Apply for this job

We collaborate with best-in-class platforms, consultants, and technology providers to deliver seamless, future-proof solutions, built to grow with your organization.

Download Whitepaper

We collaborate with best-in-class platforms, consultants, and technology providers to deliver seamless, future-proof solutions, built to grow with your organization.

GRC Implementation Consultant & Risk Officer

Hybrid
Full-time

As a GRC Implementation Consultant & Risk Officer at CERRIX, you split your week across two complementary roles. Three days a week you work client-facing as a GRC Implementation Consultant, translating clients' governance, risk, and compliance requirements into a well-configured, adopted CERRIX platform. The other two days you switch to an internal role as Risk Officer, safeguarding our IT security while leading the compliance certifications and IT assurance that support our growth.

On the consulting side, you lead implementation projects end-to-end, from kickoff and requirements analysis through configuration, data migration, testing, training, and go-live. You act as a trusted risk advisory partner, helping clients strengthen their risk and control frameworks, benchmark GRC maturity against leading practice, and translate regulation (e.g. DORA, ISO 27001, DNB/AFM guidance) into practical, implementable controls.

On the risk side, you manage our current compliance and IT assurance certifications (ISO 27001, ISAE 3402) and lead our transition toward SOC 2 Type II, acting as the trusted link between internal stakeholders and external auditors. We're in an exciting phase of growth and digital transformation, and this role puts you right at the center of it. If you're looking to grow with a dynamic, forward-thinking organization, this is the opportunity for you.

Here's what you'll do

As a GRC Implementation Consultant (3 days per week)

  • Run discovery workshops to capture client GRC requirements (risk management, controls, audit, compliance) and translate them into CERRIX configuration.
  • Configure and set up the CERRIX platform: workflows, risk frameworks, control libraries, dashboards, and integrations.
  • Advise clients on risk and control framework design, benchmarking their approach against leading practice and relevant regulation (e.g. DORA, ISO 27001, DNB/AFM).
  • Own the implementation project plan, timeline, and milestones, working closely with the project manager and client stakeholders.
  • Support data migration and validation from legacy systems or spreadsheets into CERRIX.
  • Deliver end-user and administrator training, and produce clear configuration and process documentation.
  • Leverage AI to optimise every step of the implementation, from configuration and data mapping to testing and documentation, so clients go live faster.
  • Act as the primary point of contact for clients during implementation, managing expectations and escalations.
  • Feed client insights and recurring configuration needs back to Product and Customer Success to improve CERRIX.

As a Risk Officer (2 days per week)

  • Manage and maintain our Information Security Management System (ISMS) in accordance with ISO 27001.
  • Drive the transformation and successful audit to SOC 2 Type II (coming from ISAE 3402), coordinating cross-functional readiness.
  • Conduct risk assessments, gap analyses, and mitigation planning, including maintaining and updating a risk register.
  • Serve as the point of contact for external auditors and compliance officers during audit processes.
  • Advise management on risk exposure, audit findings, and necessary corrective measures.
  • Develop and update risk and security policies, awareness programs, and training initiatives.

Does this sound like you?

  • 2-5+ years of experience in IT security, risk management, internal audit, compliance, or IT/software implementation consulting, preferably in a SaaS, tech, or heavily regulated environment.
  • Strong knowledge of one or more risk and control frameworks (COSO, COBIT, NIST).
  • A risk advisory mindset: comfortable challenging and guiding clients on risk and control design, not just configuring what's asked for.
  • Experience implementing or configuring SaaS/enterprise software; GRC/IRM platform experience is a strong plus.
  • Comfortable working with auditors and guiding teams through certification and compliance processes.
  • Strong analytical skills and the ability to translate business requirements into practical system configuration.
  • Excellent stakeholder management and communication skills, able to explain risk concepts clearly to both technical and non-technical audiences.
  • Self-driven, organized, and proactive, with a continuous improvement and solutions-focused mindset.
  • Fluent in Dutch and English (written and spoken); additional languages are a plus.
  • Bachelor's or Master's degree in a relevant field (e.g. Business, IT, Risk Management, Accounting).

What we offer you

  • Learning and development opportunities to grow your expertise.
  • Fun teambuilding initiatives, social and sports activities.
  • Work in an inspiring, fast-growing, international environment.
  • Competitive salary and benefits to support your well-being and growth, including:
    • Ergonomics Voucher – upgrade your home office for optimal productivity.
    • Quarterly Mental Health Days – take a fully paid day off each quarter to rest and recharge.
    • Learning & Development Budget – an annual budget (e.g. €500+) for professional certifications or training.
    • Flexible Work Location – go to the office two days per week, with occasional "workations" from inspiring places.
    • Pension scheme – to help you build financial security for the future.

At CERRIX, we believe in the power of diversity and innovation, valuing each team member's unique perspective to drive our success. As we grow, we're looking for driven professionals who are passionate about making a real difference.

About CERRIX

Founded in 2014, CERRIX is the European GRC platform purpose-built for financial institutions and other highly regulated industries. We help organisations bring structure, clarity, and accountability to governance, risk, and compliance, managing risks, controls, evidence, and audit activities in one integrated environment. We are valued for our high security standards, strong user-friendliness, flexibility, and swift implementations.

Full-time
Apply for this job

If you think this role fits you perfectly, please apply with your CV and motivation letter.

Open Positions

Senior Software Engineer

Hybrid
Full-time
Junior Software Engineer

Hybrid
Full-time
Sales
Partnership Manager

We’re looking for a Partnership Manager to build strong relationships, accelerate our growth, and help us scale into new markets.

Hybrid
Full-time