Pracuj.pl Hybrydowo Senior

Governance risk and compliance expert

MAGNITUDE CLOUD LECH GORLEWICZ

⚲ Gdańsk

Do uzgodnienia

Opis stanowiska

Nasze wymagania:
Experience in security compliance operations, including internal or external security compliance audits.
Hands-on GRC experience in some of the relevant frameworks (SOC 2, ISO 27001, NIST CSF, NIS2, DORA, GDPR, or others).
Great communication skills — much of the role is giving clear, structured feedback and writing down what "good" looks like.

Mile widziane:
Experience with any GRC platform (Archer, Vanta, ServiceNow, etc.).
Experience using and running cybersecurity systems (Wiz, CrowdStrike, etc.).

O projekcie:
We're building an AI-native GRC platform, and we're looking for an in-house GRC
expert to shape the development of the system and act as its internal customer
and domain quality bar. In practice, that means you're the person who makes sure
what we build is correct and defensible the way a real auditor or CISO would
judge it. This isn't a role running our own security program — it's about
bringing deep compliance expertise into the product itself, so the tool earns
the trust of the specialists who'll rely on it.

Zakres obowiązków:
Be the voice of CISOs and auditors inside the product team — represent how they actually think and work, so we build what the industry needs
Shape the platform direction according to the needs of industry specialists, helping us prioritize what matters most to real compliance teams.
Review our framework mapping crosswalks (SOC 2, ISO 27001, NIST) for correctness and defensibility — the mappings between requirements and controls are the credibility of the product, and they have to hold up under scrutiny.
Evaluate the design and logic of the system as we build it, telling us where our model matches real GRC practice and where it doesn't.
Judge the quality of our AI across different areas

🔍 Dekoder Ogłoszenia

🟡
Be the voice of CISOs and auditors inside the product team — represent how they actually think and work, so we build what the industry needs
Oczekuje się, że będziesz tłumaczyć potrzeby i perspektywę specjalistów ds. bezpieczeństwa i audytorów na język zespołu produktowego, wpływając na rozwój platformy.
🟡
This isn't a role running our own security program — it's about bringing deep compliance expertise into the product itself, so the tool earns the trust of the specialists who'll rely on it.
Twoim głównym zadaniem nie będzie zarządzanie wewnętrznym bezpieczeństwem firmy, ale wykorzystanie Twojej wiedzy do tworzenia produktu, który będzie wiarygodny dla zewnętrznych specjalistów.
🟡
act as its internal customer and domain quality bar.
Będziesz pełnił rolę kluczowego użytkownika wewnętrznego i wyznacznika jakości dla rozwijanej platformy GRC.
🟡
much of the role is giving clear, structured feedback and writing down what "good" looks like.
Znaczna część pracy polega na formułowaniu jasnych wytycznych i dokumentowaniu oczekiwań dotyczących funkcjonalności i jakości produktu.