Skip to main content
Omilia

Senior CGRC Operations Analyst

RemoteGreece, Portugal, Spain +2 more only
Published
Role
Security
Experience
Senior
Salary not disclosed
Check eligibility

Open to GR, PT, ES, RO, CZ only. Set where you work from to check your eligibility.

No BS summary

Compliance/GRC delivery role running Omilia's ISMS and cert portfolio (ISO 27001, SOC 2 Type II, GDPR) end to end. Must have 4–8 yrs in regulated B2B tech/SaaS and a mandatory ISO 27001 Lead Auditor or Lead Implementer credential. Based in Greece, Portugal, Spain, Romania or Czechia, with occasional travel to Greece.

Core skills

ISO 27001SOC 2 Type II

Required skills

SOC 2GDPRDORANIS2EU Data ActPCI-DSSC5Cyber EssentialsCGRC automation platformISO 27001 Lead Auditor/ISO 27001 Lead ImplementerSCCs/BCRs

Optional skills

HIPAACCPA/CPRA

Required languages

English Business fluency

What you'll do

  • Own the full lifecycle of ISO 27001, SOC 2 Type II, C5, PCI-DSS, and Cyber Essentials certifications: scoping, evidence, audit coordination, management responses, remediation tracking.
  • Own the GDPR operational compliance framework: DPIA process, DPIA and TIA governance, RoPA maintenance, breach response documentation, and cross-border transfer mechanisms.
  • Maintain active compliance frameworks for DORA, NIS2, HIPAA, CCPA/CPRA, and the EU Data Act, including current obligation tracking and client assurance artefacts.
  • Own breach incident response governance end to end: process, regulatory notification decision support, Art. 33/34 documentation, and the regulatory notification register.
  • Manage the ISMS evidence library and certification body relationships.
  • Coordinate SOC 2 Type II readiness: TSC scoping, evidence collection, auditor engagement, report distribution, management response drafting.
  • Maintain the RoPA, conduct DPIAs and LIAs, and manage data subject rights governance under GDPR.
  • Track and implement obligations under DORA, NIS2, HIPAA, CCPA/CPRA, EU Data Act, and Cyber Resilience Act as live regulatory requirements.
  • Coordinate BAA execution and PHI obligation documentation with Legal for healthcare accounts.
  • Run compliance deliverable tracker; close loops on evidence collection.
  • Translate regulatory obligations into plain-language business impact and secure timely responses from technical and product stakeholders.
  • Manage end-to-end coordination of client compliance audits: evidence packs, management responses, findings remediation.
  • Maintain and administer the CGRC automation platform: uploading evidence and monitoring control status.

What they require

  • 4 to 8 years in the CGRC field, with the majority in regulated B2B technology or SaaS environments.
  • ISO 27001 Lead Auditor or Lead Implementer credential (mandatory).
  • Demonstrated end-to-end SOC 2 Type II ownership: scoping, evidence coordination, auditor management, and management response — not just participation.
  • GDPR practitioner depth: DPIA, RoPA, data subject rights, cross-border transfer mechanisms (SCCs, BCRs), regulation-level fluency.
  • Active working knowledge of DORA and NIS2 as live compliance obligations.
  • Experience with a CGRC automation platform at an operational level, not just as a user.
  • Familiarity with HIPAA BAA coordination and US state privacy law tracking (CCPA/CPRA) is a strong advantage.
  • Degree in Law, Business, Information Systems, or equivalent professional experience.

Benefits

  • Fixed compensation.
  • Long-term employment with vacation days.
  • Professional growth: courses, training.
  • Part of successful cutting-edge technology products with global impact in the service industry.
  • Proficient and fun-to-work-with colleagues.
  • Apple gear.
  • Equal opportunity employer — diverse and inclusive workplace.

Omilia provides an AI-powered contact centre automation platform and advanced contact center solutions.

AIMid-size
Salary not disclosed