role offers an exciting opportunity to contribute to a pioneering product that aims to disrupt the traditional, often complex, compliance industry by integrating control rationalization and automation solutions. Ideal candidates will have a solid understanding of security frameworks, experience with control mapping, and basic scripting skills, all within a collaborative and fast-paced environment.
Important: for this search, we’re prioritising candidates who have:
1) Experience building security programs from scratch to meet with compliance requirements.
2) Strong working knowledge of major compliance frameworks (ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS).
Must-haves (hard requirements)
- Security Compliance Framework Knowledge: Practical experience understanding and working with frameworks like ISO 27001, SOC 2, GDPR, HIPAA, and ISO 42001. Ability to interpret and break down these frameworks into actionable requirements.
- Assessment & Framework Development: Ability to evaluate existing control frameworks, identify gaps, and develop rationalization strategies that enhance compatibility across standards.
- Control Mapping & Rationalization: Skilled in mapping controls across multiple frameworks to identify overlaps, redundancies, and inefficiencies in control libraries, supporting seamless automation.
- Scripting & Automation: Basic scripting skills capable of automating control and requirement updates, and validating compliance processes through code.
- JSON & Configuration Management: Comfortable reading, editing, and manipulating structured configuration files (JSON), crucial for maintaining control libraries and automation scripts.
Technical Nice to Have Skills:
- Programming Experience: Coding background, especially in Python or related languages, enhancing automation and integration capabilities.
- GRC SaaS Experience: Prior exposure to security governance, risk, and compliance software, providing context to platform integration.
Educational and Certification Requirements:
- Educational Background: Bachelor’s degree in information security, computer science, or related field preferred.
- Certifications: Advantageous include ISO 27001 Lead Implementer, SOC 2 Auditor, or related compliance certifications.
What you’ll do
This role centers on integrating and supporting various cybersecurity frameworks into our client’s platform. The successful candidate will focus on analyzing new frameworks, optimizing existing control libraries, and developing automation solutions that streamline compliance processes for clients. Their work directly impacts the effectiveness and usability of the platform, ensuring it remains a leading solution for security and compliance automation.
Next steps
Apply with your CV, and we’ll come back quickly to arrange a first conversation.
Job Ref: BBBH26108