Remote job
GRC Security Analyst - Information Security
Job details
About this role
Role overview A fast-growing, remote-first software company is hiring a GRC Security Analyst to join its Information Security team. The role supports governance, risk, and compliance operations across people, processes, systems, and metrics, with a focus on keeping security programs aligned to recognised standards as the organisation scales and integrates new acquisitions. It suits a self-starting communicator who can translate technical controls into business language for internal leaders, prospects, and external auditors.
Responsibilities - Coordinate and facilitate security governance goals, initiatives, and policy reviews across the organisation. - Partner with sales channels to respond to prospect and customer security questionnaires, assessments, and audits, explaining technical controls and acceptable alternatives. - Run vendor risk assessments and follow up on findings, exceptions, and remediation plans. - Support regulatory and compliance programmes such as ISO 27001, SOC 2, and GDPR, including audit coordination and evidence collection. - Track information security non-conformities, risk acceptances, and mitigation progress, and assist with business continuity and disaster recovery testing. - Contribute to security awareness campaigns, periodic compliance checks, and integration planning for acquired businesses.
Requirements - Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience). - Solid understanding of GRC operations, including risk management, policy governance, and audit support. - Demonstrated ability to build lasting relationships with business owners, vendors, and customers. - Highly organised, detail-oriented approach with strong written and verbal communication skills. - Creative problem-solving ability and a proactive, self-starter mindset. - Experience handling sensitive or confidential information with appropriate discretion.
Nice to have - CISA, CISSP, or similar security or GRC-focused certifications.
Benefits and work setup - Remote working model with employees distributed across many countries. - Eligibility for company equity, fostering a sense of ownership. - 26 paid vacation days annually plus 12 wellness days and paid volunteer hours. - Private healthcare, life insurance, and partner-coverage options. - Monthly benefits allowance, a meal card, and a home office allowance to support remote work. - Access to an internal learning platform for continuous professional development.