5 дней назад
Senior GRC Analyst (Cybersecurity)
5 000€
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior GRC Analyst (Cybersecurity): Maintaining and strengthening ISO 27001 and SOC 2 compliance programs through audit management, evidence collection, vendor security, risk management, and GRC automation with an accent on audit readiness, compliance-as-code, and AI-assisted workflows. Focus on executing complete audit cycles, designing practical evidence-collection automation, assessing third-party vendors, and driving risk remediation to closure.
Location: Fully remote from Latvia, Lithuania, Estonia, Spain, or Poland; access to an office in Riga is also available.
Salary: EUR 5,000+ gross per month, depending on experience, education, and skills.
Company
powers on-demand commerce at global scale through technology, talent, and production infrastructure for creators, brands, and entertainment companies.
What you will do
- Plan and execute internal and external audits across ISO 27001, SOC 2, and related frameworks.
- Collect audit evidence, communicate with external auditors, and drive findings through closure.
- Design automation for evidence collection and recurring compliance activities, including compliance-as-code and AI-assisted workflows.
- Conduct third-party vendor security assessments during onboarding and annual reviews.
- Maintain the risk register, perform risk assessments, and track remediation plans.
- Develop information security policies, procedures, awareness materials, and training.
Requirements
- 5+ years of experience in cybersecurity GRC, IT audit, or security compliance.
- Hands-on participation in complete ISO 27001 and/or SOC 2 audit cycles.
- Strong communication, negotiation, judgment, and stakeholder-management skills.
- Demonstrated ability to build practical automation using scripts, integrations, GRC platforms, or AI-assisted workflows.
- Self-directed approach with strong ownership of ambiguous problems and completed outcomes.
- Excellent written and spoken English required.
Nice to have
- ISO 27001 Lead Implementer or Lead Auditor, CISA, CISSP, or CISM certification.
- Industry-side audit and compliance experience.
Culture & Benefits
- High-trust, compact team with minimal bureaucracy and direct implementation of initiatives.
- Flexible working hours, with the option to start the day as late as 11 AM.
- Private health insurance and additional paid well-being and celebration days.
- Internal and external learning opportunities, mentorship, meetups, and hackathons.
- Free healthy lunch and employee discounts when working from the Riga office.
Hiring process
- 30–45-minute introductory chat with Talent Acquisition.
- Practical take-home or live assignment for applicable roles.
- 30–60-minute hiring manager interview followed by a decision and offer.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Senior GRC Analyst
4 000 - 5 000€
12 дней назад
GRC Specialist (AI)
200 000 - 220 000$
8 дней назад
Senior Information Security Engineer (GRC)
6 дней назад
GRC Security Analyst (AI Governance)
114 000 - 139 000$
6 дней назад
Lead Security Analyst - GRC (Cybersecurity)
138 000 - 215 625$
Clerk
10 дней назад