Skip to content
← Back to job listings

GRC Program Manager

Aily Labs · Madrid, Spain

External listingfull-time2 months ago

About The Role

Join our team as a GRC Program Manager, where you will own a defined set of compliance, risk, and security operations frameworks end-to-end. You will be responsible for stakeholder coordination, conceptual design, and managing external auditor relationships. Your role will extend beyond traditional GRC into the program and organizational aspects of Security Operations. You will design how regulatory requirements translate into concrete controls, enable control owners to be self-sufficient, and leverage AI and automation to streamline compliance work.

  • Posséder un ensemble défini de cadres de conformité, de risque et d'opérations de sécurité, en coordonnant les parties prenantes et en concevant comment ces cadres s'appliquent à l'environnement de l'entreprise.
  • Agir en tant que point de contact unique pour les cadres de conformité assignés, en gérant les relations avec les auditeurs externes et en anticipant les changements réglementaires.
  • Concevoir et maintenir des flux de travail automatisés pour la collecte de preuves, la surveillance et le reporting, en identifiant continuellement les domaines où l'effort humain peut être remplacé par l'automatisation.
  • Experience managing external auditor relationships and driving audits to completion independently
  • Experience: 4+ years in GRC, compliance, security operations, or audit roles, with demonstrated experience owning at least one compliance framework or security operations program end-to-end (scoping, control design, audit coordination, certification)
  • Experience configuring GRC platforms and designing automated compliance workflows— you think in systems, not spreadsheets
  • Strong stakeholder management skills—you can coordinate across technical and non-technical teams, hold people accountable, and resolve conflicts without escalation
  • Strong written communication—you can author policies and reports that are clear, concise, and actionable for their intended audience
  • Experience in cloud-native environments (AWS preferred) with an understanding of how infrastructure choices affect compliance scope
  • Ability to design control mappings and assessment methodologies, not just execute predefined checklists
  • AI-First Mindset: You leverage AI tools daily as a core part of how you work. You don’t wait to be told where to automate—you actively seek to eliminate routine work from your programs so you can focus on the hard problems that require human judgment
  • Deep knowledge of governance frameworks (ISO 27001, SOC 2) and data privacy regulations (GDPR, CCPA), with the ability to interpret requirements and design practical control implementations
  • Comfort with ambiguity: you can make sound judgment calls when regulatory guidance is unclear or when business context requires interpretation
  • Certifications such as CISA, CRISC, CIPP/E, or ISO 27001 Lead Auditor/Implementer
  • Experience with emerging AI regulations (EU AI Act, ISO 42001) and building governance approaches for AI/ML systems
  • Background in high-growth SaaS or platform companies where compliance programs had to scale quickly
  • Experience building or significantly maturing a GRC program—not just inheriting a fully built one
  • Experience with security operations frameworks—incident response lifecycle, detection engineering governance, or SOC program management
  • Familiarity with security engineering practices and how compliance automation integrates with CI/CD and infrastructure-as-code

This is an external listing. JobSpring does not represent or verify the employer. Report this listing