Job Drop BerlinYOUR WAY INTO BERLIN TECH
NewsletterLinkedIn
AboutTermsImpressumPrivacy
Browse jobs
Engineering jobs in BerlinProduct jobs in BerlinDesign jobs in BerlinMarketing jobs in BerlinSales jobs in BerlinData jobs in BerlinOperations jobs in BerlinFinance jobs in BerlinCustomer success jobs in BerlinPeople & HR jobs in BerlinEnglish-speaking jobs in BerlinRemote jobs at Berlin startupsStartup internships in Berlin

Senior GRC Analyst (m,f,x)

HHelloFresh
Seniority
Senior
Model
Hybrid
Sector
Consumer
Salary
Undisclosed
Contract
Full-Time

Support the implementation and ongoing maintenance of information security compliance and certification programs, working with cross-functional internal teams and external auditing agencies. The person will also support data protection, data privacy, and third-party vendor risk management functions.

What you'll do

  • Lead end-to-end compliance readiness for NIS2 and support alignment across other key frameworks (e.g., PCI DSS, CSRD, ISO/SOC and EU AI Act).
  • Plan and execute internal control assessments and coordinate external compliance audits on a defined cadence.
  • Translate regulatory requirements into practical controls; drive cross-functional implementation across international teams.
  • Own remediation management: track findings, evidence, owners, deadlines, and report status to stakeholders.
  • Improve GRC maturity through continuous monitoring, clear documentation, and mentoring junior team members.
  • Evaluate and validate the design and operational effectiveness of security policies, standards, and internal controls to help reduce compliance risk in the company.
  • Develop comprehensive and accurate reports and presentations on the compliance landscape for both technical and executive audiences.

What you'll need

  • 3+ years' experience in performing compliance activities in a corporate environment related to IT General Controls (ITGC), SOC 2, ISO 27001, PCI DSS, EU NIS2, and various data privacy directives (GDPR, CCPA/CPRA, etc.)
  • Ability to interpret compliance regulations and map them to the actual implementation of systems, whilst referencing various security frameworks.
  • Experience supporting data privacy regulations (GDPR, CCPA) and third-party risk management programs.
  • Experience with developing and executing security awareness programs and trainings.
  • Highly organized and detail-oriented, with an ability to work independently.

Nice to have

  • Industry compliance certifications (CISA, CISM, CISSP).
  • Prior experience working in a SaaS environment, mainly Cloud and AWS-based.

What they offer

  • Competitive compensation package with HelloFresh-subsidized Pension Scheme and Berlin relocation support.
  • Hybrid working model.
  • Exclusive discounts on HelloFresh box and office meals.
  • German language learning budget and access to HelloFresh Academy.
  • Mental health support, transportation perks, 24/7 gym access, wellbeing platforms, and sabbatical leave options.
APPLY →

ABOUT HELLOFRESH

Consumer · Public stage

10,000+ employees

51 more open roles at HelloFresh

This role is English-speaking — no German required.

SIMILAR ROLES THIS WEEK

More roles like this, every Thursday →

No spam. Unsubscribe anytime.