Overview
In this role, you anchor Frontify’s security governance and GRC program, driving automation and AI-enabled processes to move from point-in-time compliance to continuous, measurable governance. You will own customer security assurance, support audits, and scale vendor risk management, partnering with stakeholders to reduce risk while enabling business growth. You’ll shape the program with modern GRC tools and AI, ensuring clear risk communication to technical and business audiences. This is a hands-on role at the intersection of security, compliance, and technology innovation.
Pay / Benefits
- Private health benefits
- Pension scheme with 5% matched
- 25 days annual leave
- Educational and wellbeing days off
- Wellbeing, learning and development support
- Work from anywhere (workation) 45 days annually
Responsibilities
- Own customer security assurance and respond to audit inquiries efficiently
- Manage and improve ISO 27001, SOC 2, TISAX programs and emerging regulations
- Serve as SME during audits and keep control environment audit-ready
- Automate evidence collection, control monitoring, and access reviews in the GRC program (Vanta-based)
- Design AI-enabled GRC workflows for policy management, risk assessments, and documentation
- Scale vendor risk assessments through automation with appropriate human review
- Contribute to security awareness by making training practical and actionable
Key requirements
- 5+ years in information security governance, GRC, or technology risk in SaaS/cloud
- Subject matter expert in SOC 2 and/or ISO 27001 audits with hands-on control work
- Experience with additional frameworks like TISAX or Microsoft SSPA is a plus
- Hands-on with GRC platforms (Vanta, Conveyor) and a bias for automation
- Strong communication of risk to technical and business audiences
- Relevant certifications (CISA, CISM, CISSP, CIPP) is a plus
- Fluent in English; German a plus
- strong communication
- entrepreneurial mindset
- collaboration across teams
- Vanta
- Conveyor
- GRC automation
…
