About the company
At Preply, we’re all about creating life-changing learning experiences. We help people discover the magic of the perfect tutor, craft a personalised learning journey, and stay motivated to keep growing. Our approach is human-led, tech-enabled - and it’s creating real impact. We’ve just reached unicorn status with a $150M Series D, accelerating our vision to transform education through human-led, AI-enhanced learning. Today, 100,000+ tutors teach 90+ languages to learners in 180 countries - and we’re only getting started. As a category-defining company, we’re shaping what the future of learning looks like at global scale.
Responsibilities
- Maintain and continuously improve the risk management framework.
- Lead risk assessments. Run enterprise risk assessments, surfacing both technical and non-technical risks, and track Key Risk Indicators (KRIs) and other data-driven risk metrics to report to leadership.
- Manage third-party risk. Maintain a third-party risk management program and perform periodic vendor reviews to ensure suppliers meet Preply's security bar.
- Help shape governance and policy. Participate in developing and maintaining security, AI, and compliance policies in collaboration with Legal, Security, and Data teams, embedding governance checks into everyday business operations.
- Drive SOC 2 and beyond. Support compliance initiatives for SOC 2 Type 2, with potential expansion to ISO 27001, ensuring controls are documented, tested, and audit-ready.
- Support privacy initiatives. Contribute to data retention policies and guidelines for how different departments handle personal data.
- Be the cross-functional bridge. Support coordination between Cybersecurity, Legal, and Engineering - translating regulatory requirements (GDPR, CCPA, etc.) into actionable policies, and supporting internal/external audits, policy reviews, and compliance syncs.
- Champion security culture. Drive security awareness and compliance culture across the company.
- Automate GRC operations. Identify opportunities to use AI tools to automate and streamline risk and compliance workflows (e.g. evidence collection, control monitoring, reporting).
Requirements
- 5+ years in GRC, risk management, compliance, or cybersecurity - preferably in a tech or SaaS environment.
- A flexible background, which could include: Engineering or technical roles with exposure to platform risk/security; Legal or compliance roles, ideally with a specialization in cybersecurity or privacy; Hybrid profiles (e.g., lawyers with CISSP, or engineers with compliance experience).
- A proven track record in: SOC 2 implementation (must-have); Experience with frameworks/standards such as ISO 27001, ISO 27701, PCI DSS, or similar; Experience with regulations such as GDPR, CCPA, COPPA, EU AI Act, or similar; Risk assessments and KRIs; Cross-functional collaboration and stakeholder management.
- Core Competencies: Strong understanding of cloud security and modern SaaS risk landscapes; Ability to translate regulatory requirements into practical, business-friendly policies; Effective communicator with experience in running cross-functional sessions; Practical experience applying AI tools in day-to-day work; Experience with GRC/compliance automation tooling is a plus.
- Certifications (nice to have, not required): CISA, CISM, CISSP, CRISC, ISO 27001 Lead Auditor, CIPM.
Conditions
- An open, collaborative, dynamic and diverse culture
- A generous monthly allowance for lessons on Preply.com, Learning & Development budget and time off for your self-development
- A competitive financial package with equity, leave allowance and health insurance
- Access to free mental health support platforms
- The opportunity to shape the lives of learners and tutors through language learning and teaching in 175 countries (and counting!)