hellofresh

Senior GRC Analyst (m,f,x)

Berlin, Germany full-time Mid Salary not listed
full-time Mid level Technology & IT Curated
Sign in to apply Free account — we bring you straight back to this role.

About the role

The role

We’re looking for a new teammate who will support the implementation and ongoing maintenance of information security compliance and certification programs, working with cross-functional internal teams and external auditing agencies. The person will also support data protection, data privacy, and third-party vendor risk management functions.

The position will be part of the Governance, Risk & Compliance (GRC) team at HelloFresh that is responsible for creating, maintaining and improving HelloFresh’s security risk management program and remediation activities; information security and data privacy related processes, policies, and guidelines; supporting compliance and certification related activities; and driving security awareness and education.

Above all, we are looking for people who will make HelloFresh better. We believe there are many different ways of developing skills and we love diverse experiences! So even if you don’t “tick all the boxes” but think you’d thrive in this role, we would really like to learn more about you.

What you’ll do

Lead end-to-end compliance readiness for NIS2 and support alignment across other key frameworks (e.g., PCI DSS, CSRD, ISO/SOC and EU AI Act).

Plan and execute internal control assessments and coordinate external compliance audits on a defined cadence.

Translate regulatory requirements into practical controls; drive cross-functional implementation across international teams.

Own remediation management: track findings, evidence, owners, deadlines, and report status to stakeholders.

Improve GRC maturity through continuous monitoring, clear documentation, and mentoring junior team members.

Lead internal assessments and coordinate external compliance audits at planned intervals

Evaluate and validate the design and operational effectiveness of security policies, standards, and internal controls to help reduce compliance risk in the company

Develop comprehensive and accurate reports and presentations on the compliance landscape for both technical and executive audiences

What you’ll bring

3+ years' experience in performing compliance activities in a corporate environment related to IT General Controls (ITGC), SOC 2, ISO 27001, PCI DSS, EU NIS2, and various data privacy directives (GDPR, CCPA/CPRA, etc.)

Ability to interpret compliance regulations and map them to the actual implementation of systems, whilst referencing various security frameworks

Experience supporting data privacy regulations (GDPR, CCPA) and third-party risk management programs

Experience with developing and executing security awareness programs and trainings

Highly organized and detail-oriented, with an ability to work independently

Industry compliance certifications (CISA, CISM, CISSP) are a plus

Prior experience working in a SaaS environment, mainly Cloud and AWS-based

What we offer

Elevate your lifestyle! Join one of Europe's fastest-growing tech powerhouses in a dynamic phase of expansion.

Immerse yourself in a diverse global community of 90+ nationalities.

Enjoy a competitive compensation package that goes beyond the norm, with perks like a HelloFresh- subsidized Pension Scheme, Berlin relocation support, and a Hybrid working model.

Elevate your lifestyle with exclusive discounts on your weekly HelloFresh box and office meals.

Invest in your growth with a German language learning budget, and access to the HelloFresh Academy.

Plus, we've got your well-being covered with mental health support, transportation perks, and working-parent-friendly benefits. From our 24/7 gym access,wellbeing platforms like Headspace and Spill, to sabbatical leave options, HelloFresh is not just a workplace; it's a lifestyle of perks and possibilities!

 
Find more English Speaking Jobs in Germany on Arbeitnow

Interview prep

Walk in with sharper answers.

Use this as a quick practice sheet before you speak with the employer.

Mid
Technology & IT Writing Senior Grc Analyst Technology Mid level

Likely questions

  1. Tell us about work you have done that is close to the Senior GRC Analyst (m,f,x) role.
  2. How would you approach your first 30 days at hellofresh?
  3. Which of Writing, Senior and Grc have you used recently, and what did it help you achieve?
  4. Describe a time you solved a problem without waiting to be told exactly what to do.
  5. How do you handle busy days, changing priorities, or pressure at work?

Prepare before the call

  • A recent example that proves your experience with Writing, Senior and Grc.
  • One short story with a problem, your action, and the result.
  • Two examples that show the strengths listed on your CV.
  • A clear reason why this role and company interest you.
  • Your availability, preferred work style, and salary expectations.

Ask them

  • What would success look like in the first 90 days?
  • What are the main problems this hire should help solve?
  • How does the team give feedback and measure good work?
  • What does a normal working week look like for this role?
Practice line

I am interested in the Senior GRC Analyst (m,f,x) role because I can bring practical experience in Writing, Senior and Grc, learn the team quickly, and contribute to the outcomes hellofresh needs from this hire.

Related jobs.

More roles from this company or category.