P
Senior GRC Analyst
Preply
Barcelona, Catalonia, ES
Preply operates a global online language-learning marketplace that matches students with tutors for live, one-on-one sessions across 90+ languages and 180 countries. The platform's recommendation algorithm is core infrastructure - handling tutor-student matching at scale, optimizing for learning outcomes, and processing behavioral signals from over 100,000 tutors and a massive, multilingual user base. Founded in 2012 and headquartered in Brookline, Massachusetts, the company also runs Preply Business, a corporate language-training product, and has raised $150M in Series D funding. The threat surface here is significant: a marketplace holding personal data, payment information, video session content, and AI-driven behavioral models across dozens of jurisdictions and regulatory regimes. The AI and recommendation-engine stack sits at the center of both product experience and data risk - tutor matching, progress tracking, and study assistance all depend on models trained on user activity at scale. The company maintains offices in Barcelona, London, New York, and Kyiv, with a team of over 678 people drawn from more than 50 nationalities. Security and platform-integrity roles at Preply would be working against a threat model that includes account takeover across a high-volume marketplace, fraud in tutor payments and lesson verification, data exfiltration from a globally distributed user base, and adversarial manipulation of recommendation systems. The engineering domains of note - AI, recommendation algorithms, and real-time communication tooling - demand teams that understand how to secure ML pipelines, protect PII at scale, and maintain trust in a platform where the product is the interaction between strangers over live video.
Preply operates a global online language-learning marketplace that matches students with tutors for live, one-on-one sessions across 90+ languages and 180 countries. The platform's recommendation algorithm is core infrastructure - handling tutor-student matching at scale, optimizing for learning outcomes, and processing behavioral signals from over 100,000 tutors and a massive, multilingual user base. Founded in 2012 and headquartered in Brookline, Massachusetts, the company also runs Preply Business, a corporate language-training product, and has raised $150M in Series D funding.
The threat surface here is significant: a marketplace holding personal data, payment information, video session content, and AI-driven behavioral models across dozens of jurisdictions and regulatory regimes. The AI and recommendation-engine stack sits at the center of both product experience and data risk - tutor matching, progress tracking, and study assistance all depend on models trained on user activity at scale. The company maintains offices in Barcelona, London, New York, and Kyiv, with a team of over 678 people drawn from more than 50 nationalities.
Security and platform-integrity roles at Preply would be working against a threat model that includes account takeover across a high-volume marketplace, fraud in tutor payments and lesson verification, data exfiltration from a globally distributed user base, and adversarial manipulation of recommendation systems. The engineering domains of note - AI, recommendation algorithms, and real-time communication tooling - demand teams that understand how to secure ML pipelines, protect PII at scale, and maintain trust in a platform where the product is the interaction between strangers over live video.