GRC Manager

Omilia

España

Presencial

EUR 90 000 - 120 000

Tempo integral

14 dias+
Gerador de candidaturas

Uma candidatura feita para esta oferta — um currículo e uma carta de apresentação personalizados que vão ao encontro do anúncio.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Fixed compensation
Long-term employment
Professional growth
Global impact products
Great colleagues
Apple gear

Resumo da oferta

Omilia is seeking a Senior CGRC Operations Analyst to own regulatory compliance programmes end to end. This is a delivery role and you will run the ISMS, manage certification body relationships, govern GDPR, and coordinate evidence across ISO 27001, SOC 2 Type II, C5, PCI-DSS, and related frameworks for global enterprise clients.

You will maintain live obligations and drive timely responses across cross-functional teams in a fast-paced environment with minimal supervision.

Qualificações

  • 4–8 years in CGRC in regulated B2B tech or SaaS.
  • ISO 27001 Lead Auditor or Lead Implementer credential required.
  • End-to-end SOC 2 Type II ownership experience.
  • GDPR proficiency: DPIA, RoPA, data rights, cross-border transfers.
  • Familiarity with DORA and NIS2; HIPAA/CCPA knowledge a plus.
  • Experience with CGRC automation platforms.

Responsabilidades

  • Own ISO 27001, SOC 2 Type II, and other certifications lifecycle.
  • Maintain GDPR framework, DPIA and RoPA governance.
  • Track DORA, NIS2, HIPAA, CCPA/CPRA obligations.
  • Coordinate client compliance audits and evidence packs.
  • Manage ISMS evidence library and certification body relations.
  • Communicate regulatory obligations in plain language to tech teams.

Conhecimentos

CGRC
ISO Lead Auditor
SOC 2 ownership
GDPR DPIA
DORA knowledge
NIS2 awareness
CCPA familiarity
Automation platform

Formação académica

Degree in Law
Degree in Business
Degree in Information Systems

Ferramentas

CGRC platform

Descrição da oferta de emprego

The Senior CGRC Operations Analyst owns Omilia's regulatory compliance programmes and certification portfolio end to end. This is a delivery role, not an advisory one: the person in it runs the ISMS, manages certification body relationships, drives data protection governance, and coordinates evidence across SOC 2, ISO 27001, and adjacent frameworks. Omilia operates under EU law with enterprise clients in regulated industries around the world. The Senior CGRC Operations Analyst is the operational backbone that keeps those relationships defensible and those certifications current.

Accountabilities
  • Own the full lifecycle of ISO 27001, SOC 2 Type II, C5, PCI-DSS, and Cyber Essentials certifications: scoping, evidence library, audit coordination, management responses, and remediation tracking
  • Own the GDPR operational compliance framework: DPIA process, LIA and TIA governance, RoPA maintenance, breach response documentation, and cross-border transfer mechanisms in collaboration with the DPO
  • Maintain active compliance frameworks for DORA, NIS2, HIPAA, CCPA/CPRA, and the EU Data Act, maintaining current obligation tracking and client assurance artefacts
  • Own breach and incident response governance end to end: process, regulatory notification decision support, Art. 33/34 documentation, and the regulatory notification register
  • Drive control owner accountability without direct authority: translate regulatory obligation into business consequence, manage evidence deadlines, escalate where necessary
Key Responsibilities
  • Manage the ISMS evidence library, own the certification body relationship for ISO 27001 and C5
  • Coordinate SOC 2 Type II readiness: TSC scoping, evidence collection, auditor engagement, report distribution, and management response drafting
  • Maintain the RoPA, conduct DPIAs and LIAs, and manage data subject rights governance under GDPR
  • Track and implement obligations under DORA, NIS2, HIPAA, CCPA/CPRA, EU Data Act, and Cyber Resilience Act as live regulatory requirements, not awareness items
  • Coordinate BAA execution and PHI obligation documentation with Legal for healthcare accounts
  • Run the compliance deliverable tracker; close loops on evidence collection without being managed
  • Translate regulatory obligations into plain-language business impact and secure timely responses from technical and product stakeholders who do not report to this role
  • Manage the end-to-end coordination of client compliance audits: evidence packs, management responses, findings remediation
  • Maintain and administer the CGRC automation platform, including uploading evidence and monitoring control status
Requirements
Technical and Professional Skills
  • 4 to 8 years in the CGRC field, with the majority in regulated B2B technology or SaaS environments
  • ISO 27001 Lead Auditor or Lead Implementer credential (mandatory)
  • Demonstrated end-to-end SOC 2 Type II ownership: scoping, evidence coordination, auditor management, and management response, not just participation
  • GDPR practitioner depth: DPIA, RoPA, data subject rights, cross-border transfer mechanisms (SCCs, BCRs). Not a legal role, but Regulation-level fluency is required
  • Active working knowledge of DORA and NIS2 as live compliance obligations; familiarity with HIPAA BAA coordination and US state privacy law tracking (CCPA/CPRA) is a strong advantage
  • Experience with a CGRC automation platform at an operational level, not just as a user
Soft and Behavioural Skills
  • Runs a personal compliance tracker, closes loops independently, and does not require follow-up to meet deadlines
  • Translates regulatory obligation into business consequence in plain language and drives timely response from technical teams and product stakeholders without formal authority
  • Treats business pushback as the beginning of a process, not the end: documents, escalates, and tracks to resolution
  • Comfortable being the compliance practitioner in the room during an audit: composed, prepared, and accountable for management responses
  • Operates with minimal supervision in a small, high-output team where there is no large department to absorb operational errors or deadline slippage
Formal Requirements
  • Degree in Law, Business, Information Systems, or equivalent professional experience
  • Business fluency in English (written and spoken) is mandatory
  • No formal travel requirement; occasional travel to Greece for client audits or certification body engagements may arise
Benefits
  • Fixed compensation;
  • Long-term employment with the working days vacation;
  • Development in professional growth (courses, training, etc);
  • Being part of successful cutting-edge technology products that are making a global impact in the service industry;
  • Proficient and fun-to-work-with colleagues;
  • Apple gear

Omilia is proud to be an equal opportunity employer and is dedicated to fostering a diverse and inclusive workplace. We believe that embracing diversity in all its forms enriches our workplace and drives our collective success. We are committed to creating an environment where everyone feels welcomed, valued, and empowered to contribute their unique perspectives without regard to factors such as race, color, religion, gender, gender identity or expression, sexual orientation, national origin, heredity, disability, age, or veteran status, all eligible candidates will be given consideration for employment.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Senior CGRC Operations Analyst
Senior CGRC Operations Analyst

Omilia • Portugal

Presencial
EUR 80 000 - 110 000
Fixed compensation
Vacation days
Professional growth
+2
CGRC Operations Lead: ISO 27001 & SOC 2 Expert
CGRC Operations Lead: ISO 27001 & SOC 2 Expert

Omilia • Portugal

Presencial
EUR 80 000 - 110 000
Fixed compensation
Vacation days
Professional growth
+2
Solution Consultant, Iberia
Solution Consultant, Iberia

Omilia • Portugal

Híbrido
EUR 70 000 - 100 000
Fixed compensation
Vacation days on top of standard leave
Professional development
Senior Conversational AI Delivery Engineer
Senior Conversational AI Delivery Engineer

Omilia • Portugal

Presencial
EUR 50 000 - 70 000
Fixed compensation
Long-term employment with paid vacation
Professional growth opportunities
+1
Solution Consultant Director, EMEA
Solution Consultant Director, EMEA

Omilia • Portugal

Presencial
EUR 80 000 - 120 000
Fixed compensation
Long-term employment
Professional development opportunities
+1
Compliance Manager
Compliance Manager

Prisonsystems • Portugal

Híbrido
EUR 40 000 - 60 000
Senior Governance, Risk and Compliance Engineer
Senior Governance, Risk and Compliance Engineer

payabl. • Lisboa

Presencial
EUR 70 000 - 90 000
Provident Fund
Annual Learning Budget
€150 Wolt allowance
+8
IT Security Specialist GRC
IT Security Specialist GRC

Match Profiler • Porto

Híbrido
EUR 40 000 - 60 000
Personalized support from the team
Exclusive discounts with partners
Celebration of victories
+2
Cyber Security DORA Control Officer
Cyber Security DORA Control Officer

Decskill • Lisboa

Presencial
EUR 40 000 - 70 000
Compliance Analyst
Compliance Analyst

PrimeIT • Portugal

Híbrido
EUR 13 000 - 17 000