SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior GRC Analyst

Preply - London, United Kingdom - In-office - posted 2026-08-14

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Preply, a unicorn edtech platform with 100,000+ tutors teaching 90+ languages globally, is seeking a Senior GRC Analyst to join its Cybersecurity team. Reporting to the Director of Security, you will own and scale the company's governance, risk, and compliance (GRC) program as a critical business function. Key responsibilities include maintaining and improving the risk management framework, running enterprise risk assessments, and tracking Key Risk Indicators (KRIs) to inform leadership decisions. You'll manage third-party vendor risk through periodic security reviews, develop and maintain security and compliance policies in collaboration with Legal and Engineering, and drive SOC 2 Type 2 compliance with potential expansion to ISO 27001 certification. You'll serve as a cross-functional bridge between Cybersecurity, Legal, Engineering, and Product teams, translating regulatory requirements (GDPR, CCPA, EU AI Act, etc.) into actionable business policies. Additional responsibilities include supporting privacy initiatives, coordinating internal and external audits, championing security culture across the organization, and identifying opportunities to automate GRC workflows using AI tools. The ideal candidate brings 5+ years of GRC, risk management, compliance, or cybersecurity experience, preferably in tech or SaaS. Required expertise includes SOC 2 implementation, familiarity with frameworks like ISO 27001 or PCI DSS, and knowledge of data privacy regulations. A flexible background is valued—whether engineering with security exposure, legal/compliance with cybersecurity specialization, or hybrid profiles combining technical and compliance skills. You should excel at translating complex regulatory requirements into practical policies, managing stakeholders across functions, and leveraging AI tools to streamline compliance operations. Certifications such as CISA, CISM, or CISSP are nice-to-have but not required.

Similar roles