GRC Lead

Sorry, this job was removed at 02:16 p.m. (CST) on Tuesday, Apr 15, 2025
Denver, CO, USA
Hybrid
Enterprise Web • Marketing Tech • Software
Content that takes you from anywhere to everywhere.
The Role

About the Opportunity

At Contentful, we prioritize the security and privacy of our services. Our Governance, Risk, and Compliance (GRC) team supports company-wide initiatives, upholding high standards of quality to ensure continuous compliance and reduce exposure. We believe that Security and GRC are anchored in principles of repeatability, scalability, and practicality.

We are seeking a committed and driven GRC Lead to support and enhance our GRC program through structured processes and continuous improvement. In this role, you will play a key part in maintaining compliance frameworks within Vanta, managing the risk register, and assisting with compliance monitoring efforts. You will work closely with stakeholders across the business to assess risks, conduct gap analyses, and support audit readiness activities. As an experienced internal auditor, you will bring hands-on ISO 27001 and SOC 2 expertise.

Candidates should be detail-oriented, proactive, and eager to develop within a fast-paced and evolving security environment. You will be a member of the Security Department, reporting to the Business Resilience and GRC Director, and collaborate across business functions to ensure compliance requirements are met. You will work both independently and as part of a team, contributing to the maturity of Contentful’s GRC practices.

What to expect?

Compliance Alignment:

  • Support the identification, assessment, and remediation of compliance gaps across multiple frameworks.
  • Assist in mapping controls across frameworks to streamline compliance efforts.
  • Translate controls into actionable steps and provide implementation guidance to stakeholders.
  • Support the ongoing maintenance and improvement of GRC software (Vanta), including control testing.
  • Monitor compliance tasks in Vanta, track progress, and ensure timely completion of assigned actions.

GRC Maturity and Continuous improvement:

  • Support the use of compliance and industry frameworks to enhance GRC maturity at Contentful.
  • Assist in identifying systemic issues, analyzing root causes, and recommending improvements.
  • Track regulatory changes and support updates to maintain compliance.
  • Maintain policies and procedures, recommending updates to align with best practices.
  • Contribute to team initiatives and strategies to strengthen GRC programs.

Internal and External Audits:

  • Support audit preparation and execution to facilitate successful outcomes.
  • Conduct internal audits and gap assessments to evaluate compliance with established frameworks.
  • Identify areas of non-compliance, assess control effectiveness, and recommend improvements.

Risk Management:

  • Support functional teams in applying the risk management policy and embedding compliance.
  • Assist in defining responsibilities and ensuring consistent risk mitigation efforts across Contentful.
  • Maintain the risk register, track risk mitigation activities, and collaborate with stakeholders.
  • Conduct risk assessments and gap analyses to identify areas for improvement.

GRC Committee:

  • Support GRC committees by coordinating meetings, preparing materials, and documenting actions.
  • Assist in tracking outcomes and following up on action items to ensure progress.

GRC Initiatives:

  • Assist in preparing compliance reports, tracking key metrics, and providing cross-functional updates.
  • Address compliance queries and support internal escalations as needed.
  • Support stakeholders with compliance inquiries, including contributing to RFP responses.
  • Participate in customer engagements to provide security and compliance information.
  • Maintain internal and external GRC resources, such as the Trust Center, datasheets, and whitepapers.
  • Provide training to drive education on security compliance requirements and best practices.
  • Contribute to the growth and scalability of GRC practices by supporting team initiatives.

What you need to be successful?

  • 4+ years of Governance, Risk, and Compliance experience.
  • 3+ years focused on implementing and maintaining ISO 27001 and SOC 2 frameworks.
  • Ability to understand and manage multiple compliance frameworks and customer requirements.
  • Experience conducting internal audits, risk assessments, and gap analyses with moderate oversight.
  • Familiarity with maintaining ISO 27001 and SOC 2 programs, including supporting external audits.
  • ISO 27001 Lead Implementer, Internal Auditor, or similar certifications (e.g., SOC 2, NIST) preferred.
  • Exposure to frameworks like PCI DSS, CIS, COBIT, GDPR, NIST (CSF, 800-171, 800-53) is a plus.
  • Experience working in a technical or development-focused environment.
  • Experience supporting the management and execution of projects.
  • Ability to translate requirements and communicate effectively with technical resources.
  • Strong written and verbal communication skills.
  • Ability to collaborate effectively across different business units and locations.
  • Proven track record of building and nurturing relationships with stakeholders.
  • Detail-oriented, with a commitment to maintaining quality and compliance.
  • Ability to work independently while being an effective team player.
  • Ability to work in a fast-paced environment, managing multiple tasks simultaneously.

What's in it for you?

  • Join an ambitious tech company reshaping the way people build digital experiences
  • Full-time employees receive Stock Options for the opportunity to share in the success of our company
  • Comprehensive healthcare package covering 100% of monthly health premiums for employees  and 85% of costs for your dependents. 
  • Fertility and family building benefits, including a lifetime reimbursable wallet to support your growing family.
  • We value Work-Life balance and You Time! A generous amount of paid time off, including vacation days, sick days, compassion days for loss,  education days, and volunteer days
  • Company paid parental leave to care for and focus on your growing family 
  • Use your personal annual education budget to improve your skills and grow in your career
  • Enjoy a full range of virtual and in-person events, including workshops, guest speakers, and fun team activities, supporting learning and networking exchange beyond the usual work duties 
  • An annual wellbeing stipend to care for your physical, financial, or emotional health
  • A monthly communication stipend and phone hardware upgrade reimbursement.
  • New hire office equipment stipend for hybrid or distributed employees. Get the gear you need to work at your best.

This role will need to be conducted in a state in which we are currently registered to do business. 

The application deadline is 5/10/25

Colorado Salary Statement: The salary range displayed is specifically for those potential hires who will work or reside in the state of Colorado if selected for the role. Any offered salary is determined based on internal equity, internal salary ranges, market data/ranges, applicant's skills and prior relevant experience, certain degrees and certifications (e.g. JD/technology), for example.

Colorado Salary Range: $144,000 - $160,000
[This position is eligible for equity awards in accordance with the terms of Contentful’s equity plans.]

#LI-JE1 #LI-Hybrid

Who are we?

Contentful is the intelligent composable content platform that unlocks all of an organization’s digital content to deliver impactful customer experiences, making content a strategic business asset. The Contentful Platform, Contentful Studio, and the Contentful Ecosystem combine the flexibility of composable content with the intelligence of AI, empowering digital teams to drive business momentum through collaboration, speed, and scale. Contentful powers innovative content experiences across brands, regions, and channels for organizations around the world, including nearly 30% of the Fortune 500. Nearly 800 people from more than 70 nations contribute their energy and creativity to Contentful, working from hubs in Berlin, Denver and distributed around the world.

Everyone is welcome here!

“Everyone is welcome here” is a celebrated component of our culture. At Contentful, we strive to create an inclusive environment that empowers our employees. We believe that our products and services benefit from our diverse backgrounds and experiences and are proud to be an equal opportunity employer. All qualified applications will receive consideration for employment without regard to race, color, national origin, religion, sexual orientation, gender, gender identity, age, physical [dis]ability, or length of time spent unemployed. We invite you to apply and join us!

If you need reasonable accommodations at any point during the application or interview process, please let your recruiting coordinator know.

Please be aware of scammers who may fraudulently allege to be from Contentful. These types of fraud can be carried out through copycat websites, fake email addresses claiming to be from our company, or social media. We do not ask for your personal information such as bank account numbers, identification numbers, etc through social media or chat-based apps, nor do we request or send money for the purchase of business equipment. If you suspect fraud, please report it to your local authorities, as well as reaching out to us at [email protected] with any information you may have.

By clicking “Apply for this job,” I acknowledge that I have read the “Contentful’s Candidate Privacy Notice”, and hereby consent to the collection, processing, use, and storage of my personal information as described therein.

Contentful Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Contentful and has not been reviewed or approved by Contentful.

  • Fair & Transparent Compensation Pay is considered competitive for many roles, particularly in sales and technical tracks, with structured packages that include base and variable components. Feedback suggests compensation ranges are outlined by role, location, and experience, helping set expectations.
  • Healthcare Strength Healthcare coverage is described as comprehensive with strong employer cost coverage and broad medical, dental, vision, life, and mental health support. Wellness programs and a wellbeing stipend further reinforce the health offering.
  • Parental & Family Support Family-building support is emphasized through generous paid parental leave, adoption assistance, and fertility benefits. These programs position the company as supportive of different family needs.

Contentful Insights

Similar Jobs

Applied Systems Logo Applied Systems

Senior User Experience Designer

Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Remote or Hybrid
4 Locations
3040 Employees
100K-130K Annually

Applied Systems Logo Applied Systems

Cloud Platform Engineer

Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Remote or Hybrid
2 Locations
3040 Employees
100K-160K Annually

Vertafore Logo Vertafore

Consultant

Information Technology • Insurance • Software
Hybrid
Denver, CO, USA
2372 Employees
70K-95K Annually

PwC Logo PwC

Deals - Capital Markets Accounting Advisory Services - Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
17 Locations
370000 Employees
77K-202K Annually
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Berlin
744 Employees
Year Founded: 2013

What We Do

Contentful is a leading composable content platform that unlocks all of an organization’s digital content to deliver impactful customer experiences, making content a strategic business asset. The Contentful Platform, Contentful Studio, Ninetailed by Contentful and the Contentful Ecosystem combine the flexibility of composable content with the intelligence of AI, empowering digital teams to drive business momentum through collaboration, speed, and scale. Contentful powers innovative content experiences across brands, regions, and channels for organizations of all sizes around the world, including nearly 30% of the Fortune 500.

Why Work With Us

Nearly 800 people from more than 70 nations contribute their energy and creativity to Contentful, working from hubs in Berlin, Denver and distributed around the world.

Gallery

Gallery

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account