GRC Program Manager @vivenu
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted YDay

[Hiring] GRC Program Manager @vivenu

YDay - vivenu is hiring a remote GRC Program Manager. 💸 Salary: unspecified 📍Location: Germany

Role Description

As our GRC Program Manager, you will be the driving force behind vivenu’s Governance, Risk, and Compliance execution. This is fundamentally an execution- and delivery-focused role: you are a true program manager who knows how to get things done yourself while driving cross-functional accountability across Engineering, Product, Legal, and Security teams.

  • Lead our GRC initiatives end-to-end, driving audit strategy, owning internal risk workflows, and managing complex compliance projects across the organization.
  • Translate regulatory and framework requirements into actionable, practical business processes to ensure vivenu continues to scale securely and responsibly across global markets without sacrificing developer velocity.

As a Senior Security Engineer - AppSec (d/f/m) your responsibilities will include:

  • Drive Program Execution & Ownership: Take full end-to-end accountability for GRC deliverables, setting timelines, tracking cross-functional dependencies, and orchestrating teams to ensure compliance milestones are hit on schedule.
  • Lead Internal Audit Operations: Serve as the primary internal leader and project owner for third party audits (e.g., SOC 2 Type II, PCI DSS). Own the process from scoping to successful completion, managing evidence collection, guiding control owners, and leading remediation efforts.
  • Build & Scale Compliance Frameworks: Maintain and mature robust compliance frameworks, ensuring continued preparation for evolving global requirements such as GDPR and related security standards.
  • Manage Risk & Remediation Workflows: Conduct practical IT, security, and third-party risk assessments. Maintain vivenu’s risk register, ensuring risk treatment plans and corrective actions are actively assigned, tracked, and closed out by control owners.
  • Optimize GRC Operations & Tooling: Leverage modern GRC platforms and automation tools to streamline audit tracking, policy administration, vendor risk management and issue remediation workflows.
  • Enable Engineering & Product Teams: Partner closely with technical teams to embed security controls, privacy-by-design, and cloud best practices directly into our development lifecycle and API-first platform.
  • Support Enterprise Sales Readiness: Assist in answering complex enterprise customer security questionnaires, supporting third-party risk reviews, and demonstrating vivenu's robust compliance posture during high-value sales engagements.
  • Governance & Executive Reporting: Translate complex technical and regulatory findings into clear risk posture dashboards, KRIs, and operational updates for leadership.

Qualifications

  • Proven track record of getting things done: driving cross-functional projects, aligning diverse technical and business stakeholders, and holding teams accountable to deliverables.
  • Hands-on experience leading major compliance audits (e.g., SOC 2, PCI DSS, ISO 27001) from start to finish as the internal counterpart and owner.
  • Prior experience in SaaS, Fintech, or cloud-native technology environments is highly preferred.
  • Demonstrated exposure to GRC and Security processes such as risk assessments, internal audits, policy development, corrective actions management.
  • Solid working knowledge of core industry standards and frameworks (e.g., SOC 2, PCI DSS, ISO 27001, GDPR, NIST CSF/RMF).
  • Outstanding ability to translate regulatory requirements into clear operational steps, communicating effectively with both deep technical experts and business executives.
  • Business fluency in English is required.

Requirements

  • Basic hands-on technical familiarity (e.g., basic scripting, working with APIs, or reading system logs/configurations) is a big plus.
  • Exposure to GRC automation tools (e.g., Vanta, Drata, ServiceNow IRM, or LogicGate).
  • Relevant professional certifications such as CRISC, CISA, CISM, CISSP, CSSP or ISO/IEC 27001 Lead Auditor.
  • German language proficiency would be a plus.

Benefits

  • We scale sustainably on a profitable, VC-backed foundation with true product-market fit.
  • Collaborate with over 160 dedicated professionals, including leaders from Google, Slack, and Salesforce.
  • We’re a diverse, merit-driven team spread across six global offices.
  • Sifted consistently ranks us among the fastest-growing scale-ups in Europe.
  • Work alongside some of tech’s brightest minds — from Forbes 30 Under 30 founders to Executive of the Year award winners.

Company Description

At vivenu, we believe our people define our success – and that we win with bold, diverse minds. The strongest teams are built on different perspectives, experiences, and voices. We’re committed to creating a workplace where everyone feels empowered to contribute, grow, and thrive to shape the future of live entertainment globally.

Before You Apply
remote Be aware of the location restriction for this remote position: Germany
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
GRC Program Manager @vivenu
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted YDay
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Application Denied
Unlock 125,000+ Remote Jobs
remote Be aware of the location restriction for this remote position: Germany
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Application Denied
Unlock 125,000+ Remote Jobs
×

Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews
Unlock All Jobs Now

Maybe later