🌏 Berlin / Remote
We’re building a meeting agent that builds company-wide conversational context and eliminates busy work around meetings. We’re a fast-moving team looking for a GRC Engineer to join our core team in Berlin (hybrid/remote possible). You’ll own our governance, risk, and compliance program — from audits and customer security reviews to the automation that keeps our evidence current as we ship.
Every company runs on conversations, and most of that context disappears the moment a meeting ends. Jamie captures it, structures it, and makes it usable across the entire organisation. We work closely with our customers to build a magical product with real-world impact.
We believe in shipping fast, learning constantly, and building a product users love.
Jamie handles sensitive conversations for teams whose work depends on trust. As we grow, customers need clear answers about how we protect their information, and auditors need evidence that our controls work in practice.
You’ll own that work end to end. Turn security and compliance requirements into practical controls, keep audits moving, and help customers complete their security reviews. Work directly with engineering, our commercial team, and external specialists to close gaps and keep commitments grounded in how the product actually works.
This is a technical role: build integrations, scripts, and agents that collect evidence, flag gaps, and make recurring compliance work easier. You’ll have significant ownership over how we build and run the program.
Own Audits & Certifications: Lead ISO 27001 and SOC 2 workstreams, from scoping and readiness through evidence collection, auditor coordination, remediation, and ongoing review. Own the calendar and follow every finding through to closure.
Automate Evidence & Controls: Build integrations and checks that collect reliable evidence from our cloud infrastructure, identity systems, code repositories, and internal tools. Keep evidence traceable and make control failures visible early.
Run Our Compliance Program: Maintain our information security management system, risk register, policies, control owners, and exception process. Keep documentation accurate as the product and company change.
Customer Security Reviews: Own security questionnaires, due diligence requests, and the evidence customers need to evaluate Jamie. Work with our commercial team and engineers to give clear, accurate answers and keep reviews moving.
Vendor & Access Reviews: Assess vendors and subprocessors, coordinate periodic access reviews, and follow up on gaps with the people who can fix them. Make recurring reviews straightforward to run and easy to evidence.
Close the Loop with Engineering: Map requirements to the systems we actually run, agree practical controls with our Cybersecurity and Platform Engineers, and verify that changes address the underlying risk.
We use the best tools to build the best product, and we’re always happy to hear new ideas and perspectives that could make working better. Currently:
☁️ We’re thoroughly Cloudflare-pilled and run a hybrid setup on Cloudflare + GCP