Senior GRC Analyst
Core
Own the Information Security Program's governance, aligning it with frameworks like NIST CSF and ISO27001:2022, and integrating cyber risk into the Enterprise Risk Management framework.
Role type
Senior GRC Analyst (Information Security)
Builds
Governance frameworks, risk metrics, compliance documentation, and security training materials
Domain
FinTech / Cybersecurity / Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Information security governance, cyber risk quantification, regulatory mapping (GDPR, DORA), risk assessment, security policy management, GRC tool implementation
Preferred skills
CISSP, CRISC, CISA, CISM, ISO27001 Lead Auditor/Implementer, leveraged trading regulations experience
Technologies
NIST CSF, ISO27001:2022, SOC2, PCI-DSS, GRC tools
Responsibilities
Take ownership of the Information Security Program's governance; Quantify and track cyber risks; Map security program against regulatory requirements; Create and deliver security training materials; Act as key point of contact for auditors; Streamline and automate GRC processes
Seniority
Senior, hands-on IC
