Job
- Level
- Experienced
- Job Field
- IT, Security, Test/QA
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Berlin
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will develop automated control systems for compliance standards like SOC 2 and ISO 27001, closely collaborating with various teams to seamlessly integrate security and compliance.
Job Technologies
Your role in the team
- Taktile empowers financial institutions to transform into truly AI-native organizations. We're growing rapidly with enterprise customers across banks and insurance companies, and we're looking for a GRC Engineer.
- Operating in highly regulated markets means trust isn't a feature for us, it's the foundation of every customer relationship. As we scale into larger enterprise and fintech accounts, a strong, demonstrable security and compliance posture is what lets us win and keep that trust.
- As our GRC Engineer on the Platform Team, you'll own the controls, evidence, and processes that keep Taktile secure, compliant, and continuously audit-ready. You'll be the engineering-minded backbone of our compliance program, turning frameworks like SOC 2, ISO 27001, GDPR, and the EU AI Act into automated, continuously-monitored controls rather than one-off, point-in-time checklists.
- This is a cross-functional, high-leverage role. You'll partner with Security, Engineering, Product, and IT to close the gap between policy and control implementation, and with Sales, Legal, Support, and Leadership to make compliance a competitive advantage rather than a bottleneck.
- The ideal candidate pairs deep framework knowledge with the technical ability to automate it; fielding a complex customer security questionnaire in the morning and scripting AWS evidence collection in the afternoon.
- Own continuous compliance end-to-end; SOC 2, ISO 27001, and customer security reviews, keeping us audit-ready year-round rather than scrambling at renewal time.
- Manage and evolve the compliance roadmap, prioritizing initiatives against business and customer needs; own Vanta end-to-end, including tasks, documentation, integrations, and automated evidence collection.
- Leiten Sie vierteljährliche Zugriffskontrollen für alle Systeme in Zusammenarbeit mit IT und Engineering, wobei sichergestellt wird, dass die Ergebnisse bis zur Behebung verfolgt werden.
- Run vendor risk reviews and DPIAs for new tools (especially AI tooling) and help teams adopt new software quickly without compromising our risk posture.
- Serve as the technical voice on customer security questionnaires and DPAs, working alongside Sales and Legal to keep deals moving.
- Define and report compliance and risk KPIs to leadership, giving them a clear, ongoing view of our posture and where investment is needed.
- Partner with the Security Architect to identify and close gaps between written policy and actual control implementation.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Has owned a SOC 2 program end-to-end (must-have), ideally ISO 27001 too, from gap analysis through audit and maintenance; familiar with GDPR, PCI DSS, and the EU AI Act.
- Technically hands-on: comfortable scripting against AWS APIs to automate evidence collection, with a solid grasp of software development and security concepts.
- A strong writer and communicator who can turn around a 200-row security questionnaire quickly and accurately, and translate fluently between compliance and technical teams.
- DORA / EU AI Act / fintech regulatory exposure.
- Has shipped engineering-led automation (not just dashboards).
- Vertrautheit mit NIST CSF, CIS Controls oder GDPR/DPAs.
Experience
- 4+ years in GRC, security compliance, or audit readiness at a SaaS company, ideally in a regulated environment (Finance, Insurance, Healthcare).
- Deep experience running Vanta (or Drata/Secureframe) as a continuous compliance backbone, not a point-in-time checklist.
- Experience with customer trust programs (Trust Center, FAQs, security whitepapers).
This text has been machine translated. Show original
What we offer
- Work with colleagues that lift you up, challenge you, celebrate you and help you grow. We come from many different backgrounds, but what we have in common is the desire to operate at the very top of our fields.
- Make an impact and meaningfully shape an early-stage company.
- Experience a truly flat hierarchy and communicate directly with founding team members. Having an opinion and voicing your ideas is not only welcome but encouraged, especially when they challenge the status quo.
- Learn from experienced mentors and achieve tremendous personal and professional growth. Get to know and leverage our network of leading tech investors and advisors around the globe.
- Receive a top-of-market equity and cash compensation package.
- Get access to a self-development budget you can use to e.g. attend conferences, buy books or take classes.
- Use the equipment of your choice including meaningful home office set-up.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Topics You Will Work On
Job Locations
About Your Employer
Taktile GmbH
Taktile GmbH, an innovative company based in Berlin, offers an AI-driven platform for automating complex decision-making processes in the financial sector. This platform enables departments to efficiently automate decisions such as lending and fraud detection, while maintaining control and transparency. Since its founding in 2020, Taktile has positioned itself as an emerging startup in the fintech space.
Description
- Company Type
- Startup
- Working Model
- Hybrid, Onsite
- Industry
- Banking, Finance, Insurance