GRC Program Manager

Aily Labs SLU

Barcelona

Híbrido

EUR 90.000 - 120.000

Jornada completa

14 días+
Generador de candidaturas

Transforma esta oferta en una entrevista: un currículum y una carta de presentación creados pensando en lo que quiere el empleador.

Supera los filtros ATS

Descripción de la vacante

Aily Labs SLU is seeking a GRC Program Manager to own a defined set of compliance, risk, and security operations frameworks end-to-end. You will design how controls map to our systems, coordinate across Engineering, Legal, Product, and People, and manage external auditors to ensure readiness.

Your role extends beyond traditional GRC into organizational security operations, measuring effectiveness, and driving continuous improvement.

Formación

  • Deep knowledge of governance frameworks (ISO 27001, SOC 2) and GDPR/CCPA interpretation for practical controls.
  • Experience managing external auditors and driving audits to completion.
  • Strong stakeholder management across technical and non-technical teams.
  • Ability to design control mappings and assessment against technology stacks.

Responsabilidades

  • Own end-to-end GRC programs, aligning frameworks with the business and approvals.
  • Coordinate cross-functional stakeholders to embed controls in workflows and ensure accountability.
  • Shape and govern security operations processes, including detection, response, and automation pathways.
  • Define and maintain policies and assessment methodologies beyond mere compliance theatre.

Conocimientos

Governance frameworks
Data privacy regulations
Auditor relationships
Stakeholder management
Control mappings

Descripción del empleo

Mission

We’re seeking a GRC Program Manager to own a defined set of compliance, risk, and security operations frameworks end-to-end.

You won’t spend your time on routine evidence collection or manual audit checklists—we automate that. Instead, you’ll own the complexity: the stakeholder coordination, the conceptual design of how frameworks apply to our environment, and the human judgment calls that automation can’t make. Your scope extends beyond traditional GRC into the program and organizational aspects of Security Operations—ensuring detection, response, and operational processes are governed, measured, and continuously improved. Success means your frameworks run smoothly, auditors get what they need without chasing people, and control owners across the business understand what’s expected of them—because you designed it that way.

As a GRC Program Manager, you are the reference person for your assigned frameworks—spanning compliance, risk, and security operations. You own them from interpretation through implementation—designing how controls map to our systems, coordinating across teams to ensure accountability, and managing external auditor relationships. You also own the programmatic and organizational side of Security Operations: how we structure detection and response processes, measure operational effectiveness, and ensure continuous improvement.

Routine operational work is handled through AI and automation; your value is in the complexity
that requires human judgment.

Framework Ownership & Coordination:
  • Own assigned compliance frameworks (e.g., SOC 2, ISO 27001, GDPR, AI regulations) endto-end—from interpreting requirements and designing control mappings to ensuring audit readiness
  • Act as the single point of accountability for your frameworks: auditors, control owners, and leadership come to you for answers
  • Coordinate cross-functional stakeholders (Engineering, Product, Legal, People) to ensure controls are embedded in their workflows—not bolted on as afterthoughts
  • Manage external auditor relationships, including scoping discussions, audit planning, finding resolution, and certification delivery
  • Anticipate how regulatory changes affect your frameworks and proactively adapt the control environment
  • Own the program structure of Security Operations—defining how detection and incident response processes are organized, governed, and reported on
Conceptual Design & Judgment:
  • Design how abstract regulatory requirements translate into concrete, testable controls for our specific technology stack and business model
  • Make judgment calls on control applicability, risk acceptance recommendations, and framework interpretation where guidance is ambiguous
  • Define the conceptual structure of vendor assessments for your domain—what matters, what doesn’t, and where to draw the line
  • Design and maintain the organizational framework for security operations—playbook governance, escalation structures, SLA definitions, and operational metrics
  • Author and maintain policies that are enforceable and aligned to how the business actually operates—not compliance theater
Stakeholder Enablement & Human Coordination:
  • Enable control owners to be self-sufficient: design clear expectations, provide context on why controls exist, and remove friction from their compliance responsibilities
  • Coordinate remediation across teams when gaps are identified—driving accountability without micromanaging execution
  • Communicate compliance posture and framework status to leadership in business terms
  • Resolve ambiguity and competing priorities between business velocity and compliance obligations—finding paths that serve both
AI & Automation Leverage:
  • Design and maintain automated evidence collection, monitoring, and reporting workflow so routine compliance work runs without manual intervention
  • Continuously identify where human effort in your programs can be replaced by automation, AI-assisted review, or platform configuration
  • Use AI tools as a force multiplier for research, gap analysis, policy drafting, and audit preparation—the expectation is that you operate at a level only possible with these tools
Your profile

Experience: 4+ years in GRC, compliance, security operations, or audit roles, with demonstrated experience owning at least one compliance framework or security operations program end-to-end (scoping, control design, audit coordination, certification).

Must-Have Skills :
  • Deep knowledge of governance frameworks (ISO 27001, SOC 2) and data privacy regulations (GDPR, CCPA), with the ability to interpret requirements and design practical control implementations
  • Experience managing external auditor relationships and driving audits to completion independently
  • Strong stakeholder management skills—you can coordinate across technical and non-technical teams, hold people accountable, and resolve conflicts without escalation
  • Ability to design control mappings and assessment …
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

GRC Compliance Specialist
GRC Compliance Specialist

HappyRobot • Madrid

Presencial
EUR 55.000 - 85.000
Healthcare
Dental and vision
Equity
Strategic GRC & Security Operations Lead
Strategic GRC & Security Operations Lead

Aily Labs SLU • Barcelona

Híbrido
EUR 90.000 - 120.000
Security Program Director
Security Program Director

Business Insights • Barcelona

Presencial
EUR 150.000 - 190.000
Senior GRC Analyst: Risk, Compliance & Automation
Senior GRC Analyst: Risk, Compliance & Automation

Preply • Bellprat

Presencial
EUR 90.000 - 130.000
Equity
Learning budget
Health insurance
+3
GRC Manager
GRC Manager

Omilia • España

Presencial
EUR 90.000 - 120.000
Fixed compensation
Long-term employment
Professional growth
+3
Senior Compliance Analyst
Senior Compliance Analyst

TaxBit • Madrid

Presencial
EUR 70.000 - 95.000
GRC Compliance Specialist
GRC Compliance Specialist

Happyrobot Inc. • España

Presencial
EUR 42.000 - 64.000
GRC Compliance Lead — SOC 2/ISO 27001 for AI Security
GRC Compliance Lead — SOC 2/ISO 27001 for AI Security

HappyRobot • Madrid

Presencial
EUR 55.000 - 85.000
Healthcare
Dental and vision
Equity
Technical GRC Cybersecurity Account Lead
Technical GRC Cybersecurity Account Lead

S2 Grupo • Madrid

Presencial
Senior Information Security GRC Analyst
Senior Information Security GRC Analyst

OneTrust • Madrid

Híbrido
EUR 55.000 - 75.000
Healthcare coverage
Equity RSUs
Annual performance bonus opportunities
+3