SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
ERGO NEXT (Next Insurance) is building a technology-led, full-stack small business insurance platform. The company is expanding its SaaS platform capabilities from the US into Europe and needs a dedicated GRC (Governance, Risk, and Compliance) capability to support European regulatory, security, privacy, operational resilience, and assurance requirements.
You will build and lead the GRC domain supporting NEXT's expansion into ERGO Europe. This is a high-impact, program-building role at the intersection of GRC, engineering, product, security, privacy, legal, and ERGO Group stakeholders.
Key responsibilities:
- Build and lead the GRC domain for European expansion
- Translate DORA, GDPR, EU AI Act, and ERGO Group standards into practical governance, controls, and evidence processes
- Partner with Engineering, Product, Security, Privacy, and Legal to embed compliance into platform design and software delivery
- Support platform replication and SaaS-readiness, including cyber security risk, operational resilience, data protection, AI governance, third-party dependencies, incident management, logging, monitoring, access controls, and auditability
- Serve as key GRC interface with Group and European stakeholders
- Develop regulatory readiness roadmaps, control mappings, gap assessments, risk registers, and executive reporting
- Design scalable evidence collection and assurance processes for audits and regulatory inquiries
- Coach and support GRC team members on the Europe domain
- Help mature NEXT's GRC function as it grows into a broader group technology provider
Required qualifications:
- 7+ years in GRC, security & regulatory compliance, operational resilience, privacy governance, and audit readiness
- Proven managerial experience leading, coaching, and developing team members while driving accountability across complex GRC initiatives
- Experience in AWS native environments delivering cloud-based regulated financial services and fintech products
- Strong understanding of EU regulatory expectations (DORA, GDPR, EU AI Act) with ability to translate into actionable technical and operational controls
- Proven ability to build new programs, not just operate existing processes
- Experience working directly with engineering, product, security, cloud infrastructure, DevOps, legal, privacy, and audit stakeholders
- Strong stakeholder management skills, including experience with group-level or parent-company functions
- Experience using AI, automation, or data-driven approaches to improve productivity, regulatory analysis, evidence management, or operational efficiency
- Excellent written and verbal communication skills
- Strong prioritization, execution, and follow-through
Ideal candidate is a proactive self-starter with strong ownership, execution discipline, and ability to drive outcomes without waiting for perfect instructions. Comfortable with ambiguity and experienced in regulated technology environments.