IT Security Governance, Risk & Compliance Analyst
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 1d ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 4d ago
The date the source published, not the day we noticed it (2026-09-10). Last seen at its source just now.
Is it remote?
The listing says yes
The location field doesn't say remote, so our assessment is based on the title or the description. Read the listing before applying.
Who may apply?
Europe
The description states no restriction of its own. This is the source's own tag.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
greenhouse employer's own board first seen 4d ago · last seen just now
The listing
We are looking for an IT Compliance Analyst/Information Security GRC Analyst to join our Security team and help strengthen the effectiveness and transparency of our security controls.
In this role, you will work across security compliance, control assurance, third-party risk, and security awareness. You will collaborate with Security, Legal, Procurement, technical and business teams to ensure controls are supported by reliable evidence, risks are identified and tracked, and the organization remains ready for audits and regulatory requirements.
This is a great opportunity for someone who enjoys hands-on GRC work, wants to take ownership of processes, and is interested in developing expertise across multiple areas of information security compliance.
Requirements
- Experience in IT compliance, Information Security GRC, IT risk, IT audit, third-party security risk, or a related field
- Hands-on experience collecting, validating, and maintaining audit and control evidence
- Understanding of security controls and experience with control testing, gap identification, and remediation tracking
- Knowledge of information security and assurance frameworks such as SOC 2, ISO 27001, NIST, CIS Controls, or similar
- Understanding of risk assessment and risk treatment principles
- Ability to maintain accurate control records, findings, remediation actions, owners, and deadlines
- Strong attention to detail and ability to work with sensitive information
- Clear written and verbal communication skills with both technical and non-technical stakeholders
- Good English communication skills
Will be a plus
- Experience with SOC 2, DORA, CySEC, or other financial-services regulatory requirements
- Experience with third-party/vendor security risk management, including supplier assessments, security questionnaires, and due diligence
- Experience with GRC platforms such as ServiceNow GRC, OneTrust, Archer, Vanta, Drata, Hyperproof, or similar
- Experience preparing or delivering security awareness activities, phishing simulations, onboarding, or role-based security training
- Relevant certifications such as CISA, CRISC, CISM, ISO 27001 Lead Auditor/Implementer, or similar
- Experience supporting internal or external audits
- Experience working in FinTech, financial services, SaaS, or another regulated environment
Responsibilities
- Collect, validate, organize, and maintain audit and security-control evidence
- Test assigned security controls, identify gaps, and prepare clear and traceable evidence packages
- Support internal and external audits, including SOC 2, DORA, and CySEC-related assurance activities
- Maintain control records, evidence repositories, findings, remediation actions, owners, and deadlines
- Perform third-party security assessments, including supplier tiering, due diligence, questionnaire reviews, and analysis of assurance evidence
- Assess security risks related to SaaS providers, ICT providers, outsourced services, and critical vendors
- Track supplier findings, treatment plans, reassessment dates, and remediation progress
- Collaborate with Security, Procurement, Legal, technical teams, and business stakeholders
- Support security-awareness campaigns, employee onboarding, phishing simulations, and role-based training
- Maintain awareness and training completion data and follow up on outstanding actions
- Prepare clear, evidence-based compliance and security-risk reporting
- Escalate control gaps, overdue evidence, critical supplier findings, and other significant risks through established processes
We offer
- Tax expenses coverage for private entrepreneurs in Ukraine
- Expert support and guidance for Ukrainian private entrepreneurs
- 20 paid vacation days per year
- 10 paid sick leave days per year
- Public holidays as per the company's approved Public holiday list
- Medical budget
- Opportunity to work remotely
- Professional education budget
- Language learning budget
- Wellness budget (gym membership, sports gear and related expenses)
Role mission
Strengthen the real and demonstrable state of security controls by validating evidence, testing assigned controls, assessing supplier security, and delivering security-awareness activities. Turn evidence, findings, supplier reviews, and training data into clear recommendations and timely escalations so audits and management reporting remain reliable, third-party risk is visible before decisions, and employees understand expected security behaviour—while final risk acceptance, supplier approvals, and policy exceptions remain with authorized owners.
Requirements hard skills
- At least three years of relevant experience in IT compliance, information-security governance, risk and compliance, IT audit, third-party security risk, or a closely related function.
- Ability to collect, validate, organize, and trace audit or control evidence to authoritative source systems.
- Ability to test the design and operation of assigned controls, document gaps, and prepare clear evidence packages for review.
- Ability to interpret control and assurance requirements and support requests involving SOC 2, the Digital Operational Resilience Act, and Cyprus Securities and Exchange Commission requirements.
- Ability to perform supplier tiering, review questionnaires and assurance evidence, and assess security risks involving SaaS, ICT providers, outsourced services, and critical vendors.
- Ability to maintain control records, evidence repositories, findings, remediation actions, owners, deadlines, and reassessment dates in a GRC platform or equivalent repository.
- Ability to prepare and deliver security-awareness content and support phishing simulations, onboarding sessions, and role-based training.
- Ability to produce concise, evidence-based status reporting and metrics for technical, business, audit, and management stakeholders.
Requirements soft skills
- Strong attention to detail and commitment to evidence quality.
- Sound judgment and discipline when operating within authorization and escalation boundaries.
- Integrity and discretion when handling sensitive control, audit, supplier, and employee information.
- Ownership of deadlines, follow-ups, records, and stakeholder communication.
- Clear written and verbal communication with technical and non-technical audiences.
- Ability to prioritize concurrent assurance, supplier, and awareness activities while keeping records current.
- Constructive collaboration across Security, Procurement, Legal, business, and technical teams.
- Curiosity and willingness to learn evolving control, supplier-risk, and awareness practices.
Responsibilities
- Assess the design and operation of assigned IT and security controls, including access control and change management. Document what you tested, the evidence reviewed and any gaps identified.
- Prepare and coordinate evidence for SOC 2 audits and other agreed security assurance requests. Check that evidence is current, complete and traceable to its source.
- Draft and maintain practical security policies, standards and procedures with GRC leadership and control owners. Turn requirements into clear actions and evidence expectations.
- Help teams introduce workable access and change processes, and verify that agreed requirements are implemented and used. Operational teams remain responsible for running those processes.
- Track control gaps, audit findings and remediation commitments with their owners. Validate closure evidence and escalate missing ownership, failed controls or overdue actions.
- Keep control records, evidence repositories and audit trackers organised. Reuse valid evidence, reduce duplicate requests and provide concise progress updates.
- Coordinate security onboarding and agreed targeted awareness activities with HR and team leads. Maintain guidance, track completion and follow-up, and use employee questions and feedback to improve understanding.
- Support risk colleagues with documented control findings and proposed improvements. GRC leadership and authorised owners retain policy approvals and risk-acceptance decisions.
Will be a plus
- Experience in a regulated fintech, trading, brokerage, payments, or digital-assets environment.
- Experience with a GRC or compliance-automation platform, audit-evidence repository, or learning-management system.
- Experience using dedicated security-awareness or phishing-simulation platforms.
- Basic scripting, data-analysis, or workflow-automation capability for compliance reporting.
- Relevant certifications such as CISA, CRISC, CISM, or ISO 27001 auditor or implementer certification.