Senior Consultant GRC Engineering (m/f/d)
GRC Engineering is a new field in Cybersecurity that moves stale Governance, Risk and Compliance processes into the age of Cloud and AI. We want to support our clients in upgrading their GRC processes through technical excellence in modern software development and our consultative approach with a strong ownership mindset.
We're primarily looking to hire in Germany but may be open to other EU countries for the perfect candidate.
Activities
- Support clients with building and implementing modern Governance, Risk and Compliance Programs
- Use modern technology, including public cloud and AI, to accelerate our client's GRC programs
- Deliver individual workstreams in Cybersecurity projects independently
- Develop high-quality deliverables - this explicitly includes code, ranging from simple scripts to full web applications - but also presentations, workshops and written reports
- Engage with internal stakeholders as a representative of our clients
- Extend our client relationships
Requirements
- At least 3 years of experience in Cybersecurity or IT Compliance consulting in a high-performing team
- Hands-on experience in software development, cloud security, red teaming, detection engineering or similar modern approaches to solve security problems
- First experience leading consulting projects or workstreams
- Understanding of major Cybersecurity regulations, such as NIS2, DORA or the Cyber Resilience Act
- Experience with modern technology stacks, including but not limited to programming languages, Public Cloud, CI/CD pipelines and AI agents
- Interest and experience in management- and/or technology-related topics surrounding Cybersecurity, such as economics, social sciences, software development, cloud and AI technologies or anything else that expands your viewpoint
- Strong ownership and self-starter attitude
Team
Why Work for Us
We are a young consulting start-up, so we understand that you're taking a risk with us. We still think the rewards outweigh the risks by a mile. Here is why you should join Envoy Security:
Salary
- Your salary will be made up of a base component and an uncapped bonus (based on your engagement profitability, business development successes and project management responsibilities)
- You get to decide how much of your salary you want to take as variable pay and how much as base pay (in a range of 10% to 30% variable) - the higher the variable component, the higher the profit share you can participate in
- Your bonus is paid out quarterly - no waiting a whole year until your hard work pays off
- We're happy to provide any gross salary conversion option that fits your lifestyle; be it a pension scheme, taking over costs for daycare or other benefits: we'll help you get the most out of your salary
Impact
- You get to directly influence the culture and structure of a newly founded company
- You get to work on some of the most interesting challenges on the intersection of technology, risk, business and regulation
- Learning is not just encouraged, it's expected; we of course pay for relevant certifications and courses
- We're working regularly on Interim CISO engagements; if you're interested in becoming a CISO or just want to be a better consultant, you'll have trouble finding similar exposure
The job is remote first, which means we don't offer a fruit bowl in the office - sorry about that.
Travel to client locations will be required - depending on the specific client and project this can be only twice throughout the entire engagement or several times a week - that is the unpredictable nature of the consulting job.
What we can promise is that we will always consider your personal circumstances when discussing travel frequency in a project.
Startups are not for everyone. We move fast, solve difficult problems, and adapt quickly. If you want to shape both the business and your own career, this is your opportunity to do it.
We believe diverse teams create stronger solutions. We encourage applicants from non-traditional backgrounds. Bring your whole self with your own identity and perspectives.
Application Process
The hiring process consists of 1-2 interviews.
The interview will include technical questions about technical security and GRC, as well as about your problem-solving skills