Senior GRC Analyst
Posted 8hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior GRC Analyst maintaining ISO 27001 and SOC 2 compliance for FYUL, which powers global on-demand commerce. Automating audits, vendor security, risk, and governance operations.
Responsibilities:
- Plan and execute internal and external audit activities across ISO 27001, SOC 2, and related frameworks
- Collect evidence and ensure control readiness
- Communicate directly with external auditors
- Follow through on audit findings until closure
- Represent the function in audit interactions and professionally decline inappropriate requests when necessary
- Design and implement automation for evidence collection and recurring compliance activities
- Apply compliance-as-code practices where they deliver measurable value
- Leverage AI-based agents and workflows to reduce manual effort
- Maintain working knowledge of the commercial GRC platform landscape
- Prefer established industry solutions over custom development
- Conduct security assessments of third-party vendors during onboarding and annual reviews
- Continuously improve vendor security assessment efficiency
- Maintain the risk register
- Perform risk assessments and track remediation plans
- Ensure timely closure of identified risks
- Develop and maintain information security policies and procedures with the manager
- Contribute to security awareness materials and training delivery
Requirements:
- 5+ years of experience in cybersecurity GRC, IT audit, or security compliance
- Direct hands-on participation in complete ISO 27001 and/or SOC 2 audit cycles
- Strong communication and negotiation skills
- Professional confidence to hold a position under pressure from auditors, vendors, and internal stakeholders
- Judgment to know when refusal is the correct response
- Demonstrated automation capability through scripts, integrations, GRC platform implementations, or AI-assisted workflows
- Track record of building practical automation; software engineering background is not required
- Self-directed working style with strong ownership
- Ability to take ambiguous problems through to completed outcomes with minimal supervision
- Excellent written and spoken English
- Relevant certifications such as ISO 27001 Lead Implementer/Lead Auditor, CISA, CISSP, or CISM are an advantage, not a requirement
- Practical audit experience weighted more heavily than certification
Benefits:
- A high-trust, compact team with minimal bureaucracy
- An opportunity to work remotely or in a modern and welcoming office in Riga
- Flexible working hours (start your day as late as 11 AM)
- Private health insurance
- 2 extra paid days off to focus on your mental or physical well-being
- 1 extra paid day off to celebrate a Birthday or any other celebration of your choice
- Internal and external learning opportunities
- Access to mentorship, internal meetups, and hackathons, both on-site and online
- Free and healthy lunch if you work from the Rīga office
- Design and order your own merch using our platforms with an employee discount
- Exciting team-building events and parties you’ll never forget!


















