Key Responsibilities
GRC Program Management: Own the end-to-end management of SOC 2 Type II and ISO 27001, driving continuous readiness rather than point-in-time audits.
Vanta: Utilise the Vanta platform to automate evidence collection, map security controls, and monitor system compliance in real-time.
AI Governance & Compliance: Implement security controls for AI systems (aligned with frameworks), ensuring transparency, safety, and fairness in AI model deployment.
Control Implementation: Proactively identify compliance gaps and remediate deficiencies
Vendor Risk Management: Oversee the Third-Party Risk Management (TPRM) process, using Vanta to conduct vendor assessments and security questionnaire automation.
Stakeholder Collaboration: Partner with engineering and executive leadership to align technical practices with security policies, ensuring audit preparedness.
Evidence Collection: Maintain audit-ready documentation in Vanta,
including policies, risk registers, and system logs.
Required Skills & Qualifications
Experience: Experience in GRC, Information Security, or IT Audit.
Framework Knowledge: Deep understanding of ISO 27001 and SOC 2 requirements and AI.
AI Knowledge: Demonstrated experience applying security controls to AI-assisted workflows, including evaluating AI risks, monitoring for AI drift, or managing data privacy in AI models.
Vanta Proficiency: Experience in Vanta and utilising Vanta's AI features.
Technical Acumen: Ability to translate complex compliance requirements into actionable engineering and operational controls.
Communication: Excellent written and verbal skills, comfortable presenting to auditors and executives.