SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
UiPath is seeking a GRC Technical Program Manager to join the TrustOps team in Bucharest. This hybrid role combines governance, risk, and compliance (GRC) leadership with national security and regulatory program oversight, supporting UiPath's operations in Romania and globally.
In the GRC domain, you will lead and support geographically strategic compliance frameworks including ISO 27001, SOC 2 Type 2, GDPR, and CCPA. You'll own compliance certification efforts end-to-end, executing risk management activities, implementing information security controls, and supporting internal and external audits. You will develop deep understanding of UiPath's control environment and articulate it to internal stakeholders, external partners, and auditors. Additional responsibilities include establishing and enforcing global data retention schedules, implementing privacy engineering controls and automations, maintaining sub-processor lists, managing customer notifications, and supporting the overall data governance and security strategy. You'll engage cross-functionally to drive control implementation and compliance initiatives.
In the national security and regulatory programs domain, you will serve as the accountable owner for obtaining and maintaining UiPath's Industrial Security Clearance. You'll oversee the establishment and operation of the internal security structure, acting as or directing the designated Security Officer (funcționar de securitate) function. You will own the PPSIC (Program for Preventing the Leakage of Classified Information)—its elaboration, approval, annual updates, and ongoing application. You'll direct implementation and assurance of physical security, personnel security, information security, and INFOSEC measures required for certification under Romanian law (Law 182/2002, HG 585/2002, HG 781/2002). You'll oversee the IT system (SIC) authorization process, including security documentation packages and CSTIC constitution. You'll act as the primary point of contact with authorities, coordinate external security consultants and audits, own incident detection and reporting for classified information, and maintain annual protection-status analysis.
This is a role of significant trust and responsibility. Obtaining a Romanian personnel security clearance is a mandatory prerequisite of employment.
REQUIREMENTS:
- 3–5 years of experience leading geographically strategic compliance frameworks (ISO 27001, SOC 2 Type 2, HITRUST R2) and global privacy regulatory requirements (GDPR, CCPA)
- Demonstrated ability to own compliance certifications end-to-end, including risk management, control implementation, and audit support
- Familiarity with cloud systems including Azure, GCP, and AWS
- Proven track record of effectively working with remote teams across different time zones
- Strong stakeholder-management skills with ability to translate complex regulatory requirements into actionable programs for technical and executive audiences
- Eligibility and willingness to obtain a Romanian personnel security clearance (certificat de securitate / autorizație de acces) as a condition of employment
NICE TO HAVE:
- Familiarity with Romanian classified information legislation (Law 182/2002, HG 585/2002, HG 781/2002) and ORNISS certification landscape
- Prior experience holding or managing a national or NATO/EU security clearance
- Experience acting as or working closely with a designated Security Officer (funcționar de securitate)
- Knowledge of INFOSEC accreditation processes for classified IT systems (SIC)
- Working proficiency in Romanian