Skip to main content
Passeca
Scraped fromDjinniYesterday
Security

Governance, Risk and Compliance (GRC) Analyst

ISO 27001SOC 2NISTGDPRExcelVantaDrataHyperproofOneTrustServiceNow GRCArcherAWSAzureIAMMFACyber EssentialsCIS ControlsJiraAzure DevOpsPower BI
Work Type
Remote
Job Type
Full Time
Location
Worldwide
Salary
$1100-1500

About the Position

We are looking for a GRC Analyst to join our Information Security and Compliance team. You will run day-to-day governance, risk and compliance activities — risk assessments, ISMS maintenance, audit evidence, and third-party security reviews — with senior support on the more complex work.

Responsibilities

  • Maintain the ISMS, control register and governance documentation.
  • Draft and update security policies, standards and procedures.
  • Coordinate security awareness activities and track governance actions.
  • Run information security risk assessments and maintain the risk register.
  • Track risk treatment plans and remediation through to closure.
  • Manage the security exception process.
  • Support compliance activities across ISO/IEC 27001, SOC 2 and GDPR.
  • Collect and organise audit evidence; act as a point of contact during internal and external audits.
  • Track audit and assessment findings to closure.
  • Run vendor security assessments and review supplier questionnaires.
  • Maintain supplier risk records and follow up on third-party remediation.
  • Produce monthly security and compliance reporting for management.
  • Maintain compliance dashboards and documentation repositories.

Requirements

  • 2–4 years in information security, risk, compliance, audit or IT governance.
  • Practical working knowledge of at least one major framework (ISO 27001, SOC 2 or NIST CSF).
  • Working understanding of GDPR and data protection obligations.
  • Confident with Excel and structured documentation; able to produce reporting for a management audience.
  • Strong written communication and attention to detail.
  • Comfortable working with both technical and non-technical stakeholders.
  • Degree in cyber security, computer science, IT or a related discipline — or equivalent practical experience.
  • Hands-on use of a GRC platform (Vanta, Drata, Hyperproof, OneTrust, ServiceNow GRC or Archer) – nice to have.
  • Cloud security fundamentals (AWS or Azure), IAM and MFA concepts – nice to have.
  • Exposure to Cyber Essentials, CIS Controls or AI governance – nice to have.
  • Jira or Azure DevOps; Power BI or Excel dashboards – nice to have.
  • A certification such as ISC2 CC, CompTIA Security+, ISO 27001 Foundation / Lead Auditor or SC-900 – nice to have.
  • German is a strong plus – nice to have.

Benefits

  • Ownership of real GRC workstreams across the full lifecycle.
  • Mentorship from senior security professionals and support for certifications.
  • Clear progression towards Senior GRC Analyst or Risk & Compliance Specialist.
  • Collaborative and inclusive working environment.
Governance, Risk and Compliance (GRC) Analyst$1100-1500
View Original