Compliance Automation Analyst

SuperhumanHub - BerlinArbeitnow٦‏/١٠‏/٢٠٢٦
إعلان
Superhuman offers a dynamic hybrid working model for this role. This flexible approach gives team members the best of both worlds: plenty of focus time along with in-person collaboration that helps foster trust, innovation, and a strong team culture. About SuperhumanGrammarly is now part of Superhuman, the AI productivity platform on a mission to unlock the superhuman potential in everyone. The Superhuman suite of apps and agents brings AI wherever people work, integrating with over 1 million applications and websites. The company’s products include Grammarly’s writing assistance, Superhuman Docs’s collaborative workspaces, Mail’s inbox management, and Go, the proactive AI assistant that understands context and delivers help automatically. Founded in 2009, Superhuman empowers over 40 million people, 50,000 organizations, and 3,000 educational institutions worldwide to eliminate busywork and focus on what matters. Learn more at superhuman.com. The OpportunityWe’ve consolidated separate compliance programs (Grammarly, Coda, Superhuman Mail, and Superhuman Go) into a single program. We’re rapidly replacing the point-in-time approaches with continuous, automated, code-defined evidence, and this role continues to build on that. The job is to automate your way out of the manual toil: our GRC automation platform is the evidence-automation backbone, agentic systems (Claude Code and similar) are the force multiplier, and GitHub is where the program lives as code. If your instinct on seeing a manual control-testing process is to turn it into a repeatable, automated pipeline, this role is for you. What You Will Do: Automate evidence collection. Configure and operate the GRC automation platform: wire up data sources, build evidence plugins, scope data sets, author analysis rules, and stand up continuous monitoring operations, replacing screenshot-and-upload workflows with automated collectors mapped to controls. Automate GRC workflows and run compliance as code. Use Claude Code (or similar) and MCPs for evidence requests, control mapping, gap analysis, vendor reviews, and reporting; build and curate the team’s agent harness; and manage policies, control definitions, and automation in GitHub through branches, pull requests, and review. Design control testing and drive remediation. Instrument testing across SOC 2, ISO 27001, ISO 27017/27018, ISO 27701, PCI DSS, and ISO 42001 for continuous assurance rather than point-in-time snapshots, and work with control owners and engineering to close gaps with automated evidence behind every finding. What Ramping Up Looks Like: You will be configuring our GRC automation platform, not just clicking through it, within your first few weeks. In your first 90 days, we’d expect you to learn the platform configuration, ship your first automated evidence collectors, retire a batch of manual screenshot evidence, and get at least one agent-assisted workflow running end-to-end. Why This Role: You’ll design the automation architecture for compliance across four products, rather than maintaining an existing checklist. You get the mandate and the tooling to retire manual evidence collection: a GRC automation platform, agentic AI, and compliance-as-code. We actually run LLMs and AI agents in production GRC workflows today. This is how the team operates day-to-day. Small team, high ownership, and a direct line to Legal and Engineering leadership. You’ll shape the program, not just sustain it. Qualifications5+ years in compliance, GRC, or IT audit, hands-on with the frameworks above (SOC 2, ISO 27001, PCI DSS, and adjacent). 1+ year using agentic AI systems (Claude Code, Codex, etc.) to do real compliance work, with automation you have delivered, not just prototypes. Comfortable in GitHub: repos, branches, pull requests, and code review. CI/CD familiarity is a strong plus. Fast on new tooling. You can pick up a GRC automation platform and be productive in weeks, configuring it directly rather than rel
إعلان