TryHackMe-logo
Arvioitu kuukausipalkka
Arvioitu €5 833 - €9 119
Julkaistu 25. elokuuta 2026 · 3 päivää sittenViimeksi nähty 27. elokuuta 2026Arvioitu päättymispäivä 29. syyskuuta 2026

GRC Content Engineer

Senior GRC Content Engineer
Kuinka tämä palkka vertautuu muihin
Palkkayhteys: GRC Content Engineer

Vie hiiri rivin päälle tai napauta riviä nähdäksesi täydelliset tilastot (EUR / kk tässä kaaviossa).

Tietoa tehtävästä

TryHackMe is the fastest-growing online cyber security training platform. Our mission is to make learning and teaching cyber security easier by providing gamified security exercises and challenges. Having only been around for handful of years, we've grown to more than 4 million community members and our growth isn't slowing down! 🥷The RoleWe're looking for a <strong>Senior GRC Content Engineer</strong> to help us build something our first GRC path, and lay the groundworks for everything than comes after it. We think people should learn GRC the way they learn everything else on TryHackMe: by <em>doing</em> it. Running a risk assessment, operating an ISMS, facing a simulated auditor, drafting a regulator notification with the 24-hour clock running.This is a senior role that demands <strong>deep, practitioner-level GRC expertise combined with a genuinely creative, teaching-oriented mind</strong>. You'll join a small squad (working directly with our GRC squad lead, who is also a senior GRC practitioner) to research, design, and build learning paths covering EU cyber regulation (NIS2, DORA, the Cyber Resilience Act), ISO 27001 and ISMS implementation, audit readiness, third-party risk, and cyber crisis management.The ideal candidate has lived this work - you've implemented or operated an ISMS, survived certification and surveillance audits, written risk registers people actually used, and translated regulation into controls a real organisation could run. You have also done this in a modern, AI-conscious environment, that's not governed by a spreadheet nobody updated since 2012. Just as importantly, you can turn that experience into interactive, scenario-driven learning experiences. Room building isn't easy: it's part instructional design, part scenario writing, part product thinking. If you've ever looked at compliance training and thought "I could make this genuinely engaging," this role is for you.TTechnical Skills & ExperienceTo be considered for this opportunity, you must have at least <strong>5+ years of hands-on GRC / information security experience</strong> in roles such as:GRC Analyst / GRC Manager, Information Security Officer / Manager, ISMS Owner, Compliance Manager, IT/Security Internal Auditor, or Security & Compliance ConsultantMandatory GRC skills — you must be able to demonstrate:<strong>Practical, implementation-level experience with ISO/IEC 27001</strong> (2022 control set): scoping, risk assessment and treatment, Statement of Applicability, running or facing internal and certification audits — not just framework literacyWorking knowledge of the <strong>EU cyber regulatory landscape</strong>: NIS2 and its Article 20/21/23 obligations, DORA for financial entities, and awareness of the Cyber Resilience Act — including how organisations operationalise these in practiceStrong grounding in <strong>risk management practice</strong>: qualitative assessment methods, risk registers, controls and control types, risk treatment and residual risk sign-offExperience with <strong>audit and evidence workflows</strong>: what auditors ask for, how evidence is collected and presented, findings and management responsesFamiliarity with <strong>third-party / vendor risk</strong>: due-diligence questionnaires, reading SOC 2 reports, contractual security requirementsA solid understanding of the technical side of security (networks, systems, cloud, common attack patterns) — enough to keep GRC content grounded in how security actually works, and to collaborate credibly with our technical content engineersExcellent written English — you will write a lot, and the writing must teach<strong>You should also demonstrate:</strong>Proven ability to <strong>research and synthesise</strong>: new regulations, framework revisions, enforcement trends, and competitor coverage — and turn that research into build decisionsA <strong>creative, learner-first mindset</strong>: you can take a dry obligation ("Article 23 incident reporting") and design an exercise with real tension in it (a branching incident where the notification clock is running)<p>Comfort with ambiguity - this is a new content stream being built from the ground up, and you'll help shape what "hands-on GRC" even means</p>ResponsibilitiesResearch, design, and develop GRC training rooms, modules, and learning paths — including hands-on artifacts such as risk register exercises, Statement of Applicability labs, audit simulations, DDQ challenges, regulator-notification drills, and branching tabletop scenariosAct as a <strong>subject-matter expert</strong> across ISO 27001/ISMS, EU regulation (NIS2, DORA, CRA), risk management, and audit readiness — owning technical accuracy across the GRC portfolio alongside the squad leadBuild and maintain lab environments using open-source GRC tooling (e.g. Eramba) and THM-built interactive widgets, working with our platform and design teams where neededTake charge of planning and designing portions of the GRC content roadmap, and pressure-test scoping decisions with data (customer requests, demand signals, competitive gaps)Track regulatory change (implementing acts, national transpositions, framework revisions) and keep shipped content current — GRC content that goes stale is worse than no contentGuide and review the work of contractors and other content engineers contributing to GRC builds; elevate quality and consistency across the streamCollaborate with Content Engineering leadership to continuously improve the content development process, and with Sales/CS to make sure what we build matches what enterprise customers are asking forPreferred Skills (nice-to-have)Instructional design or training-delivery experience — you've taught this material to real audiences (workshops, bootcamps, internal training, university teaching)Experience designing or facilitating <strong>tabletop exercises</strong> or crisis simulationsExposure to SOC 2 (Type 2) readiness or audit support, PCI-DSS, or sector frameworks (HIPAA, CMMC, Cyber Essentials)Familiarity with GRC platforms (Drata, Vanta, OneTrust, ServiceNow GRC, AuditBoard)Experience using AI tools in GRC workflows (policy drafting, evidence mapping, report summarisation) — and a clear view of where human sign-off must stayScripting or light programming (Python, Bash) for building exercises and widgetsBackground in CTF or gamified content designCertifications such as <strong>CISSP, CISM, CISA, CRISC, CGRC, ISO/IEC 27001 Lead Implementer / Lead Auditor, CIPP/E</strong> are appreciated — practical experience matters moreBenefits & Perks: 100% Remote - In a fully digital world, work from anywhere you want!; Flexi Time - Choose your own hours as long as you have at least 4 hours of overlap with the UK timezone (from 8am - 6pm); Tools - a dedicated work laptop + any accessories you need to do your best work.; Swag Pack - start your TryHackMe journey with a branded swag bundle!; Personal Development - £2,500 training budget to acquire certifications, and more.; Company Retreat - an annual company retreat, fully paid for by us!; Health Insurance - if you're in a country that doesn't have public health care.; Enhanced Maternity & Paternity- an enhanced package on top of statutory requirements.; 401k / Pension - TryHackMe makes it easy to save money for your retirement.; Our Hiring Process Stage 1: Short introduction call (30 mins) Stage 2: Take Home Exercise — design a hands-on GRC learning exercise from a scenario brief Stage 3: Technical interview with the GRC squad lead (one hour) Stage 4: Final call with a Co-Founder (30 mins) At this time, we are unable to provide sponsorship.

TryHackMe-logo
TryHackMe · 43 avointa tehtävää
Suosituimmat sijainnit: Etätyö - Globaali · 36 · Lontoo, Yhdistynyt kuningaskunta · 1 · Ettyö - Globaalisti · 1+5 muuta sijaintia
Näytä yritysprofiili
Tämänhetkiset avoimet roolit yrityksessä TryHackMe JobCrawls-palvelussa
SijaintiAktiiviset ilmoitukset
Etätyö - Globaali36
Lontoo, Yhdistynyt kuningaskunta1
Ettyö - Globaalisti1
Ete4tyf6 - Maailmanlaajuinen1
Etätyö - Maailmanlaajuinen1
Koko maailma - Etätyö1
Remote1
Etätyö - Suomi1
Nykyinen roolien jakauma yrityksessä TryHackMe JobCrawls-palvelussa
RoolityyppiAktiiviset ilmoitukset
Tuotepäällikkö4
Data-analyytikko3
Account Manager2
Oikeudellinen neuvonantaja2
Customer Success Manager2
Content Marketing Manager1
Kyberturvallisuuden kouluttaja1
Kyberturvallisuus Sisältöinsinööri1
Digital Customer Success Manager1
AI-insinööri1
Suunnittelija1
Kasvumarkkinointipäällikkö1
Ohjelmistoinsinööri1
Kyberturvallisuuden sisältöinsinööri1
Tuotejohtaja1
GRC Content Engineer1
Offensive Security Engineer1
Kasvutuotteiden suunnittelija1
Software Engineer1
Kasvupäällikkö1
Windows IR-asiantuntija1
Myynninedistäminen1
Tuotepe4e4llikkf61
Tuotesuunnittelija1
Sopimuspäällikkö1
Johtaja1
Insinööri1
Government Customer Success Manager1
Henkilöstöammattilainen1
Tietoturva-asiantuntija1
Sisällön insinööri1
QA Content Engineer1
Kasvumarkkinoija1
Talouspäällikkö1
Nykyinen roolitasojen jakauma yrityksessä TryHackMe JobCrawls-palvelussa
RoolitasoAktiiviset ilmoitukset
Keskitaso19
Manageri7
Senior-taso4
Junior ja entry-taso1

Auta meitä parantamaan JobCrawlsia — kirjaudu sisään synkronoidaksesi tallennetut työpaikat laitteiden välillä, tai lähetä palautetta milloin tahansa.