Senior GRC Analyst

Posted 8hrs ago

Employment Information

Industry
Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior GRC Analyst maintaining ISO 27001 and SOC 2 compliance for FYUL, which powers global on-demand commerce. Automating audits, vendor security, risk, and governance operations.

Responsibilities:

  • Plan and execute internal and external audit activities across ISO 27001, SOC 2, and related frameworks
  • Collect evidence and ensure control readiness
  • Communicate directly with external auditors
  • Follow through on audit findings until closure
  • Represent the function in audit interactions and professionally decline inappropriate requests when necessary
  • Design and implement automation for evidence collection and recurring compliance activities
  • Apply compliance-as-code practices where they deliver measurable value
  • Leverage AI-based agents and workflows to reduce manual effort
  • Maintain working knowledge of the commercial GRC platform landscape
  • Prefer established industry solutions over custom development
  • Conduct security assessments of third-party vendors during onboarding and annual reviews
  • Continuously improve vendor security assessment efficiency
  • Maintain the risk register
  • Perform risk assessments and track remediation plans
  • Ensure timely closure of identified risks
  • Develop and maintain information security policies and procedures with the manager
  • Contribute to security awareness materials and training delivery

Requirements:

  • 5+ years of experience in cybersecurity GRC, IT audit, or security compliance
  • Direct hands-on participation in complete ISO 27001 and/or SOC 2 audit cycles
  • Strong communication and negotiation skills
  • Professional confidence to hold a position under pressure from auditors, vendors, and internal stakeholders
  • Judgment to know when refusal is the correct response
  • Demonstrated automation capability through scripts, integrations, GRC platform implementations, or AI-assisted workflows
  • Track record of building practical automation; software engineering background is not required
  • Self-directed working style with strong ownership
  • Ability to take ambiguous problems through to completed outcomes with minimal supervision
  • Excellent written and spoken English
  • Relevant certifications such as ISO 27001 Lead Implementer/Lead Auditor, CISA, CISSP, or CISM are an advantage, not a requirement
  • Practical audit experience weighted more heavily than certification

Benefits:

  • A high-trust, compact team with minimal bureaucracy
  • An opportunity to work remotely or in a modern and welcoming office in Riga
  • Flexible working hours (start your day as late as 11 AM)
  • Private health insurance
  • 2 extra paid days off to focus on your mental or physical well-being
  • 1 extra paid day off to celebrate a Birthday or any other celebration of your choice
  • Internal and external learning opportunities
  • Access to mentorship, internal meetups, and hackathons, both on-site and online
  • Free and healthy lunch if you work from the Rīga office
  • Design and order your own merch using our platforms with an employee discount
  • Exciting team-building events and parties you’ll never forget!