Back to Jobs
vivenu
Development 12h ago

GRC Program Manager

vivenu
GermanyGermany
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

QA Engineer1h 50mFree Trial ✨
Start 10-Day Free Trial
Backend42mFree Trial ✨
Start 10-Day Free Trial
DevOps1h 38mFree Trial ✨
Start 10-Day Free Trial
CybersecurityAutomation Engineer

Want to know if you're a match for this job?

Calculate My Match Score

As our GRC Program Manager, you will be the driving force behind vivenu’s Governance, Risk, and Compliance execution. This is fundamentally an execution- and delivery-focused role: you are a true program manager who knows how to get things done yourself while driving cross-functional accountability across Engineering, Product, Legal, and Security teams.

You will lead our GRC initiatives end-to-end, driving audit strategy, owning internal risk workflows, and managing complex compliance projects across the organization. By translating regulatory and framework requirements into actionable, practical business processes, you will ensure vivenu continues to scale securely and responsibly across global markets without sacrificing developer velocity.

Responsibilities:

  • Drive Program Execution & Ownership: Take full end-to-end accountability for GRC deliverables, setting timelines, tracking cross-functional dependencies, and orchestrating teams to ensure compliance milestones are hit on schedule.
  • Lead Internal Audit Operations: Serve as the primary internal leader and project owner for third party audits (e.g., SOC 2 Type II, PCI DSS). Own the process from scoping to successful completion, managing evidence collection, guiding control owners, and leading remediation efforts.
  • Build & Scale Compliance Frameworks: Maintain and mature robust compliance frameworks, ensuring continued preparation for evolving global requirements such as GDPR and related security standards.
  • Manage Risk & Remediation Workflows: Conduct practical IT, security, and third-party risk assessments. Maintain vivenu’s risk register, ensuring risk treatment plans and corrective actions are actively assigned, tracked, and closed out by control owners.
  • Optimize GRC Operations & Tooling: Leverage modern GRC platforms and automation tools to streamline audit tracking, policy administration, vendor risk management and issue remediation workflows.
  • Enable Engineering & Product Teams: Partner closely with technical teams to embed security controls, privacy-by-design, and cloud best practices directly into our development lifecycle and API-first platform.
  • Support Enterprise Sales Readiness: Assist in answering complex enterprise customer security questionnaires, supporting third-party risk reviews, and demonstrating vivenu's robust compliance posture during high-value sales engagements.
  • Governance & Executive Reporting: Translate complex technical and regulatory findings into clear risk posture dashboards, KRIs, and operational updates for leadership.

What you will need to succeed in this role:

  • Execution & Program Management: Proven track record of getting things done: driving cross-functional projects, aligning diverse technical and business stakeholders, and holding teams accountable to deliverables.
  • Audit Leadership Experience: Hands-on experience leading major compliance audits (e.g., SOC 2, PCI DSS, ISO 27001) from start to finish as the internal counterpart and owner.
  • Domain Context: Prior experience in SaaS, Fintech, or cloud-native technology environments is highly preferred. If your background is from another sector, a strong curiosity and fast-learning mindset toward modern cloud, API, and SaaS architectures is required.
  • GRC Experience: demonstrated exposure to GRC and Security processes such as risk assessments, internal audits, policy development, corrective actions management.
  • Framework Familiarity: Solid working knowledge of core industry standards and frameworks (e.g., SOC 2, PCI DSS, ISO 27001, GDPR, NIST CSF/RMF).
  • Communication & Influence: Outstanding ability to translate regulatory requirements into clear operational steps, communicating effectively with both deep technical experts and business executives.
  • Languages: Business fluency in English is required.
Nice to have:
  • Technical Aptitude: Basic hands-on technical familiarity (e.g., basic scripting, working with APIs, or reading system logs/configurations) is a big plus.
  • Exposure to GRC automation tools (e.g., Vanta, Drata, ServiceNow IRM, or LogicGate).
  • Relevant professional certifications such as CRISC, CISA, CISM, CISSP, CSSP or ISO/IEC 27001 Lead Auditor.
  • German language proficiency would be a plus.

How would you rate this job post?

See what other professionals think about this role.

banner

vivenu is the premier, enterprise-grade API-first event ticketing infrastructure, white-label commerce platform, and live entertainment analytics powerhouse engineered to serve as the definitive, unbranded operational layer for high-volume organizers and global venues. The company completely eliminates the severe systemic friction of traditional event ticketing—where major brands, sports leagues, and festival organizers face restrictive closed-loop marketplaces, predatory per-ticket fee dependencies, and total loss of customer data sovereignty—by deploying a flexible, headless ticketing architecture. Moving far beyond passive booking engines or third-party retail wrappers, vivenu natively unifies custom 2D/3D seatmap management engines, dynamic real-time pricing algorithms, fully embedded checkout flows, and specialized multi-tenant box office Point of Sale (POS) applications into a single unified workspace. Trusted by over 1,000 premier global brands—including the Grammy Awards, Stanford University Athletics, and prominent European football clubs like FC Schalke 04—the ecosystem empowers organizers to scale their distribution networks, enforce strict GDPR data compliance structures, and optimize on-site entry operations with elite, data-backed precision. Under the hood, its sophisticated technical core—backed by $66 million in capital from premier venture firms like Balderton Capital, Activant Capital, and Redalpine—natively orchestrates robust high-concurrency ingestion pipelines built to handle high-demand on-sales without performance latency, alongside comprehensive ERP integrations and deep marketing data telemetry via Open REST APIs. What sets vivenu apart is its uncompromising dedication to replacing industry gatekeeping with absolute brand and technical autonomy; by bridging the gap between performance-intensive transaction engineering and fluidic, human-centric user experiences, the firm enables modern scaling entertainment networks to boost top-line digital revenue by up to 23%, eliminate ticketing bottlenecks, and unlock continuous commercial scalability worldwide.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More
GRC Program Manager at vivenu | HireSkys