SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Papaya Global, a rapidly growing B2B SaaS unicorn in the payroll and payments space, is seeking a GRC Specialist to join its Security group. The role reports to the GRC Manager and focuses on managing information security compliance programs at scale across a global organization operating in 160+ countries.
Key responsibilities include leading SOC 2 Type I/II and ISO 27001 audit and certification processes, supporting DORA (Digital Operational Resilience Act) compliance implementation, and owning end-to-end customer security questionnaire and RFP response workflows. You will conduct risk assessments, develop risk treatment plans, and maintain information security policies and standards. The role involves performing internal audits and gap analyses against regulatory frameworks, collaborating with cross-functional teams (R&D, IT, Legal, Sales) to embed security practices, and monitoring remediation of identified risks.
A significant component involves vendor and third-party risk management, including periodic assessments and ongoing monitoring. The specialist will leverage AI-enabled tools to streamline compliance workflows, including security control analysis, compliance documentation drafting, audit preparation, and evidence collection. You will use AI-assisted capabilities to improve efficiency in responding to security questionnaires, risk assessments, and regulatory documentation while maintaining strict compliance and traceability.
Required qualifications include 4+ years of hands-on GRC or information security compliance experience, proven SOC 2 Type I/II audit management, ISO 27001 implementation/certification experience, and familiarity with DORA requirements. Strong knowledge of information security risk management methodologies, experience with cross-functional stakeholder management, and fluent English (spoken and written) are essential. The ideal candidate is detail-oriented, organized, and a strong communicator.
Advantages include SaaS or B2B tech company experience, a degree in IT/Information Systems/Computer Science, and hands-on experience leveraging AI tools for compliance operations.