Overview
Emergent is looking for a GRC Lead to build and run its compliance program across security, privacy, AI, and consumer protection for a global B2C product.
What you'll do
- Own SOC 2, ISO 27001, and related certifications from readiness through audit and renewal.
- Drive GDPR and global privacy requirements, including data residency, DSARs, DPAs, and records of processing.
- Define controls for emerging AI regulations, including the EU AI Act, and their application to autonomous code generation and execution.
- Own policies, controls, evidence collection, vendor/subprocessor risk, and audit readiness.
- Translate compliance requirements into practical, scalable controls that engineering teams can implement.
- Work closely with Engineering, Security, Product, and Legal teams.
What you'll need
- 5 to 7+ years in GRC, security compliance, privacy, or risk.
- Hands-on experience with SOC 2 / ISO 27001.
- Strong understanding of GDPR and global privacy.
- Experience managing audits, vendors, controls, and compliance programs end to end.
- Ability to work closely with Engineering, Security, Product, and Legal teams.
Nice to have
- Experience with AI governance, EU AI Act, or cloud-native products.
- Comfort building GRC programs from the ground up.
- A systems-oriented approach rather than a checklist-oriented approach.
- A preference for practical, scalable controls over paperwork.
Details
Read the full description and apply on the company’s own careers page.