Application Deadline: 5 June 2026
Department: Engineering
Employment Type: Full Time
Location: Cape Town, SA
Reporting To: Hati Chindove
Compensation: R660,000 - R780,000 / year
We are looking for a mid-level Security GRC Analyst with a specialism in Privacy and AI Governance to join our Security Function. You will be joining an established team that spans Security GRC, Security Engineering, and Security Operations — a cohesive unit that works closely across disciplines to deliver a mature, business-aligned security programme. Reporting into the Head of Security GRC, you will own the day-to-day operation of our privacy and AI governance frameworks, bridging the gap between our engineering and product teams and the organisation’s compliance obligations. This is a high-visibility role for a structured, analytical professional who wants to shape how a fast-moving tech company approaches data privacy and responsible AI at scale.
Privacy Framework Ownership | Supports the ongoing implementation and continuous improvement of our Privacy Information Management System (PIMS) aligned to ISO 27701. Maintain Records of Processing Activities (RoPA), data flow maps, and consent registers, ensuring compliance with GDPR, UK GDPR, and applicable regional data protection regulations.
AI Governance | Supports the operational maintenance of our AI governance programme under ISO 42001. Facilitate AI impact assessments across product and engineering initiatives, identifying bias, explainability, and transparency risks. Maintain the AI systems register and escalate findings to relevant stakeholders.
GRC Documentation & Tooling | Collaborate with the team to maintain a clean, audit-ready repository of GRC artefacts within our GRC platform (e.g. ServiceNow, Drata, or equivalent). Enforce version control discipline across policies, standards, and procedures. Support evidence collection for ISO 27001, SOC 2, and internal audits.
Risk Assessments | Compliment the existing risk assessment process by operating privacy and AI-specific risk assessments, Data Protection Impact Assessments (DPIAs), and AI Impact Assessments (AIIAs) across product and business initiatives. Identify control gaps, document risk treatment decisions, and track remediation activities through to closure in line with NIST or other similar methodologies.
Stakeholder Engagement | Act as a trusted advisor to product, engineering, and data science teams. Translate regulatory requirements into practical, actionable guidance. Champion privacy-by-design and security-by-default principles throughout the software development lifecycle (SDLC). You will be comfortable engaging directly with business stakeholders and, where required, with external clients — representing the Security GRC function with confidence and clarity.
Vendor & Third-Party Risk | Support third-party risk assessments with a focus on data processor obligations, AI sub-processor relationships, and contractual compliance. Review Data Processing Agreements (DPAs) and standard contractual clauses (SCCs) in partnership with Legal.
Incident & Audit Support | Participate in privacy-related incident response activities, including breach notification workflows under GDPR Article 33/34. Prepare materials for internal and external audits, managing evidence requests and auditor queries.
Skills & Competencies
Essential Experience

Zappi is a leading consumer insights platform that helps brands win with consumers. Through AI-powered software that delivers connected insights, Zappi enables teams to make faster, smarter, consumer-driven decisions by leveraging real-time, continuous feedback.
Trusted by more than 350 brands worldwide, Zappi helps create successful products, develop impactful ads, and build winning brands by keeping the voice of the consumer at the heart of every decision.
Named the Best Marketing Insights Platform by the MarTech Breakthrough Awards in both 2023 and 2024, recognized by Business Insider as one of the hottest martech companies, and winner of the MRS Best Technology Innovation Award 2025, Zappi is redefining how modern teams use insights to drive growth.
As a certified B-Corp, Zappi is committed to net-zero emissions, fostering an equitable workplace, and using technology to benefit the communities the company serves. With more than 300 employees across 13+ countries and offices in Boston, London, and Cape Town, Zappi’s culture has been celebrated by Fast Company, Comparably, Quirks, Great Place to Work, and more.
To learn more about Zappi, visit https://www.zappi.io/web, and to join our team, visit https://www.zappi.io/web/careers/.
**Please note: For your safety, apply only through Zappi’s official careers page. Any job postings outside this portal may not be legitimate. If you come across suspicious activity, please report it to both Zappi and the recruitment site to safeguard your information.