DoctolibParis, Paris, France
JFrogPosted 4w ago
GRC Specialist
GRC Specialist at JFrog scores 0 out of 100 on AI centrality, which makes it a Level 1 role on this board.
AI in this role
Support JFrog's GRC program by managing trust platforms, compliance questionnaires, and regulatory standards.
At JFrog, we’re reinventing DevSecOps to help the world’s greatest companies innovate. Our team of industry-leading software security experts is a true pioneer, constantly pushing the boundaries with original research and technological innovation. JFrog is a special place with a unique combination of brilliance, spirit, and just all-around great people. Thousands of customers, including the majority of the Fortune 100, trust JFrog to manage, accelerate, and secure their software delivery from code to production – a concept we call “liquid software”. Wouldn't it be amazing if you could join us on our journey?
We are seeking a GRC Specialist (Governance, Risk, and Compliance) to join our growing GRC Team. This is a fantastic opportunity to be part of a growing team and support the company as it grows and matures. If you're a team player, self-driven, creative thinker, passionate about cybersecurity, and capable of blending a process-oriented mindset with a tech-oriented outlook, we are looking for you!
As a GRC specialist at JFrog you will...- Maintain internal and external trust platforms, supporting ongoing customer due diligence activities including audits, questionnaires, and reviewing security contractual requirements.
- Provide training and guidance to sales teams on compliance-related matters and develop tools and resources to enable the Sales Team to efficiently respond to compliance inquiries from prospective and existing customers.
- Collaborate with cross-functional teams to support and enhance the overall GRC program.
- Ensure company policies, procedures, and controls are aligned with regulatory requirements and industry standards.
- Proactively gather customer feedback and stay abreast of industry trends to adapt and mature the GRC program accordingly.
- Implement improvements and updates to the program, based on regulatory changes and customer requirements.
- Participate in risk assessment and risk management processes.
- Minimum 1-2 years as a cyber security / GRC specialist, expert, or consultant
- Strong knowledge and hands-on experience with ISO 27001 and SOC 2 Type II
- Familiarity with additional security frameworks as well as privacy regulations and standards (NIST, CSA, CAIQ, SIG, GDPR, CCPA, ISO 27701) is an advantage.
- An excellent ability to communicate verbally and in writing
- Ability to work on multiple projects simultaneously
- Project management skills
- Self-driven and fast learner with a can-do approach
- Passionate about the team and responsibilities
- Experience with auditing cloud environments
- Experience in working with regulators and auditors
- Experience in working with GRC tools
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- Tell me about a project where grc was part of your work. What did you do?
- Tell me about a project where cybersecurity was part of your work. What did you do?
- Tell me about a project where iso 27001 was part of your work. What did you do?
- Tell me about a project where soc 2 was part of your work. What did you do?
- Tell me about a project where compliance was part of your work. What did you do?
Adapt your resume
- List these exact terms on your resume: Grc, Cybersecurity, Iso 27001, Soc 2, and Compliance. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want your resume actually rewritten for this job?
The free preview above is everything we have today. A full resume rewrite is not live yet and has no price set. Join the waitlist and we will email you if we open it.
Similar roles
Other roles rated Level 1 at other companies.




