GRC Analyst
Core
Build, maintain, and drive the evolution of the Information Security Program ensuring strong governance, risk management, and regulatory compliance across the organization.
Role type
GRC Analyst
Builds
Information Security Program aligned with global frameworks and financial regulations
Domain
Financial Services / Cybersecurity Governance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Cybersecurity requirements analysis, Key controls monitoring, Third-party security due diligence, Control testing, Policy reviews, Risk tracking, Regulatory compliance knowledge (GDPR, DORA, ISO27001, NIST, SOC2, PCI-DSS), Analytical skills
Preferred skills
GRC tools (Vanta), Risk management evaluation, Risk treatment plans
Technologies
Vanta, ISO27001, NIST CSF, SOC2, PCI-DSS, GDPR, DORA
Responsibilities
Collect and analyze cybersecurity requirements to ensure alignment with regulations; Monitor key controls, KRIs, and KPIs; Conduct third-party security due diligence; Participate in scheduled control testing and policy reviews; Assist in creating security training materials; Gather evidence for internal/external audits.
Seniority
Mid-level, hands-on IC
