GRC Program Manager

Aily Labs

Madrid

Presencial

EUR 60.000 - 80.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Global company culture
Fast growth path
Hybrid working model

Descripción de la vacante

Aily Labs is looking for a GRC Program Manager in Madrid to lead compliance and risk frameworks end-to-end. You will coordinate with stakeholders and oversee how frameworks integrate within the organization, ensuring smooth operations and effective controls.

Your role emphasizes leveraging automation to streamline compliance processes, while also managing external audits and enhancing the security operations program. Experience in governance frameworks and a proactive AI-focused approach are key.

Enjoy a hybrid working model in a fast-growing global company.

Formación

  • 4+ years in GRC, compliance, security operations, or audit roles.
  • Experience configuring GRC platforms and designing automated workflows.
  • Deep knowledge of governance frameworks (ISO 27001, SOC 2).
  • Ability to design control mappings and assessment methodologies.

Responsabilidades

  • Own and coordinate compliance frameworks (e.g., SOC 2, ISO 27001).
  • Manage external auditor relationships and drive audits to completion.
  • Design automated evidence collection and monitoring workflows.
  • Communicate compliance posture to leadership effectively.

Conocimientos

GRC, compliance, security operations
Stakeholder management
Written communication
Cloud-native environments (AWS)
Governance frameworks knowledge
Automation and AI tools usage

Educación

Experience managing external auditor relationships
Certifications such as CISA, CRISC, CIPP/E
4+ years in GRC, compliance, or audit roles

Herramientas

GRC platforms
AI tools

Descripción del empleo

  • We’re seeking a GRC Program Manager to own a defined set of compliance, risk, and security operations frameworks end-to-end
  • You won’t spend your time on routine evidence collection or manual audit checklists—we automate that
  • Instead, you’ll own the complexity: the stakeholder coordination, the conceptual design of how frameworks apply to our environment, and the human judgment calls that automation can’t make
  • Your scope extends beyond traditional GRC into the program and organizational aspects of Security Operations—ensuring detection, response, and operational processes are governed, measured, and continuously improved
  • Success means your frameworks run smoothly, auditors get what they need without chasing people, and control owners across the business understand what’s expected of them—because you designed it that way
  • As a GRC Program Manager, you are the reference person for your assigned frameworks—spanning compliance, risk, and security operations
  • You own them from interpretation through implementation—designing how controls map to our systems, coordinating across teams to ensure accountability, and managing external auditor relationships
  • You also own the programmatic and organizational side of Security Operations: how we structure detection and response processes, measure operational effectiveness, and ensure continuous improvement
  • Routine operational work is handled through AI and automation; your value is in the complexity that requires human judgment
  • Framework Ownership & Coordination:
  • Own assigned compliance frameworks (e.g., SOC 2, ISO 27001, GDPR, AI regulations) endto‑end—from interpreting requirements and designing control mappings to ensuring audit readiness
  • Act as the single point of accountability for your frameworks: auditors, control owners, and leadership come to you for answers
  • Coordinate cross‑functional stakeholders (Engineering, Product, Legal, People) to ensure controls are embedded in their workflows—not bolted on as afterthoughts
  • Manage external auditor relationships, including scoping discussions, audit planning, finding resolution, and certification delivery
  • Anticipate how regulatory changes affect your frameworks and proactively adapt the control environment
  • Own the program structure of Security Operations—defining how detection and incident response processes are organized, governed, and reported on
  • Conceptual Design & Judgment:
  • Design how abstract regulatory requirements translate into concrete, testable controls for our specific technology stack and business model
  • Make judgment calls on control applicability, risk acceptance recommendations, and framework interpretation where guidance is ambiguous
  • Define the conceptual structure of vendor assessments for your domain—what matters, what doesn’t, and where to draw the line
  • Design and maintain the organizational framework for security operations—playbook governance, escalation structures, SLA definitions, and operational metrics
  • Author and maintain policies that are enforceable and aligned to how the business actually operates—not compliance theater
  • Stakeholder Enablement & Human Coordination:
  • Enable control owners to be self‑sufficient: design clear expectations, provide context on why controls exist, and remove friction from their compliance responsibilities
  • Coordinate remediation across teams when gaps are identified—driving accountability without micromanaging execution
  • Communicate compliance posture and framework status to leadership in business terms
  • Resolve ambiguity and competing priorities between business velocity and compliance obligations—finding paths that serve both
  • AI & Automation Leverage:
  • Design and maintain automated evidence collection, monitoring, and reporting workflow so routine compliance work runs without manual intervention
  • Continuously identify where human effort in your programs can be replaced by automation, AI‑assisted review, or platform configuration
  • Use AI tools as a force multiplier for research, gap analysis, policy drafting, and audit preparation—the expectation is that you operate at a level only possible with these tools
Benefits
  • Global company and culture
  • Fast growth path
  • Hybrid working model

Experience managing external auditor relationships and driving audits to completion independentlyExperience: 4+ years in GRC, compliance, security operations, or audit roles, with demonstrated experience owning at least one compliance framework or security operations program end-to-end (scoping, control design, audit coordination, certification)Experience configuring GRC platforms and designing automated compliance workflows— you think in systems, not spreadsheetsStrong stakeholder management skills—you can coordinate across technical and non‑technical teams, hold people accountable, and resolve conflicts without escalationStrong written communication—you can author policies and reports that are clear, concise, and actionable for their intended audienceExperience in cloud‑native environments (AWS preferred) with an understanding of how infrastructure choices affect compliance scopeAbility to design control mappings and assessment methodologies, not just execute predefined checklistsAI-First Mindset: You leverage AI tools daily as a core part of how you work. You don’t wait to be told where to automate—you actively seek to eliminate routine work from your programs so you can focus on the hard problems that require human judgmentDeep knowledge of governance frameworks (ISO 27001, SOC 2) and data privacy regulations (GDPR, CCPA), with the ability to interpret requirements and design practical control implementationsComfort with ambiguity: you can make sound judgment calls when regulatory guidance is unclear or when business context requires interpretationCertifications such as CISA, CRISC, CIPP/E, or ISO 27001 Lead Auditor/ImplementerExperience with emerging AI regulations (EU AI Act, ISO 42001) and building governance approaches for AI/ML systemsBackground in high‑growth SaaS or platform companies where compliance programs had to scale quicklyExperience building or significantly maturing a GRC program—not just inheriting a fully built oneExperience with security operations frameworks—incident response lifecycle, detection engineering governance, or SOC program managementFamiliarity with security engineering practices and how compliance automation integrates with CI/CD and infrastructure-as-code

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

GRC Program Manager - Automate Compliance & Security Ops
GRC Program Manager - Automate Compliance & Security Ops

Aily Labs • Madrid

Híbrido
EUR 60.000 - 80.000
Global company culture
Fast growth path
Hybrid working model
Information Security Lead
Information Security Lead

Jobgether • España

Presencial
EUR 90.000 - 130.000
100% remote work
Generous equity package
€1,000 annual personal development预算
+6
Senior Compliance Analyst
Senior Compliance Analyst

TaxBit • Madrid

Presencial
EUR 70.000 - 95.000
Senior GRC Analyst: Risk, Compliance & Automation
Senior GRC Analyst: Risk, Compliance & Automation

Preply • Bellprat

Presencial
EUR 90.000 - 130.000
Equity
Learning budget
Health insurance
+3
Senior GRC Consultant
Senior GRC Consultant

Hack in Hire • Madrid

Híbrido
EUR 40.000 - 45.000
Hybrid work Madrid office
Performance bonuses
Career development
Senior Technical Architect (GRC)
Senior Technical Architect (GRC)

OneTrust • Madrid

Híbrido
EUR 90.000 - 125.000
Healthcare coverage
Equity RSUs
14+ weeks paid parental leave
+3
IAM & Risk Governance Analyst
IAM & Risk Governance Analyst

Admiral Europe Tech | Admiral Group • Sevilla

Presencial
EUR 40.000 - 60.000
Security Program Director
Security Program Director

Talent-R • Barcelona

Presencial
EUR 120.000 - 180.000
Senior IT SOX Associate
Senior IT SOX Associate

Jobtailor • Barcelona

Presencial
EUR 45.000 - 65.000
Cloud Security Engineer
Cloud Security Engineer

HappyRobot • Madrid

Presencial
EUR 70.000 - 110.000
Healthcare coverage
Dental coverage
Vision coverage
+1