Назад
Company hidden
6 дней назад

Senior GRC Analyst

4 000 - 5 000€
Формат работы
remote (только Europe)
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Poland/Spain/Latvia +2 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior GRC Analyst (Cybersecurity Governance): Maintaining and strengthening ISO 27001 and SOC 2 compliance through audit management, evidence collection, vendor security assessments, risk tracking, and GRC automation with an accent on compliance operations and audit readiness. Focus on designing practical automation, applying compliance-as-code and AI-assisted workflows, and driving remediation through to closure.

Location: Fully remote from Latvia, Lithuania, Estonia, Spain, or Poland; an office option is available in Riga.

Salary: EUR 4,000–5,000 gross per month.

Company

hirify.global is part of FYUL, a global on-demand commerce group formed through the merger of hirify.global, Printify, and Snow Commerce.

What you will do

  • Plan and execute internal and external audits across ISO 27001, SOC 2, and related frameworks.
  • Collect evidence, assess control readiness, communicate with external auditors, and drive findings through closure.
  • Design automation for evidence collection and recurring compliance activities, including compliance-as-code and AI-assisted workflows.
  • Conduct third-party vendor security assessments during onboarding and annual reviews.
  • Maintain the risk register, perform risk assessments, and track remediation plans.
  • Develop information security policies, procedures, awareness materials, and training with the Governance and Assurance Manager.

Requirements

  • 5+ years of experience in cybersecurity GRC, IT audit, or security compliance.
  • Hands-on participation in complete ISO 27001 and/or SOC 2 audit cycles.
  • Strong communication, negotiation, judgment, and stakeholder-management skills.
  • Demonstrated ability to build practical automation through scripts, integrations, GRC platforms, or AI-assisted workflows.
  • Self-directed working style with strong ownership of ambiguous problems and outcomes.
  • Excellent written and spoken English required.

Nice to have

  • ISO 27001 Lead Implementer or Lead Auditor, CISA, CISSP, or CISM certification.
  • Industry-side experience.

Culture & Benefits

  • Fully remote work with access to a modern office in Riga.
  • Flexible working hours, with the option to start as late as 11 AM.
  • Private health insurance and additional paid well-being and celebration days.
  • Internal and external learning opportunities, mentorship, meetups, and hackathons.
  • Office lunch, employee merchandise discounts, and team-building events.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →