As our GRC Program Manager, you will be the driving force behind vivenu’s Governance, Risk, and Compliance execution. This is fundamentally an execution- and delivery-focused role: you are a true program manager who knows how to get things done yourself while driving cross-functional accountability across Engineering, Product, Legal, and Security teams.
You will lead our GRC initiatives end-to-end, driving audit strategy, owning internal risk workflows, and managing complex compliance projects across the organization. By translating regulatory and framework requirements into actionable, practical business processes, you will ensure vivenu continues to scale securely and responsibly across global markets without sacrificing developer velocity.
As a Senior Security Engineer - AppSec (d/f/m) your responsibilities will include:
- Drive Program Execution & Ownership: Take full end-to-end accountability for GRC deliverables, setting timelines, tracking cross-functional dependencies, and orchestrating teams to ensure compliance milestones are hit on schedule.
- Lead Internal Audit Operations: Serve as the primary internal leader and project owner for third party audits (e.g., SOC 2 Type II, PCI DSS, ). Own the process from scoping to successful completion, managing evidence collection, guiding control owners, and leading remediation efforts.
- Build & Scale Compliance Frameworks: Maintain and mature robust compliance frameworks, ensuring continued preparation for evolving global requirements such as GDPR and related security standards.
- Manage Risk & Remediation Workflows: Conduct practical IT, security, and third-party risk assessments. Maintain vivenu’s risk register, ensuring risk treatment plans and corrective actions are actively assigned, tracked, and closed out by control owners.
- Optimize GRC Operations & Tooling: Leverage modern GRC platforms and automation tools to streamline audit tracking, policy administration, vendor risk management and issue remediation workflows.
- Enable Engineering & Product Teams: Partner closely with technical teams to embed security controls, privacy-by-design, and cloud best practices directly into our development lifecycle and API-first platform.
- Support Enterprise Sales Readiness: Assist in answering complex enterprise customer security questionnaires, supporting third-party risk reviews, and demonstrating vivenu's robust compliance posture during high-value sales engagements.
- Governance & Executive Reporting: Translate complex technical and regulatory findings into clear risk posture dashboards, KRIs, and operational updates for leadership.
What you will need to succeed in this role:
- Execution & Program Management: Proven track record of getting things done: driving cross-functional projects, aligning diverse technical and business stakeholders, and holding teams accountable to deliverables.
- Audit Leadership Experience: Hands-on experience leading major compliance audits (e.g., SOC 2, PCI DSS, ISO 27001) from start to finish as the internal counterpart and owner.
- Domain Context: Prior experience in SaaS, Fintech, or cloud-native technology environments is highly preferred. If your background is from another sector, a strong curiosity and fast-learning mindset toward modern cloud, API, and SaaS architectures is required.
- GRC Experience: demonstrated exposure to GRC and Security processes such as risk assessments, internal audits, policy development, corrective actions management.
- Framework Familiarity: Solid working knowledge of core industry standards and frameworks (e.g., SOC 2, PCI DSS, ISO 27001, GDPR, NIST CSF/RMF).
- Communication & Influence: Outstanding ability to translate regulatory requirements into clear operational steps, communicating effectively with both deep technical experts and business executives.
- Languages: Business fluency in English is required.
- Technical Aptitude: Basic hands-on technical familiarity (e.g., basic scripting, working with APIs, or reading system logs/configurations) is a big plus.
- Exposure to GRC automation tools (e.g., Vanta, Drata, ServiceNow IRM, or LogicGate).
- Relevant professional certifications such as CRISC, CISA, CISM, CISSP, CSSP or ISO/IEC 27001 Lead Auditor.
- German language proficiency would be a plus.
Skills Required
- Proven track record driving cross-functional projects, aligning technical and business stakeholders, and managing deliverables
- Hands-on experience leading major compliance audits such as SOC 2, PCI DSS, or ISO 27001 from start to finish
- Experience in GRC and security processes, including risk assessments, internal audits, policy development, and corrective action management
- Working knowledge of SOC 2, PCI DSS, ISO 27001, GDPR, and NIST CSF/RMF frameworks
- Ability to translate regulatory requirements into operational processes and communicate with technical and executive stakeholders
- Business fluency in English
- Prior experience in SaaS, fintech, or cloud-native technology environments
- Basic technical familiarity with scripting, APIs, system logs, or configurations
- Experience with GRC automation tools such as Vanta, Drata, ServiceNow IRM, or LogicGate
- Professional certification such as CRISC, CISA, CISM, CISSP, CSSP, or ISO/IEC 27001 Lead Auditor
- German language proficiency
What We Do
Hundreds of thousands of sellers around the globe rely on primary ticketing solutions that haven’t kept up with their needs and expectations. Platforms from the 90s that still feel like we are in the 90s made the jobs of ticket managers worldwide constant miseries. Now there is a better way — customer-centric ticketing! vivenu is a primary ticketing provider that helps event organizers manage, market, and analyze ticket sales from one unified platform. Our mission is to build a ticketing platform that puts ticket sellers first – so they’re empowered to create experiences that people love. We empower organizers to be more efficient, absolutely independent, and fully connected – to say the very least. vivenu is the exclusive ticketing solution for the Grammy Awards, the Special Olympics, FC Schalke 04, Qatar Creates, and many many more. With $65 million in funding from renowned global investors, we’ve set out to revolutionize event ticketing – now and forever. Pumped enough? We are not just another company and we are not looking for people who seek just another job. Ready for personal growth? Join us.
Why Work With Us
Join us to shape the future of live entertainment with purpose and variety. Whether you’re refining innovative product features, creating memorable fan experiences, closing strategic partnerships, or driving customer success — every step at vivenu impacts hundreds of clients and thousands of fans daily. Here, your work truly matters.








