Preply

Senior GRC Analyst

Barcelona · Posted 2h ago

salary not listedseniorpermanenthybrid
SOC

Job Description

We power people’s progress.

At Preply, we’re all about creating life-changing learning experiences. We help people discover the magic of the perfect tutor, craft a personalised learning journey, and stay motivated to keep growing. Our approach is human-led, tech-enabled - and it’s creating real impact.

We’ve just reached unicorn status with a $150M Series D, accelerating our vision to transform education through human-led, AI-enhanced learning. Today, 100,000+ tutors teach 90+ languages to learners in 180 countries - and we’re only getting started. As a category-defining company, we’re shaping what the future of learning looks like at global scale.

Every Preply lesson sparks change, fuels ambition, and drives progress that matters. Joining Preply means helping define the future of education at global scale, and building something that truly matters for millions of people, every day.

Meet the team!

Preply is seeking a Senior GRC Analyst to join our Cybersecurity team and participate in one of the most business-critical functions in our fast-growing global company. This is an opportunity to shape and scale our governance, risk, and compliance (GRC) program.

You'll report to Director of Security and work closely with a small, high-impact Cybersecurity team. The role will be central to maintaining and expanding our risk management program, sustaining compliance with industry standards (especially SOC 2 Type 2), and building scalable governance processes to reduce identified risks.

You’ll work cross-functionally with Legal, Engineering, Security, Product, Finance, and company leadership. The ideal candidate brings deep risk and compliance expertise, thrives in ambiguity, and is energized by building secure, scalable systems that support business growth.

What you will be doing:

  • Maintain and continuously improve the risk management framework. Manage and continuously improve Preply's risk management framework, defining risk management approaches and overseeing the implementation of mitigation actions across the business.

  • Lead risk assessments. Run enterprise risk assessments, surfacing both technical and non-technical risks, and track Key Risk Indicators (KRIs) and other data-driven risk metrics to report to leadership.

  • Manage third-party risk. Maintain a third-party risk management program and perform periodic vendor reviews to ensure suppliers meet Preply's security bar.

  • Help shape governance and policy. Participate in developing and maintaining security, AI, and compliance policies in collaboration with Legal, Security, and Data teams, embedding governance checks into everyday business operations.

  • Drive SOC 2 and beyond. Support compliance initiatives for SOC 2 Type 2, with potential expansion to ISO 27001, ensuring controls are documented, tested, and audit-ready.

  • Support privacy initiatives. Contribute to data retention policies and guidelines for how different departments handle personal data.

  • Be the cross-functional bridge. Support coordination between Cybersecurity, Legal, and Engineering - translating regulatory requirements (GDPR, CCPA, etc.) into actionable policies, and supporting internal/external audits, policy reviews, and compliance syncs.

  • Champion security culture. Drive security awareness and compliance culture across the company.

  • Automate GRC operations. Identify opportunities to use AI tools to automate and streamline risk and compliance workflows (e.g. evidence collection, control monitoring, reporting).

What you need to succeed:

  • 5+ years in GRC, risk management, compliance, or cybersecurity - preferably in a tech or SaaS environment.

  • A flexible background, which could include:

    • Engineering or technical roles with exposure to platform risk/security.

    • Legal or compliance roles, ideally with a specialization in cybersecurity or privacy.

    • Hybrid profiles (e.g., lawyers with CISSP, or engineers with compliance experience).

  • A proven track record in:

    • SOC 2 implementation (must-have).

    • Experience with frameworks/standards such as ISO 27001, ISO 27701, PCI DSS, or similar

    • Experience with regulations such as GDPR, CCPA, COPPA, EU AI Act, or similar.

    • Risk assessments and KRIs.

    • Cross-functional collaboration and stakeholder management.

Core Competencies

  • Strong understanding of cloud security and modern SaaS risk landscapes.

  • Ability to translate regulatory requirements into practical, business-friendly policies.

  • Effective communicator with experience in running cross-functional sessions.

  • Practical experience applying AI tools in day-to-day work.

  • Experience with GRC/compliance automation tooling is a plus.

Certifications (nice to have, not required): CISA, CISM, CISSP, CRISC, ISO 27001 Lead Auditor, CIPM.

Why you’ll love it at Preply

  • An open, collaborative, dynamic and diverse culture;

  • A generous monthly allowance for lessons on Preply.com, Learning & Development budget and time off for your self-development;

  • A competitive financial package with equity, leave allowance and health insurance;

  • Not in Barcelona? We offer an attractive relocation package to join us in our Preply Barcelona Hub;

  • Access to free mental health support platforms;

  • Access to Gympass-partnered wellness and gym centers throughout Spain to promote and support well-being and physical health;

  • The opportunity to shape the lives of learners and tutors through language learning and teaching in 175 countries (and counting!).

Our Principles

  • Care to change the world - We are passionate about our work and care deeply about its impact to be life changing.

  • We do it for learners - For both Preply and tutors, learners are why we do what we do. Every day we focus on empowering tutors to deliver an exceptional learning experience.

  • Keep perfecting - To create an outstanding customer experience, we focus on simplicity, smoothness, and enjoyment, continually perfecting it as every detail matters.

  • Now is the time - In a fast-paced world, it matters how quickly we act. Now is the time to make great things happen.

  • Disciplined execution - What makes us disciplined is the excellence in our execution. We set clear goals, focus on what matters, and utilize our resources efficiently.

  • Dive deep - We leverage business acumen and curiosity to investigate disparities between numbers and stories, unlocking meaningful insights to guide our decisions.

  • Growth mindset - We proactively seek growth opportunities and believe today's best performance becomes tomorrow's starting point. We humbly embrace feedback and learn from setbacks.

  • Raise the bar - We raise our performance standards continuously, alongside each new hire and promotion. We build diverse and high-performing teams that can make a real difference.

  • Challenge, disagree and commit - We value open and candid communication, even when we don’t fully agree. We speak our minds, challenge when necessary, and fully commit to decisions once made.

  • One Preply - We prioritize collaboration, inclusion, and the success of our team over personal ambitions. Together, we support and celebrate each other's progress.

Diversity, Equity, and Inclusion

Preply.com is committed to creating an inclusive environment where people of diverse backgrounds can thrive. We believe that the presence of different opinions and viewpoints is a key ingredient for our success as a multicultural Ed-Tech company. That means that Preply will consider all applications for employment without regard to race, color, religion, gender identity or expression, sexual orientation, national origin, disability, age or veteran status.