← Все вакансии/Senior/preply
SeniorFlexibleLondon

GRC Analyst

P
preply
Уровень
Senior
Формат
Flexible
О роли

Описание вакансии

About the company

At Preply, we’re all about creating life-changing learning experiences. We help people discover the magic of the perfect tutor, craft a personalised learning journey, and stay motivated to keep growing. Our approach is human-led, tech-enabled - and it’s creating real impact. We’ve just reached unicorn status with a $150M Series D, accelerating our vision to transform education through human-led, AI-enhanced learning. Today, 100,000+ tutors teach 90+ languages to learners in 180 countries - and we’re only getting started. As a category-defining company, we’re shaping what the future of learning looks like at global scale.

Responsibilities
  • Maintain and continuously improve the risk management framework.
  • Lead risk assessments. Run enterprise risk assessments, surfacing both technical and non-technical risks, and track Key Risk Indicators (KRIs) and other data-driven risk metrics to report to leadership.
  • Manage third-party risk. Maintain a third-party risk management program and perform periodic vendor reviews to ensure suppliers meet Preply's security bar.
  • Help shape governance and policy. Participate in developing and maintaining security, AI, and compliance policies in collaboration with Legal, Security, and Data teams, embedding governance checks into everyday business operations.
  • Drive SOC 2 and beyond. Support compliance initiatives for SOC 2 Type 2, with potential expansion to ISO 27001, ensuring controls are documented, tested, and audit-ready.
  • Support privacy initiatives. Contribute to data retention policies and guidelines for how different departments handle personal data.
  • Be the cross-functional bridge. Support coordination between Cybersecurity, Legal, and Engineering - translating regulatory requirements (GDPR, CCPA, etc.) into actionable policies, and supporting internal/external audits, policy reviews, and compliance syncs.
  • Champion security culture. Drive security awareness and compliance culture across the company.
  • Automate GRC operations. Identify opportunities to use AI tools to automate and streamline risk and compliance workflows (e.g. evidence collection, control monitoring, reporting).
Requirements
  • 5+ years in GRC, risk management, compliance, or cybersecurity - preferably in a tech or SaaS environment.
  • A flexible background, which could include: Engineering or technical roles with exposure to platform risk/security; Legal or compliance roles, ideally with a specialization in cybersecurity or privacy; Hybrid profiles (e.g., lawyers with CISSP, or engineers with compliance experience).
  • A proven track record in: SOC 2 implementation (must-have); Experience with frameworks/standards such as ISO 27001, ISO 27701, PCI DSS, or similar; Experience with regulations such as GDPR, CCPA, COPPA, EU AI Act, or similar; Risk assessments and KRIs; Cross-functional collaboration and stakeholder management.
  • Core Competencies: Strong understanding of cloud security and modern SaaS risk landscapes; Ability to translate regulatory requirements into practical, business-friendly policies; Effective communicator with experience in running cross-functional sessions; Practical experience applying AI tools in day-to-day work; Experience with GRC/compliance automation tooling is a plus.
  • Certifications (nice to have, not required): CISA, CISM, CISSP, CRISC, ISO 27001 Lead Auditor, CIPM.
Conditions
  • An open, collaborative, dynamic and diverse culture
  • A generous monthly allowance for lessons on Preply.com, Learning & Development budget and time off for your self-development
  • A competitive financial package with equity, leave allowance and health insurance
  • Access to free mental health support platforms
  • The opportunity to shape the lives of learners and tutors through language learning and teaching in 175 countries (and counting!)
Стек и навыки

С чем работаем