GRC Specialist
We are the creators of a new fintech era!
Our mission is to revolutionize the world by making blockchain technology accessible to everyone in everyday life. WhiteBIT is a global team of more than 1,500 professionals united by a shared vision of shaping the future.
We are building our own blockchain ecosystem to ensure maximum transparency and security for over 8 million users worldwide. Our cutting-edge solutions, rapid adaptation to market challenges, and technological excellence set us apart from traditional companies.
Our official partners include Juventus, FC Barcelona, Lifecell, FACEIT, and VISA.
Join us as an Quantitative Researcher.
Requirements:
- 4β6+ years of experience in Information Security, GRC, Risk Management, Compliance, IT Audit, or a related field.
- Strong practical knowledge of information security and compliance frameworks such as ISO 27001, SOC 2, PCI DSS, CCSS or similar.
- Experience working with applicable regulatory requirements such as NIS2, DORA, GDPR, or other relevant regulations.
- Hands-on experience conducting information security risk assessments, control assessments, gap analyses, and compliance reviews.
- Experience supporting or coordinating internal and external audits, certifications, and regulatory assessments.
- Ability to independently manage compliance initiatives, track remediation activities, and follow up with control owners.
- Experience developing, reviewing, and maintaining security policies, standards, procedures, controls, and related documentation.
- Understanding of common information security domains, including access management, vulnerability management, incident management, third-party risk, business continuity, cloud security, and data protection.
- Experience working with third-party/vendor risk assessments and security due diligence.
- Experience responding to customer security questionnaires, RFIs/RFPs, or customer compliance requests.
- Ability to translate regulatory, contractual, and security requirements into clear and actionable controls for technical and business teams.
- Strong stakeholder management skills and experience collaborating with Security, IT, Engineering, Legal, Privacy, Procurement, and business teams.
- Strong analytical skills and ability to identify, assess, document, and communicate security and compliance risks.
- Excellent written and verbal communication skills, including the ability to explain GRC topics to both technical and non-technical stakeholders.
- Strong organizational skills and ability to manage several compliance, risk, and audit activities in parallel.
- Ability to work independently, prioritize effectively, and take ownership of GRC activities from identification through remediation and closure.
- Professional working proficiency in English.
Nice to have:
- Experience in SaaS, cloud-based, technology, or other highly regulated environments.
- Experience with GRC platforms or compliance automation tools such as ServiceNow GRC, OneTrust, Vanta, Drata, AuditBoard, or similar.
- Familiarity with cloud platforms such as AWS, Azure, or GCP from a governance and compliance perspective.
- Relevant professional certifications such as CISA, CISM, CRISC, CISSP, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.
- Experience participating in or leading compliance improvement and control maturity initiatives.
Responsibilities:
- Own and coordinate day-to-day GRC activities across information security, risk management, compliance, and assurance.
- Conduct information security risk assessments, identify control gaps, document risks, and track remediation actions with relevant owners.
- Support the implementation, maintenance, and continuous improvement of security and compliance frameworks such as ISO 27001, SOC 2, PCI DSS, and other applicable standards.
- Monitor relevant regulatory and contractual requirements and help translate them into practical security controls and compliance activities.
- Coordinate and support internal and external audits, certification activities, customer assessments, and regulatory reviews.
- Maintain and improve security policies, standards, procedures, control documentation, risk registers, and other GRC documentation.
- Perform control assessments and periodically evaluate the effectiveness of implemented security controls.
- Track audit findings, compliance gaps, risks, and remediation plans through to closure.
- Support third-party and vendor security risk assessments, including due diligence and ongoing risk reviews.
- Manage and respond to customer security questionnaires, security reviews, and compliance-related requests in collaboration with relevant teams.
- Partner with Security, IT, Engineering, Legal, Privacy, Procurement, and business stakeholders to ensure security and compliance requirements are understood and implemented.
- Provide guidance to control owners on compliance requirements, risk treatment, evidence collection, and remediation activities.
- Identify opportunities to improve and automate GRC processes, evidence collection, reporting, and compliance monitoring.
- Develop and maintain GRC metrics, dashboards, and reporting to provide visibility into risks, compliance status, audit findings, and remediation progress.
- Support security awareness and compliance initiatives where relevant.
- Stay informed about changes in security standards, regulations, and industry practices and assess their potential impact on the organization.
Working terms
Immerse yourself in Crypto & Web3:Master cutting-edge technologies and become an expert in the most innovative industry.
Work with the Fintech of the Future:
- Develop your skills in digital finance and shape the global market.
Take Your Professionalism to the Next Level:
- Gain unique experience and be part of global transformations.
Drive Innovations:
- Influence the industry and contribute to groundbreaking solutions.
Join a Strong Team:
- Collaborate with top experts worldwide and grow alongside the best.
Work-Life Balance & Well-being:
- Modern equipment.
- Comfortable working conditions, and an inspiring environment to help you thrive.
- 24 calendar days of paid leave.
- Additional days off for national holidays.
With us, youβll dive into the world of unique blockchain technologies, reshape the crypto landscape, and become an innovator in your field. If youβre ready to take on challenges and join our dynamic team, apply now and start a new chapter in your career!
Letβs Build the Future Together!