← Back to jobs

Remote job

IT Security Governance, Risk & Compliance Analyst

Other Full-time Freelance Europe

Job details

Not specified Salary
Europe Eligibility
Lead Experience
Full-time Employment

About this role

Role overview

A Security Governance, Risk, and Compliance (GRC) Analyst is needed to strengthen the organization's security posture through compliance work, control assurance, third-party risk, and security awareness. The role spans hands-on GRC activities, partnering with Security, Legal, Procurement, and technical teams to make sure controls are backed by reliable evidence, risks are tracked, and the business stays ready for audits and regulatory requirements. It suits someone who enjoys process ownership and wants broad exposure across multiple areas of information security compliance.

Responsibilities

- Gather, validate, organize, and maintain audit and security-control evidence across the organization - Test assigned security controls, surface gaps, and prepare clear, traceable evidence packages for assurance reviews - Support internal and external audits, including SOC 2 and financial-services regulatory assurance activities - Manage third-party security assessments covering supplier tiering, due diligence, questionnaires, and assurance evidence - Track supplier findings, treatment plans, reassessment dates, and remediation progress for SaaS, ICT, and critical vendors - Run security-awareness campaigns, phishing simulations, onboarding, and role-based training while maintaining completion records - Produce evidence-based compliance and security-risk reports and escalate control gaps, overdue evidence, and critical findings through defined processes

Requirements

- Background in IT compliance, Information Security GRC, IT risk, IT audit, third-party security risk, or a closely related field - Hands-on experience collecting, validating, and maintaining audit and control evidence - Working knowledge of information security frameworks such as SOC 2, ISO 27001, NIST, CIS Controls, or comparable standards - Understanding of risk assessment and risk treatment principles, including control testing and remediation tracking - Strong attention to detail and disciplined record-keeping when working with sensitive information - Clear written and verbal communication with both technical and non-technical stakeholders, plus solid English communication skills

Nice to have

- Familiarity with DORA, CySEC, or other financial-services regulatory regimes - Third-party or vendor security risk management experience, including supplier assessments and due diligence - Hands-on use of GRC platforms such as ServiceNow GRC, OneTrust, Archer, Vanta, Drata, or Hyperproof - Experience preparing or delivering security-awareness activities, phishing simulations, onboarding, or role-based training - Relevant certifications such as CISA, CRISC, CISM, or ISO 27001 Lead Auditor/Implementer - Prior internal or external audit support, or a background in FinTech, financial services, SaaS, or another regulated environment

Benefits and work setup

- Tax expense coverage and expert support for private entrepreneurs in Ukraine - 20 paid vacation days, 10 paid sick leave days, plus public holidays - Medical, professional education, language learning, and wellness (gym membership and sports gear) budgets - Remote work opportunity

Skills detected in the listing

Stakeholder ManagementInformation Security
Detected Sep 10, 2026
Last verified Sep 10, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight