Senior GRC Content Engineer at TryHackMe
- Company
- TryHackMe
- Employment type
- Full-Time
- Location
- Worldwide
- Posted
- 2026-09-15
About this role
TryHackMe is the fastest-growing online cyber security training platform. Our mission is to make learning and teaching cyber security easier by providing gamified security exercises and challenges. Having only been around for handful of years, we've grown to more than 4 million community members and our growth isn't slowing down! π₯· The Role We're looking for a Senior GRC Content Engineer to help us build something our first GRC path, and lay the groundworks for everything than comes after it. We think people should learn GRC the way they learn everything else on TryHackMe: by doing it. Running a risk assessment, operating an ISMS, facing a simulated auditor, drafting a regulator notification with the 24-hour clock running. This is a senior role that demands deep, practitioner-level GRC expertise combined with a genuinely creative, teaching-oriented mind . You'll join a small squad (working directly with our GRC squad lead, who is also a senior GRC practitioner) to research, design, and build learning paths covering EU cyber regulation (NIS2, DORA, the Cyber Resilience Act), ISO 27001 and ISMS implementation, audit readiness, third-party risk, and cyber crisis management. The ideal candidate has lived this work - you've implemented or operated an ISMS, survived certification and surveillance audits, written risk registers people actually used, and translated regulation into controls a real organisation could run. You have also done this in a modern, AI-conscious environment, thatβs not governed by a spreadheet nobody updated since 2012. Just as importantly, you can turn that experience into interactive, scenario-driven learning experiences. Room building isn't easy: it's part instructional design, part scenario writing, part product thinking. If you've ever looked at compliance training and thought "I could make this genuinely engaging," this role is for you. Technical Skills & Experience To be considered for this opportunity, you must have at least 5+ years of hands-on GRC / information security experience in roles such as: GRC Analyst / GRC Manager, Information Security Officer / Manager, ISMS Owner, Compliance Manager, IT/Security Internal Auditor, or Security & Compliance Consultant Mandatory GRC skills β you must be able to demonstrate: Practical, implementation-level experience with ISO/IEC 27001 (2022 control set): scoping, risk assessment and treatment, Statement of Applicability, running or facing internal and certification audits β not just framework literacy Working knowledge of the EU cyber regulatory landscape : NIS2 and its Article 20/21/23 obligations, DORA for financial entities, and awareness of the Cyber Resilience Act β including how organisations operationalise these in practice Strong grounding in risk management practice : qualitative assessment methods, risk registers, controls and control types, risk treatment and residual risk sign-off Experience with audit and evidence workflows : what auditors ask for, how evidence is collected and presented, findings and management responses Familiarity with third-party / vendor risk : due-diligence questionnaires, reading SOC 2 reports, contractual security requirements A solid understanding of the technical side of security (networks, systems, cloud, common attack patterns) β enough to keep GRC content grounded in how security actually works, and to collaborate credibly with our technical content engineers Excellent written English β you will write a lot, and the writing must teach You should also demonstrate: Proven ability to research and synthesise : new regulations, framework revisions, enforcement trends, and competitor coverage β and turn that research into build decisions A creative, learner-first mindset : you can take a dry obligation ("Article 23 incident reporting") and design an exercise with real tension in it (a branching incident where the notification clock is running) Comfort with ambiguity - this is a new content stream being built from the grouβ¦
Apply for this Senior GRC Content Engineer role