Senior GRC Analyst (m,f,x)
Core
Lead end-to-end compliance readiness for NIS2 and support alignment across key frameworks (PCI DSS, CSRD, ISO/SOC, EU AI Act) while managing data privacy and third-party vendor risk.
Role type
Senior GRC Analyst (IC)
Builds
Security risk management program, compliance policies, and audit readiness for HelloFresh
Domain
Cybersecurity, Governance, Risk & Compliance (GRC), Data Privacy
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
IT General Controls (ITGC), SOC 2, ISO 27001, PCI DSS, EU NIS2, GDPR, CCPA/CPRA, third-party risk management, security awareness program development, regulatory interpretation, cross-functional coordination, remediation management, internal control assessment, policy design validation, executive reporting
Preferred skills
CISA, CISM, CISSP certifications, SaaS environment experience, Cloud and AWS-based systems experience
Technologies
NIS2, PCI DSS, CSRD, ISO, SOC, EU AI Act, GDPR, CCPA/CPRA, AWS
Responsibilities
Lead end-to-end compliance readiness for NIS2 and support alignment across other key frameworks; Plan and execute internal control assessments and coordinate external compliance audits; Translate regulatory requirements into practical controls; Own remediation management; Improve GRC maturity through continuous monitoring and mentoring; Evaluate and validate the design and operational effectiveness of security policies and internal controls; Develop comprehensive reports on the compliance landscape
Seniority
Senior, hands-on IC
