GRC Technical Program Manager
You find the fit. Your agent handles the form.
Choose a role or send your matches to the agent. It uses your original résumé and saved details, applies in the cloud, and keeps every result in one place.
About this role
Employer-provided description, formatted for easier reading.
Life at UiPath
The people at UiPath believe in the transformative power of automation to change how the world works. We’re committed to creating category-leading enterprise software that unleashes that power.
To make that happen, we need people who are curious, self-propelled, generous, and genuine. People who love being part of a fast-moving, fast-thinking growth company. And people who care—about each other, about UiPath, and about our larger purpose.
Could that be you?
Your mission
Technical Program Manager on the UiPath TrustOps team, you will play a hybrid role supporting geographically strategic compliance frameworks and overseeing key national security and regulatory programs in Romania. You will lead the organization’s adherence to industry certifications, regulations, and best practices, while helping manage the requirements associated with UiPath’s Industrial Security Clearance.
This is a role of trust and responsibility. Due to the nature of the position, obtaining a Romanian personnel security clearance is a mandatory prerequisite of employment.
What you'll do at UiPath
A. Governance, Risk and Compliance (GRC)
- Lead and support geographically strategic compliance frameworks and regulations, including ISO 27001, SOC 2 Type 2, GDPR, and CCPA.
- Support compliance certification efforts, including executing risk management activities, information security controls, and supporting internal and external audit activities.
- Develop and maintain a deep understanding of UiPath's control environment and articulate it to various audiences, including internal and external stakeholders and auditors.
- Establish and enforce global data retention schedules, and implement privacy engineering controls and automations.
- Maintain UiPath's sub-processor lists and manage the customer notification process.
- Support the overall data governance and data security strategy.
- Engage with cross-functional teams to drive the implementation of controls, compliance strategies, and other security-related risk-reduction initiatives.
B. National Security and Regulatory Programs
- Serve as the accountable owner for obtaining and maintaining UiPath's Industrial Security Clearance.
- Oversee the establishment and operation of the internal security structure, acting as (or directing) the designated Security Officer (funcționar de securitate) function.
- Own the PPSIC (Program for Preventing the Leakage of Classified Information) - its elaboration, approval, annual updates, and ongoing application.
- Direct the implementation and assurance of physical security, personnel security, information security, and INFOSEC measures required for certification, ensuring full compliance with Law 182/2002, HG 585/2002, and HG 781/2002.
- Oversee the IT system (SIC) authorization process, including the security documentation package (CSSS, Risk Analysis Report, Security Operational Procedures) and the constitution of the CSTIC (IT and Communications Security Component).
- Act as the primary point of contact with authorities and coordinate any external security consultants, inspections, and audits.
- Own incident detection and reporting obligations for classified information, and maintain the annual protection-status analysis.
What you'll bring to the team
- 3–5 years of experience leading geographically strategic compliance frameworks (ISO 27001, SOC 2 Type 2, HITRUST R2) and global privacy regulatory requirements such as GDPR and CCPA.
- Demonstrated ability to own compliance certifications end-to-end, including risk management, control implementation, and audit support.
- Familiarity with cloud systems including Azure, GCP, and AWS.
- Proven track record of effectively working with remote teams across different time zones.
- Strong stakeholder-management skills, with the ability to translate complex regulatory requirements into actionable programs for both technical and executive audiences.
- Eligibility and willingness to obtain a Romanian personnel security clearance (certificat de securitate / autorizație de acces) as a condition of employment.
Nice to have
- Familiarity with Romanian classified information legislation (Law 182/2002, HG 585/2002, and HG 781/2002) and the ORNISS certification landscape.
- Prior experience holding or managing a national or NATO/EU security clearance.
- Experience acting as, or working closely with, a designated Security Officer (funcționar de securitate).
- Knowledge of INFOSEC accreditation processes for classified IT systems (SIC).
- Working proficiency in Romanian (given the regulatory and governmental interfaces).
Maybe you don’t tick all the boxes above—but still think you’d be great for the job? Go ahead, apply anyway. Please.
Because we know that experience comes in all shapes and sizes—and passion can’t be learned.
Many of our roles allow for flexibility in when and where work gets done. Depending on the needs of the business and the role, the number of hybrid, office-based, and remote workers will vary from team to team. Applications are assessed on a rolling basis and there is no fixed deadline for this requisition.
The application window may change depending on the volume of applications received or may close immediately if a qualified candidate is selected.
We value a range of diverse backgrounds, experiences and ideas. We pride ourselves on our diversity and inclusive workplace that provides equal opportunities to all persons regardless of age, race, color, religion, sex, sexual orientation, gender identity, and expression, national origin, disability, neurodiversity, military and/or veteran status, or any other protected classes.
Additionally, UiPath provides reasonable accommodations for candidates on request and respects applicants' privacy rights. To review these and other legal disclosures, visit our privacy policy .