Security GRC Engineer

Delivery Hero — Germany · Posted ~1 hour ago

Mid Visa History ✓

Skills

Security governance Risk assessment Security compliance Security policies and procedures Audit management Security controls GRC tools Cybersecurity risk management GRC Tools PCI DSS ISO 27001 NIST GDPR NIS2 EU AI Act

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A cybersecurity GRC engineering role focused on strengthening organizational security and navigating evolving regulatory requirements. You will maintain security policies, support major compliance frameworks, coordinate audits, assess and remediate risks, develop actionable controls, and promote security awareness across technical and business stakeholders.

Highlights

Multifaceted cybersecurity role spanning governance, compliance, risk, audits, security controls, and awareness programs, with strong collaboration across technical, legal, and business teams.

Description

Job DescriptionGlovo is seeking a proactive Security GRC Engineer to help strengthen our global security posture and navigate a rapidly evolving regulatory environment. In this multifaceted role, you will support compliance frameworks (PCI DSS, ISO 27001, NIS2), internal and external audits, drive risk assessment and remediation, and pioneer security awareness programs within our organization. Acting as a strategic bridge between technical engineering, legal, and business stakeholders, you will translate complex legal and regulatory demands into robust, actionable security controls. The ideal candidate brings deep cybersecurity risk expertise, hands-on experience with GRC tools, and the collaborative mindset needed to foster a security-first culture across Glovo. Be a part of a team where you will: Develop, implement, and maintain security policies and procedures in line with relevant compliance frameworks (e.g., ISO 27001, NIST, PCI DSS, GDPR, NIS2, EU AI Act). Develop, execute and deliver security awareness programs to educate employees on best practices and compliance requirements. Conduct security assessment risks, recommending and implementing mitigation strategies, maintaining a risk register and monitoring the status of remediation plans. Coordinate and respond to customer security inquiries and due diligence questionnaires (e.g., SIG, CAIQ). Review and provide input on contract modifications related to security, data protection, and privacy. Propose, develop and implement processes and tools for continuous monitoring of security monitoring to ensure ongoing adherence to policies. Assist with the end-to-end security certification and re-certification process (such as PCI DSS, ISO 27001, NIS2, among others). Assist with internal assessments to identify gaps, weaknesses, or non-compliance issues within our security controls. Support external and internal audits by preparing documentation and coordinating with auditors, follow ups and findings remediation. Serve as a key liaison between technical teams, legal, internal audit, and business units to ensure a unified approach to security and compliance