Senior Security Compliance Analyst (f/m/d)
Core
Lead technical risk management, drive internal IT audit activity, and support external audits to maintain and expand security certifications (BSI C5, ISO 27001, ISO 27017, SOC 1, SOC 2) for an HR technology platform.
Role type
Senior Security Compliance Analyst
Builds
Security compliance programs, risk management frameworks, and audit evidence repositories for an HR SaaS platform serving 1.5 million employees.
Domain
HR Technology / Information Security / Governance, Risk, and Compliance (GRC)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Technical risk management, IT audit execution, ISO 27001/27017 framework expertise, GRC platform proficiency (Hyperproof), stakeholder coordination, AI/LLM tooling for compliance automation
Preferred skills
German regulatory frameworks (TISAX, BSI C5), experience with SOC 1/SOC 2 attestations, advanced LLM application for control mapping
Technologies
Hyperproof, LLMs, ISO 27001:2022, ISO/IEC 27017:2015
Responsibilities
Maintain and evolve the technical risk register, draft and conduct internal audit plans, coordinate evidence collection for new attestations, produce risk snapshots for leadership, partner with Engineering/IT/Legal/HR to close control gaps, apply AI tools to scale GRC workflows
Seniority
Senior, hands-on IC