Senior GRC Analyst
Want this job? Aria tailors your résumé to this role and submits the application on the employer's own platform — on your behalf. Free to start.
About this role
We power people’s progress. At Preply, we’re all about creating life-changing learning experiences. We help people discover the magic of the perfect tutor, craft a personalised learning journey, and stay motivated to keep growing. Our approach is human-led, tech-enabled - and it’s creating real impact. We’ve just reached unicorn status with a $150M Series D, accelerating our vision to transform education through human-led, AI-enhanced learning. Today, 100,000+ tutors teach 90+ languages to learners in 180 countries - and we’re only getting started. As a category-defining company, we’re shaping what the future of learning looks like at global scale. Every Preply lesson sparks change, fuels ambition, and drives progress that matters. Joining Preply means helping define the future of education at global scale, and building something that truly matters for millions of people, every day. Meet the team! Preply is seeking a Senior GRC Analyst to join our Cybersecurity team and participate in one of the most business-critical functions in our fast-growing global company. This is an opportunity to shape and scale our governance, risk, and compliance (GRC) program. You'll report to Director of Security and work closely with a small, high-impact Cybersecurity team. The role will be central to maintaining and expanding our risk management program, sustaining compliance with industry standards (especially SOC 2 Type 2), and building scalable governance processes to reduce identified risks. You’ll work cross-functionally with Legal, Engineering, Security, Product, Finance, and company leadership. The ideal candidate brings deep risk and compliance expertise, thrives in ambiguity, and is energized by building secure, scalable systems that support business growth. What you will be doing: Maintain and continuously improve the risk management framework. Manage and continuously improve Preply's risk management framework, defining risk management approaches and overseeing the implementation of mitigation actions across the business. Lead risk assessments. Run enterprise risk assessments, surfacing both technical and non-technical risks, and track Key Risk Indicators (KRIs) and other data-driven risk metrics to report to leadership. Manage third-party risk. Maintain a third-party risk management program and perform periodic vendor reviews to ensure suppliers meet Preply's security bar. Help shape governance and policy. Participate in developing and maintaining security, AI, and compliance policies in collaboration with Legal, Security, and Data teams, embedding governance checks into everyday business operations. Drive SOC 2 and beyond. Support compliance initiatives for SOC 2 Type 2, with potential expansion to ISO 27001, ensuring controls are documented, tested, and audit-ready. Support privacy initiatives. Contribute to data retention policies and guidelines for how different departments handle personal data. Be the cross-functional bridge. Support coordination between Cybersecurity, Legal, and Engineering - translating regulatory requirements (GDPR, CCPA, etc.) into actionable policies, and supporting internal/external audits, policy reviews, and compliance syncs. Champion security culture. Drive security awareness and compliance culture across the company. Automate GRC operations. Identify opportunities to use AI tools to automate and streamline risk and compliance workflows (e.g. evidence collection, control monitoring, reporting). What you need to succeed: 5+ years in GRC, risk management, compliance, or cybersecurity - preferably in a tech or SaaS environment. A flexible background, which could include: Engineering or technical roles with exposure to platform risk/security. Legal or compliance roles, ideally with a specialization in cybersecurity or privacy. Hybrid profiles (e.g., lawyers with CISSP, or engineers with compliance experience). A proven track record in: SOC 2 implementation (must-have). Experience with frameworks/standards such as ISO 27001, ISO 27701, PCI DSS, or similar Experience with regulations such as GDPR, CCPA, COPPA, EU AI Act, or similar. Risk assessments and KRIs. Cross-functional collaboration and stakeholder management. Core Competencies Strong understanding of cloud security and modern SaaS risk landscapes. Ability to translate regulatory requirements into practical, business-friendly policies. Effective communicator with experience in running cross-functional sessions. Practical experience applying AI tools in day-to-day work. Experience with GRC/compliance automation tooling is a plus. Certifications (nice to have, not required): CISA, CISM, CISSP, CRISC, ISO 27001 Lead Auditor, CIPM. Why you’ll love it at Preply An open, collaborative, dynamic and diverse culture; A generous monthly allowance for lessons on Preply.com , Learning & Development budget and time off for your self-development; A competitive financial package with equity, leave allowance and health insurance; Access to free ment
Stop filling out applications one by one.