GRC Specialist

Reposted 16 Days Ago
Be an Early Applicant
Tel Aviv, ISR
In-Office
Mid level
Software
The Role
The GRC Specialist will manage Zafran's compliance program, focusing on SOC 2 and ISO certifications while building security frameworks and processes. This role involves close collaboration with various teams to enhance security and compliance practices, monitor regulations, and improve training initiatives.
Summary Generated by Built In
Description

We are looking for a GRC specialist who is excited to build and scale a modern compliance and security program from the ground up. This role is not just about maintaining SOC 2 and ISO certifications. It is about embedding security into our product, our engineering culture, and every customer conversation. You will partner closely with Engineering, Sales, and Leadership to turn compliance into a strategic advantage and help Zafran earn and maintain the trust of some of the most security-conscious organizations in the world.

About Zafran:

Our Mission: To stop the exploitation of vulnerabilities, everywhere.

What makes us different: Zafran de-risks 90% of critical vulnerabilities overnight across your hybrid environment and utilizes Agentic Capabilities and your existing security tools to rapidly mitigate and remediate the 10% most likely to be exploited.

​​Who’s behind us: Zafran is backed by Menlo Ventures, Sequoia Capital, Cyberstarts, and a deep belief that cybersecurity should move as fast as attackers do. We’re one of the fastest-growing companies in the industry, scaling to meet demand from the world’s most advanced, security-obsessed organizations.

We’re serious about our mission- so expect work that matters, teammates who challenge and inspire you, and plenty of fun along the way!

What you will do:

  • Own and manage Zafran’s security compliance program, including SOC 2, ISO 27001, and other relevant frameworks
  • Lead the response to customer security questionnaires and vendor security assessments, ensuring timely and accurate completion
  • Build and maintain Zafran’s internal security controls framework and evidence collection processes
  • Establish and manage continuous compliance monitoring and validation initiatives
  • Develop and maintain security policies, standards, and procedures that support both compliance and business objectives
  • Manage relationships with external auditors and assessors during compliance audits
  • Drive security awareness training and secure development practices across the organization
  • Support customer-facing security conversations during sales cycles and onboarding
  • Monitor regulatory changes and emerging compliance requirements relevant to SaaS platforms
  • Build scalability into GRC processes through automation and tooling improvements
Requirements
  • 4+ years of experience in information security and GRC
  • Proven track record managing SOC 2 Type 2, ISO 27001, or similar compliance frameworks for SaaS organizations
  • Experience working with SOC (cybersecurity operations center) and response to cybersecurity incidents
  • Hands-on experience with IT and Security tools
  • Strong understanding of security controls frameworks (NIST CSF, CIS Controls, OWASP)
  • Technical understanding of cloud security (AWS/Azure/GCP), application security, and infrastructure security
  • Excellent written and verbal communication skills with the ability to translate technical concepts for various audiences
  • Self-starter who can build processes from the ground up and operate with limited oversight
  • Relevant certifications preferred (CISSP, CISM, CISA, or equivalent)

Skills Required

  • 4+ years of experience in information security and GRC
  • Proven track record managing SOC 2 Type 2, ISO 27001, or similar compliance frameworks for SaaS organizations
  • Experience working with SOC and response to cybersecurity incidents
  • Hands-on experience with IT and Security tools
  • Strong understanding of security controls frameworks
  • Technical understanding of cloud security, application security, and infrastructure security
  • Excellent communication skills
  • Self-starter who can build processes from the ground up
  • Relevant certifications preferred
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, New York
99 Employees

What We Do

The Zafran Threat Exposure Management Platform is the first and only consolidated platform that integrates with your security tools to reveal, remediate, and mitigate the risk of exposures across your entire infrastructure. Zafran uses an agentless approach to reveal what is truly exploitable, while reducing manual prioritization and remediation through automated response workflows. https://www.zafran.io/

Similar Jobs

Remote or Hybrid
ISR
175 Employees
In-Office
Tel Aviv, ISR
100 Employees
In-Office
Tel Aviv, ISR

Similar Companies Hiring

Fairly Even Thumbnail
Hardware • Other • Robotics • Sales • Software • Hospitality
New York, NY
30 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York City, NY
100 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account