Senior GRC Analyst (m,f,x)
Core
Lead end-to-end compliance readiness for NIS2 and support alignment across frameworks like PCI DSS, CSRD, ISO/SOC, and EU AI Act; plan and execute internal control assessments and coordinate external audits.
Role type
Senior GRC Analyst (IC)
Builds
Security risk management program, compliance certification programs, data privacy and vendor risk management functions
Domain
Technology / Governance, Risk & Compliance / Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
IT General Controls (ITGC), SOC 2, ISO 27001, PCI DSS, EU NIS2, GDPR, CCPA/CPRA, third-party vendor risk management, security awareness program development, regulatory interpretation, control mapping, remediation management, cross-functional coordination, reporting to executive audiences
Preferred skills
CISA, CISM, CISSP certifications, SaaS environment experience, Cloud experience, AWS-based experience
Technologies
NIS2, PCI DSS, CSRD, ISO, SOC, EU AI Act, GDPR, CCPA, AWS
Responsibilities
Lead end-to-end compliance readiness for NIS2 and support alignment across other key frameworks; Plan and execute internal control assessments and coordinate external compliance audits; Translate regulatory requirements into practical controls and drive cross-functional implementation; Own remediation management by tracking findings, evidence, owners, and deadlines; Improve GRC maturity through continuous monitoring, documentation, and mentoring; Evaluate and validate the design and operational effectiveness of security policies and internal controls; Develop comprehensive reports and presentations on the compliance landscape for technical and executive audiences
Seniority
Senior, hands-on IC
