At a Glance
- Tasks: Lead security compliance and audits while leveraging AI for efficiency.
- Company: Join Humaans, a cutting-edge HR tech startup backed by top investors.
- Benefits: Enjoy competitive pay, 25 days off, free lunches, and health coverage.
- Other info: Collaborative office culture with opportunities for personal and professional growth.
- Why this job: Make a real impact in a fast-paced environment with ambitious teams.
- Qualifications: 4+ years in security compliance and experience with frameworks like SOC 2 and ISO 27001.
The predicted salary is between 60000 - 80000 £ per year.
Humaans is building the next generation of infrastructure for the workplace; software designed for companies that are scaling fast, operating globally, and pushing into new boundaries. We work with ambitious teams across Europe and the US, from AI-native companies to established, high-growth organisations scaling internationally and through acquisition.
We're looking for a Security GRC Manager - Trust and Compliance, to own the systems, processes, audits, and customer-facing trust work that help Humaans scale into more demanding markets. This is a hands-on ownership role, built around AI. You'll run our security compliance programme throughout the year, not just during audit season.
You'll own the operating rhythm for frameworks like ISO 27001, SOC 1, SOC 2, HIPAA and future standards that matter to our customers. You'll keep evidence organised, controls running, policies up to date, vendors reviewed, risks visible, and audits moving smoothly.
You'll also be close to revenue, supporting Sales and Customer Success on security and compliance questions, helping complete vendor security questionnaires, maintaining reusable trust materials, and ensuring enterprise buyers get accurate, fast, confidence-building answers.
This role sits at the intersection of Security, Legal, Product, Engineering, Revenue, and Operations. You don't need to be the person configuring every system yourself, but you do need to understand how modern SaaS companies operate, ask sharp questions, drive action across teams, and keep the bar high.
Focus / Ownership- You'll own Humaans' security compliance programme end-to-end, including ISO, SOC 1, SOC 2, HIPAA and future frameworks we choose to pursue.
- You'll manage audit cycles throughout the year, coordinating with external auditors, internal control owners, Engineering, People, Legal, Finance and Operations.
- You'll maintain the controls, evidence, policies, risk register, access reviews, vendor reviews, business continuity processes, and incident response documentation that support our certifications and customer commitments.
- You'll support customer-facing trust work, including sales calls, security reviews, procurement processes, vendor questionnaires, RFPs, DPAs, subprocessors, data protection questions, and enterprise diligence.
- You'll build AI-assisted systems for answering repeated security questions quickly and accurately.
- You'll work with Product and Engineering to translate compliance requirements into practical operational controls without slowing the company down unnecessarily.
- You'll help the company make clear, risk-based decisions, escalating when something matters and cutting through noise when it doesn't.
- You'll raise the maturity of how Humaans thinks about security, privacy, risk, and customer trust as we move upmarket.
- You have 4+ years of experience in security compliance, GRC, trust, audit, information security, privacy operations, or a closely related role.
- You've run or supported audits for frameworks such as SOC 2, ISO 27001, SOC 1, HIPAA, GDPR, or similar.
- You've used AI in security or compliance work and can speak to what you built and the outcome.
- You understand how modern B2B SaaS companies work, including cloud infrastructure, access management, vendor management, product development, customer data, and enterprise sales processes.
- You're comfortable being customer-facing and can join a sales call, answer security questions clearly, and give buyers confidence.
- You're strong at written communication, producing crisp policies, questionnaire responses, audit narratives, and internal guidance that people actually understand.
- You're organised and detail-oriented, keeping evidence, control owners, audit timelines, and customer commitments moving without dropping things.
- You're pragmatic, knowing the difference between meaningful risk reduction and compliance theatre.
- You can work across teams and hold a high bar without becoming a blocker.
- You're excited by a high-growth, high-ownership environment where the playbook is still being written.
- Experience in HR tech, fintech, healthtech, infrastructure, or another category where customer data and enterprise trust are central.
- Experience with security compliance platforms such as Vanta, Drata, Secureframe, Sprinto or similar.
- Experience reviewing DPAs, subprocessors, data residency questions, privacy documentation, and vendor contracts in partnership with Legal.
- Familiarity with US healthcare or HIPAA requirements.
- Experience building a trust centre, customer-facing security portal, or security questionnaire answer library.
- Experience supporting enterprise sales, procurement, RFPs, or security reviews.
- Within your first 90 days, you'll understand our current compliance posture, audit calendar, control owners, customer trust materials, and major gaps.
- Within six months, you'll have improved the operating rhythm of our compliance programme, reduced friction in sales security reviews, and made audits feel more predictable.
- Within twelve months, Humaans will have a more scalable trust function: stronger evidence, better controls, faster questionnaire turnaround, clearer ownership, and a security compliance programme that helps us win larger customers.
This is an in-person role. Our team comes together in the office Monday through Thursday, while most of the team collaborates in person on Mondays, Tuesdays, and Thursdays.
Package & BenefitsMarket-leading compensation that reflects your value, 25 days paid time off each year plus public holidays, Share Options with 5-year exercise window, free Thursday lunches at HQ, quarterly team events, and company offsites, top tier private coverage for health, vision and dental care, a new MacBook and tools you need to do your best work, enhanced parental leave with up to 16 weeks for primary and 4 weeks for secondary, and a learning & development budget.
Why Join Humaans Today?HR tech is having its AI moment and we’re positioned to own it. Humaans started as a next-gen HRIS taking on large incumbents in a massive market. We’ve since evolved into something even bigger: an AI platform that sits across workforce data and automates the operational layer of HR entirely.
We’re backed by Y Combinator, Lachy Groom, Moonfire, Frontline Ventures, and operators who’ve built some of the most consequential software companies of the last decade.
We’re a small team with an unapologetically high bar. It shows up in the product, in how we communicate, and in the standards we hold each other to.
Our Commitment to DiversityAt Humaans we’re looking for genuinely good people that are transparent and emphatic. We’re committed to providing equal opportunities, a diverse and inclusive work environment, and ensuring a fair interview process for everyone.
Privacy notice: We care about your privacy. When you apply for a role at Humaans, we’ll collect and process your personal data as part of our recruitment process.
Security GRC Manager in London employer: Humaans
Humaans is an exceptional employer, offering a dynamic work environment where innovation meets ambition. With a strong focus on employee growth, competitive compensation, and a commitment to diversity, we empower our team members to thrive in a high-ownership culture. Located in a vibrant city, our office fosters collaboration and creativity, making it an ideal place for those looking to make a meaningful impact in the HR tech space.
StudySmarter Expert Advice🤫
We think this is how you could land Security GRC Manager in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Humaans, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Humaans
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Humaans. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Security GRC Manager in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Humaans insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Humaans that you’re committed to staying ahead in the game.
How to prepare for a job interview at Humaans
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Humaans to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Humaans.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.