At a Glance
- Tasks: Join our GRC team to enhance cybersecurity and manage third-party risks.
- Company: Innovative AI startup with a collaborative culture and experienced leadership.
- Benefits: Private health insurance, flexible work, 25 days leave, and pension.
- Other info: Opportunities to mentor students in underserved communities through our nonprofit.
- Why this job: Make a real impact on cybersecurity while working with cutting-edge technology.
- Qualifications: 3+ years in compliance or cybersecurity, strong communication skills, and proactive mindset.
The predicted salary is between 50000 - 65000 € per year.
We are looking for an experienced software-as-a-service (SaaS) security practitioner to join our growing Governance, Risk & Compliance (GRC) team. This role will primarily take ownership of our security hardening standards and our Third-Party Risk Management (TPRM), focusing on proactive improvements in cybersecurity, ensuring audit readiness, and scaling GRC processes through automation.
This is a high-impact role suited to someone who wants to influence cybersecurity at scale, enjoys working cross-functionally, and is able to balance strong risk management with commercial pragmatism. You will work closely with operational stakeholders across the organization, helping strengthen our overall security posture, including vendor assurance, while enabling the business to move safely and quickly.
Responsibilities:
- Provide hands-on support in the assessment, improvement, and maintenance of technical security baselines based on industry best practices (e.g., NIST, CIS, ISO). Ensure these configurations satisfy global regulatory mandates (e.g., HIPAA, GDPR). Leverage automated tools to monitor security and compliance posture.
- Act as a GRC interface with Infrastructure and Engineering teams to ensure hardening requirements are technically feasible and effectively implemented.
- Manage and continuously improve the company’s Third-Party Risk Management programme across suppliers, vendors and strategic partners.
- Own end-to-end due diligence processes for new and existing vendors, including inherent risk assessments, security/privacy reviews and ongoing monitoring.
- Review vendor assurance documentation such as ISO 27001 certificates, SOC 2 reports, penetration test summaries, policies and compliance evidence.
- Identify, document and communicate vendor risks, remediation actions and approval recommendations.
- Maintain risk tiering and reassessment schedules for critical and high-risk vendors.
- Act as a trusted partner to internal stakeholders during vendor onboarding, renewals and procurement decisions.
- Engage directly with suppliers to resolve due diligence issues and drive remediation.
- Maintain audit-ready documentation within GRC systems.
- Support team members as necessary with global and contractual compliance efforts, as well as internal and external audits.
- Contribute to security and compliance policy, process, and control improvements.
- Identify opportunities for automation, simplification, and improved GRC tooling.
What success looks like in the first 12 months:
- Strong audit readiness with high-quality, reliable technical evidence.
- Effective use of GRC tooling to automate and streamline compliance processes.
- Mature and efficient Third-Party Risk Management workflows.
- Improved turnaround times for vendor assessments and internal requests.
- Clear visibility of cybersecurity control effectiveness and risk posture.
- Reduced manual effort through automation and improved processes.
Requirements:
Essential
- 3+ years’ experience in compliance, GRC, vendor risk management, information security, internal audit or related fields.
- Proven experience in cybersecurity and managing third-party/vendor due diligence programmes.
- Strong understanding of common assurance frameworks such as ISO 27001, SOC 2, NIST or equivalent.
- Good working knowledge of UK GDPR / privacy considerations in supplier relationships.
- Familiarity with cloud/SaaS environments and common systems (e.g. identity providers, cloud platforms, collaboration tools).
- Experience reviewing supplier security documentation and identifying practical risks.
- Strong organisational skills with the ability to manage multiple priorities independently.
- Excellent written and verbal communication skills; proficient in English.
Desirable
- SaaS / software industry experience.
- Experience in a multi-entity or fast-growth business environment.
- Familiarity with Vanta or other GRC tools.
- Relevant certifications (e.g. ISO 27001 Lead Implementer/Auditor, CISM, CRISC, CIPM, CIPP/E).
You are motivated by:
- Hustle: You inspire others to work as hard as you. You will find a way, no matter how hard the task is.
- Ownership: You have an owner/builder mentality. You care about what you deliver and own your mistakes.
- Proactivity: You don’t wait for someone to tell you what to do or what problems to solve. You are always looking for ways to learn and improve.
- Excellence: You set a high bar and surpass expectations. You hit your goals and ask for more.
- Humility: You are not above any task in the organization and are willing to drop what you’re doing to help a teammate.
What you can expect from us:
The team: Capacity team members enjoy the opportunity and benefits of working at an artificial intelligence startup, but with leaders who’ve worked at places like Apple, Ebay, Visa, Answers.com, Oracle, Boeing, and many more world-class companies. The culture at Capacity encourages innovation, independent problem solving, and collaboration as we continue to mature our product in the ever-changing world of AI.
We provide:
- Private health insurance
- Profit Interest Unit Appreciation Rights
- 25 days paid leave
- Pension
- Group life assurance
- Group income protection
- Flexible work environment
- A supportive, diverse workplace where we prioritize respect for each other and our clients
- A fun and collaborative team culture
Salary range: The expected base salary for the Technical GRC Specialist role is between £50,000 and £65,000; actual salary will be commensurate with a candidate's experience, skill and location.
Still unsure? At Capacity we value more than just hard skills. Our goal is to build a holistic and diverse team. If you aren’t sure if you qualify, just apply! We will carefully consider your application and are always grateful for any time and effort invested in Capacity.
But wait, there’s more! At Capacity we believe in more than just building amazing products and helping our customers. Although we are a remote workforce, we remember the neighborhood where we started. We still strive to elevate our community by furthering access to education and careers in the tech space. Our affiliated nonprofit, Create A Loop, brings rigorous computer science courses to underserved communities with little to no access to formal computer science education. There are many opportunities for our Capacity team members to serve and educate our Create A Loop students throughout the year.
Technical GRC Specialist employer: CAPACITY
At Capacity, we pride ourselves on being an exceptional employer that fosters a culture of innovation and collaboration within the fast-paced world of artificial intelligence. Our team enjoys a flexible work environment, comprehensive benefits including private health insurance and generous paid leave, and ample opportunities for personal and professional growth. Join us in making a meaningful impact not only in cybersecurity but also in our community through initiatives like Create A Loop, where we empower underserved individuals with access to tech education.
StudySmarter Expert Advice🤫
We think this is how you could land Technical GRC Specialist
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their GRC processes and be ready to discuss how your experience aligns with their needs. Show them you’re not just another candidate, but someone who genuinely cares about their mission.
✨Tip Number 3
Practice your pitch! Be clear about your skills and how they relate to the Technical GRC Specialist role. Highlight your experience with compliance frameworks and vendor risk management, and don’t forget to share examples of your past successes.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re serious about joining our team. Don’t hesitate to follow up after applying; it shows initiative and enthusiasm!
We think you need these skills to ace Technical GRC Specialist
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter for the Technical GRC Specialist role. Highlight your experience in compliance, vendor risk management, and any relevant frameworks like ISO 27001 or NIST. We want to see how your skills align with what we're looking for!
Showcase Your Experience:When detailing your past roles, focus on specific achievements that demonstrate your expertise in cybersecurity and GRC processes. Use metrics where possible to show the impact of your work. This helps us understand the value you can bring to our team.
Be Authentic:Let your personality shine through in your application. We appreciate candidates who are genuine and passionate about their work. Share your motivations and what excites you about the role and our mission at StudySmarter.
Apply Through Our Website:We encourage you to submit your application directly through our website. This ensures it reaches the right people quickly and gives you a chance to explore more about our culture and values while you're at it!
How to prepare for a job interview at CAPACITY
✨Know Your GRC Basics
Make sure you brush up on your knowledge of Governance, Risk & Compliance frameworks like ISO 27001 and NIST. Be ready to discuss how these frameworks apply to the role and how you've used them in past experiences.
✨Showcase Your Technical Savvy
Since this role involves security hardening and vendor risk management, be prepared to talk about specific tools and technologies you've worked with. Mention any experience with automation tools that streamline compliance processes, as this will show you're proactive and tech-savvy.
✨Prepare for Scenario Questions
Expect questions that ask you to solve hypothetical problems related to third-party risk management or audit readiness. Think through some scenarios beforehand and outline how you would approach them, focusing on your problem-solving skills and attention to detail.
✨Demonstrate Your Communication Skills
This role requires collaboration across teams, so be ready to highlight your communication skills. Share examples of how you've effectively communicated complex security concepts to non-technical stakeholders, showcasing your ability to bridge gaps between technical and operational teams.