GRC Specialist

Papaya Global

Connecticut

On-site

USD 110,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Papaya Global is actively seeking a GRC Specialist to lead security compliance programs, own audits (SOC 2 Type I/II, ISO 27001), and drive DORA implementation across the organization. You will respond to customer security questionnaires and support due diligence requests, while collaborating with R&D, IT, Legal and Sales to embed robust security practices.

You will develop policies, perform risk assessments, and manage remediation efforts, leveraging AI tools to improve efficiency and maintain

Qualifications

  • 4+ years of hands-on experience in GRC or information security.

Responsibilities

  • Lead SOC 2 Type I/II and ISO 27001 audits and ongoing compliance activity.
  • Oversee DORA compliance across the organization.
  • Own responses to customer security questionnaires and due diligence requests.
  • Conduct risk assessments and develop risk treatment plans.
  • Develop and maintain information security policies and guidelines.
  • Perform internal audits and gap analyses against frameworks.
  • Collaborate with R&D, IT, Legal and Sales to embed security practices.
  • Monitor remediation of identified risks and gaps.
  • Support vendor and third-party risk management.
  • Leverage AI tools to streamline compliance workflows and audit prep.
  • Map controls across SOC 2, ISO 27001, DORA in a controlled manner.

Skills

GRC
Information security
SOC 2 Type I/II
ISO 27001
DORA
Security questionnaires
Risk assessment
Policy development
Vendor risk management
English proficiency
Cross-functional collaboration
AI in compliance

Education

Bachelor's degree in Information Technology / Information Systems / Computer Science

Tools

AI compliance tools

Job description

Papaya Global is a rapidly growing, award-winning B2B tech unicorn with an ambitious mission to revolutionize the payroll & payments industry. With over $400M raised from multiple tier-one investors, our innovative technology provides a comprehensive solution for managing global workforces, encompassing everything from hiring and onboarding to managing and paying employees in over 160 countries.

We are seeking a GRC Specialist to join the Security group, reporting to the GRC Manager. We are looking for a team player, independent and responsible person, quick learner, who wants to work in a challenging and dynamic environment.

You will:
  • Lead and manage information security compliance programs, including SOC 2 Type I/II and ISO 27001 audits, certifications, and ongoing compliance activities.
  • Support the implementation and maintenance of DORA (Digital Operational Resilience Act) compliance requirements across the organization.
  • Own the end-to-end process of responding to customer security questionnaires, RFPs, and third-party due diligence requests.
  • Conduct risk assessments and help develop risk treatment plans to address identified gaps.
  • Develop, review, and maintain information security policies, standards, procedures, and guidelines.
  • Perform internal audits and gap analyses against regulatory frameworks and industry best practices.
  • Collaborate with cross-functional teams (R&D, IT, Legal, Sales) to embed security and compliance practices across the organization.
  • Monitor and track the remediation of identified risks and compliance gaps.
  • Support vendor and third-party risk management processes, including periodic risk assessments and ongoing monitoring.
  • Leverage AI-enabled tools to streamline compliance workflows, including analysis of security controls, drafting and refinement of compliance documentation, and support in audit preparation and evidence collection.
  • Use AI-assisted capabilities to improve efficiency and accuracy in responding to security questionnaires, risk assessments, and regulatory documentation while maintaining strict compliance and traceability standards.
  • Apply AI tools to support knowledge management, policy drafting, and cross-framework mapping (SOC 2, ISO 27001, DORA) in a controlled and auditable manner.
  • 4+ years of hands‑on experience in GRC, information security compliance, or a related field.
  • Proven experience managing SOC 2 Type I/II audits and certification processes.
  • Hands‑on experience with ISO 27001 implementation and/or certification audits.
  • Familiarity with DORA (Digital Operational Resilience Act) requirements and their practical application.
  • Experience handling customer security questionnaires and due diligence requests – Must.
  • Strong knowledge of information security risk management methodologies and frameworks.
  • Experience working with cross‑functional stakeholders and translating compliance requirements into actionable steps.
  • Highly proficient in spoken and written English.
  • Team player, detail‑oriented, with strong organizational and communication skills – Must.
  • Experience in a SaaS or B2B tech company – Advantage.
  • Degree in Information Technology / Information Systems / Computer Science – Advantage.
  • Hands‑on experience in leveraging AI tools to support compliance operations, including documentation, audit preparation, risk analysis, questionnaire handling, and policy development workflows.
  • Practical experience using AI‑assisted tools to enhance accuracy, efficiency, and consistency in governance, risk, and compliance processes while ensuring adherence to regulatory and audit requirements.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Specialist: AI-Driven Security & Compliance Lead
GRC Specialist: AI-Driven Security & Compliance Lead

Papaya Global • Connecticut

On-site
USD 110,000 - 170,000
Senior Governance, Risk, & Compliance Analyst
Senior Governance, Risk, & Compliance Analyst

Jobgether • United States

On-site
USD 58,000 - 222,000
Medical, dental, vision insurance
Flexible work environment
Paid time off
+1
Principal Security GRC Analyst
Principal Security GRC Analyst

Jobgether • United States

On-site
USD 150,000 - 210,000
High autonomy
Multi-framework exposure
Cloud environment experience
GRC Analyst
GRC Analyst

New York Technology Partners • Chicago (IL)

On-site
USD 65,000 - 90,000
GRC Specialist
GRC Specialist

Quanta • United States

Remote
GBP 90,000 - 130,000
Fully remote work environment
GRC Analyst
GRC Analyst

Glocomms • Dallas (TX)

Hybrid
USD 90,000 - 150,000
Competitive base salary
Annual bonus
Comprehensive medical, dental, and eye
+2
Director, GRC & Privacy Security
Director, GRC & Privacy Security

Jobtailor • New York (NY)

On-site
USD 130,000 - 160,000
Competitive salary & equity
Unlimited PTO
Full Health, Vision, & Dental coverage
+2
Senior Information Security Engineer
Senior Information Security Engineer

SmartRecruiters Inc • Town of Poland (NY)

Hybrid
USD 110,000 - 150,000
Competitive salaries
Remote-friendly culture
Strong internal mobility
GRC Consultant-68498
GRC Consultant-68498

Hitachi Digital Services • Town of Texas (WI)

On-site
USD 110,000 - 150,000
IT Security GRC Analyst
IT Security GRC Analyst

The Phoenix Group • Charlotte (NC)

On-site
USD 85,000 - 120,000