Назад
Company hidden
5 дней назад

Senior GRC Analyst (Cybersecurity)

5 000€
Формат работы
remote (только Europe)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Poland/Spain/Latvia +2 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior GRC Analyst (Cybersecurity): Maintaining and strengthening ISO 27001 and SOC 2 compliance programs through audit management, evidence collection, vendor security, risk management, and GRC automation with an accent on audit readiness, compliance-as-code, and AI-assisted workflows. Focus on executing complete audit cycles, designing practical evidence-collection automation, assessing third-party vendors, and driving risk remediation to closure.

Location: Fully remote from Latvia, Lithuania, Estonia, Spain, or Poland; access to an office in Riga is also available.

Salary: EUR 5,000+ gross per month, depending on experience, education, and skills.

Company

hirify.global powers on-demand commerce at global scale through technology, talent, and production infrastructure for creators, brands, and entertainment companies.

What you will do

  • Plan and execute internal and external audits across ISO 27001, SOC 2, and related frameworks.
  • Collect audit evidence, communicate with external auditors, and drive findings through closure.
  • Design automation for evidence collection and recurring compliance activities, including compliance-as-code and AI-assisted workflows.
  • Conduct third-party vendor security assessments during onboarding and annual reviews.
  • Maintain the risk register, perform risk assessments, and track remediation plans.
  • Develop information security policies, procedures, awareness materials, and training.

Requirements

  • 5+ years of experience in cybersecurity GRC, IT audit, or security compliance.
  • Hands-on participation in complete ISO 27001 and/or SOC 2 audit cycles.
  • Strong communication, negotiation, judgment, and stakeholder-management skills.
  • Demonstrated ability to build practical automation using scripts, integrations, GRC platforms, or AI-assisted workflows.
  • Self-directed approach with strong ownership of ambiguous problems and completed outcomes.
  • Excellent written and spoken English required.

Nice to have

  • ISO 27001 Lead Implementer or Lead Auditor, CISA, CISSP, or CISM certification.
  • Industry-side audit and compliance experience.

Culture & Benefits

  • High-trust, compact team with minimal bureaucracy and direct implementation of initiatives.
  • Flexible working hours, with the option to start the day as late as 11 AM.
  • Private health insurance and additional paid well-being and celebration days.
  • Internal and external learning opportunities, mentorship, meetups, and hackathons.
  • Free healthy lunch and employee discounts when working from the Riga office.

Hiring process

  • 30–45-minute introductory chat with Talent Acquisition.
  • Practical take-home or live assignment for applicable roles.
  • 30–60-minute hiring manager interview followed by a decision and offer.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →