GRC Analyst

Posted 2ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

GRC Analyst at Primer responsible for managing Governance, Risk & Compliance programs. Collaborates with engineering and security teams to maintain compliance and manage audit readiness.

Responsibilities:

  • Maintain a year-round evidence calendar, run continuous control monitoring, and coordinate with external auditors.
  • Own inbound security questionnaires, vendor assessments, and RFP responses. Maintain a response library.
  • Coordinate risk assessments, partner on security awareness and training programs, and govern vulnerability management processes.
  • Maintain policies, manage exceptions, monitor for violations, and drive remediation follow-through.
  • Drive future certification efforts, including ISO 27001, and support the operationalisation of new regulatory frameworks.

Requirements:

  • 3–5 years in a GRC, compliance, or information security governance role
  • Hands-on experience coordinating external audits (SOC 2, PCI DSS, ISO 27001, or similar)
  • Familiarity with EU regulatory frameworks such as GDPR, DORA, NIS2, and the EU AI Act
  • Experience managing vendor risk assessments and third-party due diligence
  • Track record of maintaining evidence and controls on a continuous (not just annual) basis
  • Strong organisational skills
  • Clear, concise communicator who can work across engineering, legal, and leadership teams
  • Comfortable working with compliance tooling and GRC platforms (e.g., Vanta, Drata, OneTrust, or similar)
  • Detail-oriented with a bias for proactive, systematic work over reactive cleanup
  • Able to operate independently while knowing when to pull in subject-matter experts
  • Familiarity with IAM processes and access review cycles (Nice to Have)
  • Relevant certifications (CISA, CRISC, ISO 27001 Lead Implementer, or similar; Nice to Have)
  • Experience in a payments, fintech, or regulated technology environment, particularly with PCI DSS compliance (Nice to Have)

Benefits:

  • We are fully remote and globally distributed; and have been since day one
  • Competitive share options
  • Uncapped holiday, with 25 days minimum to be taken
  • Co-working space access
  • Workations & Company Retreat
  • The best equipment for your role
  • £500 towards your home office setup
  • Generous learning budget
  • Private Medical Insurance
  • A broad set of additional perks and benefits (*depending on location)