Governance, Risk and Compliance (GRC) Analyst
to $1500
Employment Type: Full-Time
Experience: 2β4 years
About the Role
We are looking for a GRC Analyst to join our Information Security and Compliance team. You will run day-to-day governance, risk and compliance activities β risk assessments, ISMS maintenance, audit evidence, and third-party security reviews β with senior support on the more complex work.
This is a hands-on delivery role rather than a first job in security. You should be comfortable running a vendor assessment or an evidence collection cycle without step-by-step direction.
Key Responsibilities
Governance & Policy
- Maintain the ISMS, control register and governance documentation.
- Draft and update security policies, standards and procedures.
- Coordinate security awareness activities and track governance actions.
Risk Management
- Run information security risk assessments and maintain the risk register.
- Track risk treatment plans and remediation through to closure.
- Manage the security exception process.
Compliance & Audit
- Support compliance activities across ISO/IEC 27001, SOC 2 and GDPR.
- Collect and organise audit evidence; act as a point of contact during internal and external audits.
- Track audit and assessment findings to closure.
Third-Party Risk
- Run vendor security assessments and review supplier questionnaires.
- Maintain supplier risk records and follow up on third-party remediation.
Reporting
- Produce monthly security and compliance reporting for management.
- Maintain compliance dashboards and documentation repositories.
What Weβre Looking For
- 2β4 years in information security, risk, compliance, audit or IT governance.
- Practical working knowledge of at least one major framework (ISO 27001, SOC 2 or NIST CSF).
- Working understanding of GDPR and data protection obligations.
- Confident with Excel and structured documentation; able to produce reporting for a management audience.
- Strong written communication and attention to detail.
- Comfortable working with both technical and non-technical stakeholders.
- Degree in cyber security, computer science, IT or a related discipline β or equivalent practical experience.
Nice to Have
- Hands-on use of a GRC platform (Vanta, Drata, Hyperproof, OneTrust, ServiceNow GRC or Archer).
- Cloud security fundamentals (AWS or Azure), IAM and MFA concepts.
- Exposure to Cyber Essentials, CIS Controls or AI governance.
- Jira or Azure DevOps; Power BI or Excel dashboards.
- A certification such as ISC2 CC, CompTIA Security+, ISO 27001 Foundation / Lead Auditor or SC-900.
- German is a strong plus
What We Offer
- Ownership of real GRC workstreams across the full lifecycle.
- Mentorship from senior security professionals and support for certifications.
- Clear progression towards Senior GRC Analyst or Risk & Compliance Specialist.
- Collaborative and inclusive working environment.
Required languages
English
B2 - Upper Intermediate
Published 7 September
13 views
Β·
3 applications
π
Average salary range of similar jobs in
analytics β
Loading...