SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Camunda is an enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex business processes. The company is trusted by over 700 organizations worldwide, including 9 of the top 10 US banks, and is recognized as a Visionary in the 2025 Gartner Magic Quadrant for Business Orchestration and Automation Technologies.
As Senior InfoSec GRC Analyst, you will own the governance, risk, and compliance side of Camunda's security practice within a small, senior, and highly collaborative InfoSec team. This is a role with real ownership and substantial cross-functional contact across Legal, Procurement, IT, PreSales, and PostSales teams.
Key responsibilities include:
- Own and continuously improve Camunda's Information Security Management System (ISMS), identifying gaps and driving measurable improvements
- Drive security audit cycles for ISO 27001, SOC 2, and future frameworks with minimal supervision, working directly with external auditors and internal control owners
- Review information security requirements in customer contracts, provide redlines and practical recommendations to negotiators
- Lead responses to complex customer security questionnaires and serve as trusted InfoSec point of contact for PreSales, PostSales, and customer security teams
- Run and improve GRC tooling, adding automation and continuous monitoring to collect compliance evidence once and reuse it
- Take ownership of emerging compliance topics (Cyber Resilience Act, AI Act), perform gap analysis, and partner across teams to implement requirements
Required experience includes hands-on implementation and maintenance of ISO 27001 and/or SOC 2 certifications, substantial background in information security/risk management/compliance (ideally in SaaS or cloud software), practical experience reviewing security requirements in customer contracts and leading security questionnaire responses, experience with GRC tools and compliance automation, and strong project management and collaboration skills across technical and non-technical stakeholders.
Nice-to-haves include software development or scripting ability, experience with business continuity or disaster recovery testing, familiarity with newer regulatory frameworks (Cyber Resilience Act, AI Act, NIS2), and experience in fully remote, async-first organizations.