GRC Specialist

Posted 3 Days Ago
Be an Early Applicant
Kraków, Małopolskie, POL
Hybrid
Mid level
Fintech • Payments • Financial Services
The Role
The GRC Specialist will lead information security compliance programs, manage SOC 2 audits, implement ISO 27001, perform risk assessments, develop policies, and ensure cross-functional collaboration for security compliance.
Summary Generated by Built In
Description

Papaya Global is a rapidly growing, award-winning B2B tech unicorn with an ambitious mission to revolutionize the payroll & payments industry. With over $400M raised from multiple tier-one investors, our innovative technology provides a comprehensive solution for managing global workforces, encompassing everything from hiring and onboarding to managing and paying employees in over 160 countries. 

We are seeking a GRC Specialist to join the Security group, reporting to the GRC Manager. We are looking for a team player, independent and responsible person, quick learner, who wants to work in a challenging and dynamic environment.

You will:

  • Lead and manage information security compliance programs, including SOC 2 Type I/II and ISO 27001 audits, certifications, and ongoing compliance activities.
  • Support the implementation and maintenance of DORA (Digital Operational Resilience Act) compliance requirements across the organization.
  • Own the end-to-end process of responding to customer security questionnaires, RFPs, and third-party due diligence requests.
  • Conduct risk assessments and help develop risk treatment plans to address identified gaps.
  • Develop, review, and maintain information security policies, standards, procedures, and guidelines.
  • Perform internal audits and gap analyses against regulatory frameworks and industry best practices.
  • Collaborate with cross-functional teams (R&D, IT, Legal, Sales) to embed security and compliance practices across the organization.
  • Monitor and track the remediation of identified risks and compliance gaps.
  • Support vendor and third-party risk management processes, including periodic risk assessments and ongoing monitoring.
  • Leverage AI-enabled tools to streamline compliance workflows, including analysis of security controls, drafting and refinement of compliance documentation, and support in audit preparation and evidence collection.
  • Use AI-assisted capabilities to improve efficiency and accuracy in responding to security questionnaires, risk assessments, and regulatory documentation while maintaining strict compliance and traceability standards.
  • Apply AI tools to support knowledge management, policy drafting, and cross-framework mapping (SOC 2, ISO 27001, DORA) in a controlled and auditable manner.

  

Requirements
  • 4+ years of hands-on experience in GRC, information security compliance, or a related field.
  • Proven experience managing SOC 2 Type I/II audits and certification processes.
  • Hands-on experience with ISO 27001 implementation and/or certification audits.
  • Familiarity with DORA (Digital Operational Resilience Act) requirements and their practical application.
  • Experience handling customer security questionnaires and due diligence requests – Must.
  • Strong knowledge of information security risk management methodologies and frameworks.
  • Experience working with cross-functional stakeholders and translating compliance requirements into actionable steps.
  • Highly proficient in spoken and written English.
  • Team player, detail-oriented, with strong organizational and communication skills – Must.
  • Experience in a SaaS or B2B tech company – Advantage.
  • Degree in Information Technology / Information Systems / Computer Science – Advantage.
  • Demonstrated ability to effectively leverage AI tools to support compliance operations, including documentation, audit preparation, risk analysis, questionnaire handling, and policy development workflows.
  • Practical experience using AI-assisted tools to enhance accuracy, efficiency, and consistency in governance, risk, and compliance processes while ensuring adherence to regulatory and audit requirements.

Skills Required

  • 4+ years of hands-on experience in GRC, information security compliance, or related field
  • Proven experience managing SOC 2 Type I/II audits and certification processes
  • Hands-on experience with ISO 27001 implementation and/or certification audits
  • Familiarity with DORA requirements and their practical application
  • Experience handling customer security questionnaires and due diligence requests
  • Strong knowledge of information security risk management methodologies and frameworks
  • Experience working with cross-functional stakeholders and translating compliance requirements into actionable steps
  • Highly proficient in spoken and written English
  • Team player, detail-oriented, with strong organizational and communication skills
  • Experience in a SaaS or B2B tech company
  • Degree in Information Technology / Information Systems / Computer Science
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Austin, , Texas
807 Employees
Year Founded: 2016

What We Do

Imagine controlling all your global payroll and payments from a single place, supported by certified experts who keep you compliant in every country, even when laws change. No more juggling third parties. No more foreign bank accounts. No more repetitive manual work. Finally, there’s one platform that gives you total control of your global operations, from creating local contracts automatically to paying workers in the local currency of 160+ countries. It’s called Papaya Global, and we’d love to show it to you. Papaya Global: How the world gets paid

Similar Jobs

HERE Technologies Logo HERE Technologies

Lead Software Engineer

Artificial Intelligence • Automotive • Computer Vision • Information Technology • Internet of Things • Logistics • Software
Hybrid
Kraków, Małopolskie, POL
6000 Employees

HERE Technologies Logo HERE Technologies

Data Scientist

Artificial Intelligence • Automotive • Computer Vision • Information Technology • Internet of Things • Logistics • Software
Hybrid
Kraków, Małopolskie, POL
6000 Employees

HERE Technologies Logo HERE Technologies

Artificial Intelligence Engineer

Artificial Intelligence • Automotive • Computer Vision • Information Technology • Internet of Things • Logistics • Software
Hybrid
Kraków, Małopolskie, POL
6000 Employees

HERE Technologies Logo HERE Technologies

Engineering Manager

Artificial Intelligence • Automotive • Computer Vision • Information Technology • Internet of Things • Logistics • Software
Hybrid
Kraków, Małopolskie, POL
6000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
31 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account