Security GRC Manager

Open 0d

About us

Humaans is building the next generation of infrastructure for the workplace; software designed for companies that are scaling fast, operating globally, and pushing into new boundaries.

What started as a system of record has evolved into a broader platform for operating people globally. With Athena, our agentic AI layer, Humaans moves beyond data management into intelligent orchestration, connecting workflows across HR, IT, Finance, and Operations so organisations can act faster and with greater confidence, redefining how work gets done.

We work with ambitious teams across Europe and the US, from AI-native companies like Lovable, Poolside, Fyxer AI, and Tandem Health, to established, high-growth organisations scaling internationally and through acquisition, including Quantexa, Sellpy, Manychat, Gigs, Croud, and Threecolts. These teams don’t buy software for features,they buy leverage. The ability to run faster, cleaner, and with more control as complexity compounds.

To date, we’ve raised $20m in venture funding from some of the most respected founders, operators, and funds in technology: Lachy Groom (Physical Intelligence), Stewart Butterfield (Slack), Tobias Lütke (Shopify), Dylan Field (Figma), Jeff Weiner (LinkedIn), Claire Johnson (Stripe), Oliver Jay (OpenAI), Jay Simmons (Bond) as well as Y Combinator, Moonfire, Frontline Ventures, Pathlight Ventures, and Exor.

If you have massive ambition and want to work on a hard problem, with a small team that moves fast, at a moment when the category is genuinely up for grabs - this is it.

The role

We’re looking for a Security GRC Manager to own the systems, processes, audits and customer-facing trust work that help Humaans scale into more demanding markets.

This is a hands-on ownership role, built around AI. You’ll run our security compliance programme throughout the year, not just during audit season. You’ll own the operating rhythm across frameworks such as ISO 27001, SOC 1, SOC 2 and HIPAA, keeping evidence organised, controls running, policies current, risks visible and audits moving smoothly.

You’ll also own the commercial trust layer. You’ll work directly with enterprise buyers through security reviews, questionnaires, procurement processes and diligence, making sure security builds confidence rather than slowing deals down. Fast, accurate and reusable is the standard.

AI should give you leverage across all of this. You’ll use it to draft and maintain policies, accelerate questionnaire responses, keep evidence current and build systems that make repeated trust work faster without compromising quality.

The role sits across Security, Legal, Product, Engineering, Revenue and Operations. You don’t need to configure every system yourself, but you do need to understand how modern SaaS companies operate, ask sharp questions, drive action across teams and know the difference between meaningful risk reduction and compliance theatre.

What you’ll do

  • Own Humaans’ security compliance programme end to end, including ISO 27001, SOC 1, SOC 2, HIPAA and future frameworks we choose to pursue

  • Run audit cycles throughout the year, coordinating external auditors and internal control owners across Engineering, People, Legal, Finance and Operations

  • Maintain the controls, evidence, policies, risk register, access reviews, vendor reviews, business continuity processes and incident response documentation that support our certifications and customer commitments

  • Build AI into the day-to-day operation of our compliance programme, using it to draft and update artefacts, maintain evidence and reduce manual work

  • Own customer-facing trust work across sales calls, security reviews, procurement, vendor questionnaires, RFPs, DPAs, subprocessors, data protection questions and enterprise diligence

  • Build AI-assisted systems that help us answer recurring security questions quickly and accurately, while maintaining a strong review process as volume grows

  • Keep our trust collateral, answer libraries and customer-facing security information accurate, current and reusable

  • Partner with Product and Engineering to translate compliance requirements into practical operational controls without creating unnecessary friction

  • Help teams make clear, risk-based decisions, escalating issues that genuinely matter and cutting through noise when they don’t

  • Raise the maturity of how Humaans approaches security, privacy, risk and customer trust as we move upmarket

  • Make security compliance a commercial asset, with stronger evidence, cleaner controls, faster responses and clear ownership helping us win and grow

What we’re looking for

  • 4+ years of experience across security compliance, GRC, trust, audit, information security, privacy operations or a closely related area

  • Hands-on experience running or supporting audits across frameworks such as SOC 2, ISO 27001, SOC 1, HIPAA or GDPR

  • Direct experience supporting enterprise sales, procurement, RFPs or security reviews, with the confidence to lead customer conversations and give buyers clear, credible answers

  • AI is already part of how you work. You can point to systems or workflows you’ve built and explain how they improved things such as policy drafting, questionnaire turnaround or vendor reviews

  • Strong written communication skills, with the ability to produce crisp policies, questionnaire responses, audit narratives and internal guidance that people actually understand

  • A strong understanding of how modern B2B SaaS companies operate across cloud infrastructure, access management, vendor management, product development, customer data and enterprise sales

  • Excellent organisation and attention to detail, particularly around evidence, control ownership, audit timelines and customer commitments

  • Strong judgement about risk, with the ability to distinguish meaningful security improvements from compliance theatre

  • The ability to work across teams, drive action and maintain a high bar without becoming a blocker

  • Comfort operating in a high-growth, high-ownership environment where the playbook continues to evolve

  • Experience building or owning a trust centre, customer-facing security portal or security questionnaire answer library

You may not be a great fit if

  • You think of compliance primarily as preparing for an annual audit rather than an operating programme that runs throughout the year

  • You prefer coordinating GRC work from a distance rather than owning the evidence, controls, questionnaires and processes yourself

  • You’re uncomfortable getting directly involved in customer and enterprise sales conversations about security, privacy and risk

  • You approach every compliance requirement as equally important rather than applying judgement based on actual risk and customer impact

  • You see AI as an occasional productivity tool rather than something that should materially improve how GRC work gets done

  • You need every process and ownership boundary to be established before you can make progress

  • You tend to treat Security and Compliance as gatekeepers rather than partners that help the company move quickly and responsibly

  • You’re uncomfortable holding teams accountable for controls, evidence and commitments when things need to get done

This is an in-person role. Our team comes together in the office Monday through Thursday, while most of the team collaborates in person on Mondays, Tuesdays, and Thursdays.

Package & Benefits

Early stage startups can be messy – we know that. We're putting effort in providing you with the best employee experience and a quality driven environment in exchange for trusting us.

  • Market-leading compensation that reflects your value

  • 25 days paid time off each year plus public holidays

  • Share Options with 5-year exercise window so you don’t feel pressure to exercise if you leave

  • Free Thursday lunches at HQ, quarterly team events, and company offsites.

  • Top tier private coverage for health, vision and dental care

  • A new MacBook and tools you need to do your best work

  • Enhanced parental leave with up to 16 weeks for primary and 4 weeks for secondary

  • Learning & development budget

Why Join Humaans Today?

HR tech is having its AI moment and we’re positioned to own it. Humaans started as a next-gen HRIS taking on large incumbents in a massive market. We’ve since evolved into something even bigger: an AI platform that sits across workforce data and automates the operational layer of HR entirely; the natural progression of what we’ve been building toward.

The product is highly differentiated. It’s built around a structured workforce data model that makes AI reliable in an HR context, something no one else has gotten right. Customers notice the difference immediately.

We’re backed by Y Combinator, Lachy Groom, Moonfire, Frontline Ventures, and operators who’ve built some of the most consequential software companies of the last decade: the founders of Slack, Figma, and Shopify, and Asana’s former CRO and Head of OpenAI International.

We’re a small team with an unapologetically high bar. It shows up in the product, in how we communicate, and in the standards we hold each other to.

Our Commitment to Diversity

At Humaans we’re looking for genuinely good people that are transparent and emphatic. We’re committed to providing equal opportunities, a diverse and inclusive work environment, and ensuring a fair interview process for everyone. You’re welcome to apply no matter your gender, ethnicity, sexual orientation, religion, civil or family status, age, disability, or race.

Privacy notice

We care about your privacy. When you apply for a role at Humaans, we’ll collect and process your personal data as part of our recruitment process. This includes things like your CV, contact details, and any other information you choose to share. We may also contact you about future opportunities. You can ask us to delete your data at any time. For more details, see our Privacy Policy.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available