Source Job

Europe 4w PTO

  • Lead and develop the Information Security GRC strategy, roadmap, operating model, and governance cadence.
  • Coordinate SOC 2, DORA/CySEC-related assurance, internal and external audits, and regulatory requests.
  • Build, develop, and manage the GRC team and improve GRC efficiency through automation and reusable evidence.

SOC 2 ISO 27001 Stakeholder Management

20 jobs similar to Information Security Governance, Risk & Compliance Manager Europe

Jobs ranked by similarity.

Europe

  • Act as Information Security Officer for FinTech, supporting ISO 27001, SOCv2, and DORA implementation.
  • Coordinate security activities across teams, ensuring alignment with cyber security strategy and governance.
  • Track risks, gaps, and remediation, while preparing updates for security leadership.

Coinspaid Dev is the engineering brand behind the technology and infrastructure built within Coinspaid. With over 120 engineers and 11 years of industry experience, the team builds distributed systems and blockchain infrastructure across more than 20 blockchain networks.

United States Unlimited PTO

  • Own and strengthen the controls environment, ensuring compliance requirements are effectively implemented and maintained.
  • Support and mature the GRC program, including SOC 2 operations and alignment with frameworks such as NIST.
  • Manage vendor risk assessments, regulatory licensing, and security issue lifecycle across jurisdictions.

Mesh enables consumers to pay and be paid with any asset, bridging crypto payments into everyday commerce. Backed by investors like PayPal Ventures and Paradigm, the company is building infrastructure for the global economy with a small, fast-moving team.

Canada

  • Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
  • Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
  • Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.

Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.

Global 5w PTO

  • Automate governance, risk, and compliance frameworks including ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials.
  • Engineer GRC workflows with internal systems to support compliance by design.
  • Translate compliance requirements into technical specifications for engineering teams and non-technical stakeholders.

Pleo builds spend solutions that make managing money seamless for finance teams and employees. They are a driven, progressive team of 850+ people from over 100 nationalities, committed to delivering the future of business spending.

$100,000–$130,000/yr
Global

  • Take ownership of information security governance, including policies, risk registers, and control documentation.
  • Manage day-to-day security program operations, mentor analysts, and coordinate cross-functional initiatives.
  • Lead incident response, compliance support, and serve as primary counterpart to the vCISO.

Aries is a financial technology company building modern infrastructure and products for active investors and traders. As a growing organization, they are investing in a practical, accountable security program deeply integrated into how the company operates.

$150,000–$200,000/yr
US

  • Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
  • Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer-facing discussions and security due diligence reviews.

Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.

Germany

  • Own and build the group-wide ISMS following BSI standards and ISO 27001 certification.
  • Manage risk, incident response, and security awareness across technical and organizational domains.
  • Work hands-on with IT and engineering teams, ensuring security governance and regulatory compliance.

Vektor Group builds AI platforms for customers in the defence and government sector. It is a startup with flat hierarchies, real ownership, and fast decisions.

  • Build and lead the Cyber GRC function, including policy, NIST/CIS/ISO frameworks, and regulatory compliance.
  • Manage vendor risk and security assessments across the vendor lifecycle.
  • Drive security awareness, AI governance, and quantified cyber risk reporting.

Mariner is a leading financial services firm providing wealth management and advisory solutions to individuals and institutions. The company fosters a collaborative, innovative culture focused on professional growth, diversity, and work-life balance.

$80,208–$83,372/yr
Poland

  • Lead the design, implementation, and maintenance of Hyland's enterprise ISO governance and certification program across multiple certifications, business units, and regions.
  • Drive strategic expansion of ISO scope, including advanced certifications like TISAX and C5, and establish governance models and control ownership across teams.
  • Measure and report ISO program health through metrics, dashboards, and reporting, while providing leadership and mentorship to compliance specialists.

Hyland is the pioneer of the Content Innovation Cloud, delivering enterprise intelligence through solutions that unlock actionable insights and drive automation. Trusted by thousands of organizations worldwide, including many Fortune 100 companies, Hyland has nearly 4,000 employees and fosters an employee-centric, inclusive culture.

Germany

  • Drive end-to-end execution of GRC programs, leading audit strategy and cross-functional compliance projects.
  • Manage internal risk workflows, evidence collection, and remediation efforts for audits like SOC 2 and PCI DSS.
  • Translate regulatory requirements into actionable business processes and enable engineering teams to embed security controls.

They are a global leader in event ticketing technology, transforming ticketing for major events like the Grammys and Golden Globes. With over 160 employees and six offices worldwide, they have received over $65 million in funding and are known for their fast-growing, merit-driven culture.

US Unlimited PTO

  • Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
  • Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
  • Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.

$102,500–$102,500/yr
US Unlimited PTO

  • Own GRC workstreams from initial request through evidence collection, testing, and remediation.
  • Test security controls and conduct risk assessments to identify gaps and drive realistic remediation.
  • Support audits, vendor reviews, customer questionnaires, and policy maintenance across teams.

YipitData is a leading market research and analytics firm for the disruptive economy, providing actionable insights from alternative data. The company has a global presence with offices in the US, APAC, and India, and is recognized as an Inc. Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.

US

  • Design and implement an end-to-end Enterprise Cybersecurity Risk Register.
  • Lead governance lifecycle, establish risk ownership, and drive cross-functional stakeholder alignment.
  • Deliver audit-ready documentation and ensure post-contract sustainability through structured knowledge transfer.

ASSYST is a technology consulting firm that provides staffing and solutions. The company seeks to place experienced professionals in client engagements, though size and culture are not specified.

$128,270–$189,230/yr
UK

  • Lead and coordinate second-line regulatory compliance and privacy oversight activities for the UK entity, serving as the operational lead for UK privacy compliance and Data Protection Officer.
  • Translate legal and regulatory requirements into compliance standards, governance routines, and oversight expectations for first-line stakeholders.
  • Prepare management reporting, governance materials, and issue summaries, and support audits and regulatory enquiries.

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. They are a remote-first company with a focus on inclusive culture and competitive benefits.

$135,000–$145,000/yr
Global

  • Own the IT evidence program across ISO 27001, SOC 1, SOC 2, PCI DSS, and HIPAA for approximately 13 operating sites, managing audits and remediation.
  • Manage vulnerability management end to end, oversee endpoint detection and response, and lead security incident response through to conclusion.
  • Contribute to identity governance across a hybrid cloud and on-premises IdP, overseeing access review and privileged access controls.

Serverfarm is a leading developer and operator of data centers with over 750 locations and key customer relationships in 45 countries. With Manulife Investment Management's acquisition in 2023, the company is positioned for explosive growth and offers a culture of innovation and career development.

Global Unlimited PTO

  • Own and mature the compliance framework, including continuous controls monitoring, security awareness, and audit coordination.
  • Automate GRC processes using compliance platforms and AI tooling for evidence collection and risk management.
  • Develop policies, manage third-party risk, and scale customer security assurance end-to-end.

Monarch is an all-in-one personal finance platform that simplifies finances. Since 2021, they have become the top-recommended app, with a fully remote, AI-driven team focused on building a product people love.

US

  • Own end-to-end audit evidence collection and validation across multiple compliance frameworks including FedRAMP, ISO 27001, and SOC 2.
  • Maintain and continuously verify technical controls across GCP, GitHub, and Microsoft 365 environments.
  • Serve as the primary liaison between GRC and technical teams to reduce audit burden and ensure continuous audit readiness.

A-LIGN is a leading provider of cybersecurity compliance programs, offering services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. They are the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor, operating in a high-growth, PE-backed environment.

Germany

  • Act as central contact for information security in the business group, working with development teams and customers.
  • Implement local ISMS, conduct risk analyses and security reviews.
  • Collaborate with corporate security and advise on practical security requirements.

Haufe provides digital research systems and software solutions, making complex professional knowledge easily applicable for over one million customers. It is a Great Place to Work® with cross-functional teams across Germany, Romania, and Spain.

Global

  • Manage the Compliance and Security workstream, coordinating SOC 2, ISO 27001, GDPR, and related audit-readiness activities.
  • Build and maintain execution plans with clear owners, milestones, dependencies, risks, and decision points.
  • Facilitate workshops, track evidence, and escalate risks to keep audits on schedule.

Miratech is a global IT services and consulting company that helps visionaries change the world through digital transformation. With nearly 1000 full-time professionals across 25+ countries, the company maintains a culture of Relentless Performance and has achieved over 99% project success since 1989.

Global

  • Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
  • Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
  • Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.

Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.