408,526open jobs
14,178companies
72,784added this week
Browse all
Salary
$77k – $211k per year (Estimated)
Location
Remote (Germany)
Employment
Full-Time
Overview
Company
Impact
Profile match
vivenu is a flexible and advanced ticketing platform designed for ambitious event organizers around the world. It offers a fully customizable, white-label solution that centers around the brand, sales, and business needs of its users. vivenu provides powerful tools such as APIs and SDKs, enabling a seamless integration with third-party software and allowing enterprises to build their own applications.

With over 10 million end users and usage quadrupling annually, our infrastructure now handles over 1 billion requests per month - and counting. Our API-first platform solves complex system challenges at scale - delivering performance, flexibility, and reliability for the world’s leading live entertainment brands.

As our GRC Program Manager, you will be the driving force behind vivenu’s Governance, Risk, and Compliance execution. This is fundamentally an execution- and delivery-focused role: you are a true program manager who knows how to get things done yourself while driving cross-functional accountability across Engineering, Product, Legal, and Security teams.

You will lead our GRC initiatives end-to-end, driving audit strategy, owning internal risk workflows, and managing complex compliance projects across the organization. By translating regulatory and framework requirements into actionable, practical business processes, you will ensure vivenu continues to scale securely and responsibly across global markets without sacrificing developer velocity.

As a GRC Program Manager (d/f/m) your responsibilities will include:

  • Drive Program Execution & Ownership: Take full end-to-end accountability for GRC deliverables, setting timelines, tracking cross-functional dependencies, and orchestrating teams to ensure compliance milestones are hit on schedule.
  • Lead Internal Audit Operations: Serve as the primary internal leader and project owner for third party audits (e.g., SOC 2 Type II, PCI DSS, ). Own the process from scoping to successful completion, managing evidence collection, guiding control owners, and leading remediation efforts.
  • Build & Scale Compliance Frameworks: Maintain and mature robust compliance frameworks, ensuring continued preparation for evolving global requirements such as GDPR and related security standards.
  • Manage Risk & Remediation Workflows: Conduct practical IT, security, and third-party risk assessments. Maintain vivenu’s risk register, ensuring risk treatment plans and corrective actions are actively assigned, tracked, and closed out by control owners.
  • Optimize GRC Operations & Tooling: Leverage modern GRC platforms and automation tools to streamline audit tracking, policy administration, vendor risk management and issue remediation workflows.
  • Enable Engineering & Product Teams: Partner closely with technical teams to embed security controls, privacy-by-design, and cloud best practices directly into our development lifecycle and API-first platform.
  • Support Enterprise Sales Readiness: Assist in answering complex enterprise customer security questionnaires, supporting third-party risk reviews, and demonstrating vivenu's robust compliance posture during high-value sales engagements.
  • Governance & Executive Reporting: Translate complex technical and regulatory findings into clear risk posture dashboards, KRIs, and operational updates for leadership.

What you will need to succeed in this role:

  • Execution & Program Management: Proven track record of getting things done: driving cross-functional projects, aligning diverse technical and business stakeholders, and holding teams accountable to deliverables.
  • Audit Leadership Experience: Hands-on experience leading major compliance audits (e.g., SOC 2, PCI DSS, ISO 27001) from start to finish as the internal counterpart and owner.
  • Domain Context: Prior experience in SaaS, Fintech, or cloud-native technology environments is highly preferred. If your background is from another sector, a strong curiosity and fast-learning mindset toward modern cloud, API, and SaaS architectures is required.
  • GRC Experience: demonstrated exposure to GRC and Security processes such as risk assessments, internal audits, policy development, corrective actions management.
  • Framework Familiarity: Solid working knowledge of core industry standards and frameworks (e.g., SOC 2, PCI DSS, ISO 27001, GDPR, NIST CSF/RMF).
  • Communication & Influence: Outstanding ability to translate regulatory requirements into clear operational steps, communicating effectively with both deep technical experts and business executives.
  • Languages: Business fluency in English is required.
  • Nice to have:

  • Technical Aptitude: Basic hands-on technical familiarity (e.g., basic scripting, working with APIs, or reading system logs/configurations) is a big plus.
  • Exposure to GRC automation tools (e.g., Vanta, Drata, ServiceNow IRM, or LogicGate).
  • Relevant professional certifications such as CRISC, CISA, CISM, CISSP, CSSP or ISO/IEC 27001 Lead Auditor.
  • German language proficiency would be a plus.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
408,526 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
Remote/Hybrid • 10+ years exp • Bachelor's Degree • Hyderabad
AI/ML
ISO 42001
DevOps
Incident Management
Cybersecurity
GDPR
HIPAA
ISO 27001
NIST 800-171
SOC 2
Apply
$160k – $190k per year • In office • 8+ years exp • Bachelor's Degree
PowerShell
Python
AI/ML
AI Agents
DevOps
AWS
Azure
CI/CD
CloudFormation
GCP
IAM
Rest API
Terraform
Cybersecurity
Delinea
HashiCorp Vault
HIPAA
ISO 27001
Least Privilege
Microsoft Entra ID
Okta
PCI DSS
Cryptography
Vault
Apply
$180k – $322k per year • In office • 15+ years exp • Bachelor's Degree • Herndon
Python
DevOps
Ansible
AWS
Azure
CI/CD
FinOps
GCP
Red Hat
Terraform
Cybersecurity
FedRAMP
SOC 2
Zero Trust
Management
Google Workspace
ServiceNow
Apply
$129k – $215k per year • In office • 5+ years exp • Bachelor's Degree
Cybersecurity
ISO 27001
Apply
In office • 3+ years exp • Bachelor's Degree
Cybersecurity
GDPR
Apply
$78k – $173k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Go
TypeScript
AI/ML
Red Teaming
DevOps
ArgoCD
AWS
Azure
CI/CD
GCP
GitHub
GitOps
Kubernetes
Shift-Left
Terraform
Cybersecurity
EPSS
PCI DSS
Shift-Left Security
Threat Modeling
Apply
In office • Full-Time • 7+ years exp • Zurich
Apply
$140k – $180k per year • In office • Full-Time • 7+ years exp • New York
Management
Notion
Apply
$240k – $280k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • New York
Apply
Financial Accountant 11 days ago
In office • Full-Time • 2+ years exp • Bachelor's Degree • Düsseldorf
Apply
See all jobs
This is one of many
408,526 more open roles from verified company boards, updated every day.