GRC Specialist (German-speaking)
Secfix
Seniority
Midweight
Model
Remote
Sector
Salary
Undisclosed
Contract
Full-Time
```html
About the role
GRC Specialist to strengthen Secfix's compliance function as we scale into more frameworks, mid-market customers, and a growing compliance team. This role sits at the intersection of compliance delivery, content, and team support. You'll own the compliance knowledge that lives inside our platform, run internal audits, support our customer success team, and act as the compliance voice for customers, auditors, and product.
What you'll do
- Build and maintain compliance frameworks in the Secfix platform (ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 42001, C5, and more as we expand)
- Own internal audits for our customers end to end, from kickoff through to the final report they take into their external audit
- Keep several audits moving at once and keep every one on schedule
- Implement ISO 27001 and adjacent frameworks end-to-end for customers
- Own the quality of compliance content in the platform (including creating policies, automated checks, evidence templates, Compliance enable playbooks for our CSMs, security awareness trainings and more)
- Close framework gaps and incorporate auditor feedback into both team practice and platform improvements
- Partner with product and engineering to translate compliance gaps into structured product work
- Collaborate closely with CS, Product, and Founders to align compliance, customer, and roadmap priorities
What you'll need
- German (C1/C2) and English (fluent)
- 3+ years of hands-on information security and GRC experience
- Led at least 1 successful ISO 27001 certification projects as an implementer and/or auditor at a startup or mid-market company
- Run at least 2 internal audits before
- Hands on experience with a GRC platform like Secfix, or similar GRC platforms
- Real depth in at least one framework beyond ISO 27001 (TISAX, SOC 2, GDPR, NIS2, or similar)
- Strong project management skills with the ability to break down ambiguous initiatives into concrete deliverables, prioritizes ruthlessly, and ships
- Bachelor's degree in computer science, software engineering, or a related technical field, or equivalent hands-on technical experience
Nice to have
- Experience mentoring or coaching colleagues in a compliance, audit, or GRC context
- Experience in a startup environment
- PECB ISO 27001 Lead Auditor certification or direct equivalent
What they offer
- 100% remote work with a virtual office in Gather
- Industry-competitive local salaries at or above market
- Generous equity package
- €1,000 annual personal development budget
- 26 days holiday + local public holidays
- Comprehensive health insurance, home office budget, annual retreat, latest tech equipment

