About the job
Synthesia is a leading AI video platform, trusted by a large share of Fortune 100 companies. Founded in 2017 and based in London, the company has grown to include teams across Europe and the US. Synthesia's products help organizations communicate more effectively and support skill development, aiming to help teams succeed in a competitive business world.
Following a recent Series E funding round, Synthesia has raised $200 million, bringing its valuation to $4 billion and total funding above $530 million. Investors include Accel and Nvidia's NVentures.
Role overview
The Governance, Risk, and Compliance (GRC) Analyst will strengthen Synthesia’s GRC initiatives, working to ensure these efforts align with technical teams and deliver clear business value. This position is designed for someone with a technical background, such as engineering, IT management, DevOps, or SRE, who can connect system architecture and operational needs with compliance requirements. Familiarity with tools like GitHub, CI/CD pipelines, Kubernetes, cloud platforms, and observability solutions is important, as is the ability to address audit and customer needs.
The role involves close collaboration with Engineering, DevOps/Platform, Security, Legal, and customer-facing teams. Key goals include maintaining audit readiness, addressing risks with practical solutions, and supporting future compliance initiatives like ISO 22301, HITRUST, and FedRAMP.
While prior compliance experience is not required, a solid understanding of security, a willingness to learn, and a proactive approach are essential.
What you will do
- Own and improve the GRC program, focusing on frameworks such as ISO 27001, SOC 2, ISO 27701, and ISO 42001. This includes detailed control mapping and evidence collection.
- Work with control owners to make compliance processes more efficient, aiming to integrate evidence gathering into regular workflows.
- Lead audit preparation by managing documentation, timelines, action items, and clear demonstrations of controls.
Requirements
- Technical background in engineering, IT management, DevOps, or SRE.
- Experience working with system architecture and operational tools such as GitHub, CI/CD, Kubernetes, and cloud technologies.
- Strong foundation in security.
- Willingness to learn and take initiative.
This position is open to candidates based in Europe.
