Overview
As Security GRC Specialist, you will strengthen and scale security practices across products, operations, and customer commitments. You will partner with engineering, IAM, IT, and security teams to embed controls and ensure measurable risk management. You drive assurance activities (SOC 2, ISO 27001) and translate security requirements into practical, scalable processes. You will engage with customers and partners on security inquiries, audits, and contractual security clauses, influencing our security program at scale. This role offers impact across cloud, SaaS, identity, and infrastructure in a fast-growing financial services tech environment.
Leistungen / Benefits
- flexible work setting
- competitive compensation
- career advancement opportunities
- dynamic, innovative environment
- global, diverse team
- startup agility with established organization
Verantwortungsbereiche
- Assist engineering teams to ensure security controls across cloud, SaaS, identity, infrastructure, and applications meet requirement thresholds
- Perform security risk assessments, control reviews, gap analyses, and technical design assessments to define remediation
- Drive SOC 2, ISO 27001, and related assurance activities including control design, evidence readiness, audit support, and continuous compliance
- Partner with Engineering, IAM, IT, Security Operations, and other stakeholders to embed security requirements into technology, projects, and processes
- Support customer-facing security activities, including reviewing security clauses in contracts, RFPs, security inquiries, due diligence, and customer audits
Zentrale Anforderungen
- 5+ years in information security, security compliance, risk management, audit, or related fields
- Hands-on SOC 2 program management experience (control design, evidence collection, audit coordination, remediation tracking) with governance tooling
- Strong knowledge of security frameworks and standards such as SOC 2 and ISO 27001
- Ability to assess security risks, evaluate control effectiveness, and communicate to technical and non-technical stakeholders
- Experience working cross-functionally with engineering, infrastructure, product, and business teams to drive security initiatives
- Cross-functional collaboration
- Clear communication to both technical and non-technical audiences
- Analytical thinking and problem solving
- SOC 2
- ISO 27001
- security risk assessments
Security GRC Specialist in Dortmund Arbeitgeber: SAP Fioneer
SAP Fioneer ist ein hervorragender Arbeitgeber, der Innovation und Agilität in den Mittelpunkt seiner Unternehmenskultur stellt. Mit einem starken Fokus auf Mitarbeiterentwicklung und einem dynamischen Arbeitsumfeld bietet das Unternehmen zahlreiche Wachstumschancen und fördert kreative Lösungen im Bereich der Finanzdienstleistungen. Die Lage in einem globalen Unternehmen ermöglicht es den Mitarbeitern, an spannenden Projekten zu arbeiten und Teil eines engagierten Teams zu sein, das die Zukunft der digitalen Transformation gestaltet.