Назад
Company hidden
2 часа Π½Π°Π·Π°Π΄

Senior GRC Analyst

72Β 000 - 121Β 000$
Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
remote (Ρ‚ΠΎΠ»ΡŒΠΊΠΎ USA)
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Π“Ρ€Π΅ΠΉΠ΄
senior
Английский
b2
Π‘Ρ‚Ρ€Π°Π½Π°
France/UK/US +5 Π΅Ρ‰Π΅
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/

TL;DR

Senior GRC Analyst (Security): Build and operate enterprise risk management program including security risk assessments, third-party risk management, risk register, and AI governance initiative with an accent on compliance frameworks, internal audits, and policy development. Focus on leading cross-functional initiatives, designing unified control frameworks, performing risk assessments, and establishing compliance metrics for leadership visibility.

Location: Remote from Canada, England, France, Germany, Italy, Portugal, Spain, or United States. hirify.global does not offer visa sponsorship for this role.

EU Salary Range: €72K–€121K β€’ Offers Equity; US Salary Range: $123.8K–$202.4K β€’ Offers Equity

Company

Globally distributed remote-first team building developer tools like hirify.global Desktop, Hub, and Scout, powering containerized applications and secure AI workflows.

What you will do

  • Own compliance program roadmap, aligning SOC 2, ISO 27001, ISO 27701, ISO 42001 with business and product strategy
  • Lead cross-functional initiatives with Engineering, Product, Legal, IT as authority on governance and risk
  • Design unified control framework, cross-map to NIST 800-53, identify gaps
  • Plan and execute internal audits: scoping, testing, findings, auditor coordination
  • Perform risk assessments on systems, processes, vendors, cloud; create treatment plans
  • Own vendor risk management, evaluate third-parties, drive remediations
  • Draft security policies, map to standards; establish and report KPIs

Requirements

  • 4-6 years in Information Security, GRC
  • Experience building/operating enterprise risk management: assessments, registers, treatment
  • Third-party risk management, vendor assessments
  • Knowledge of ISO 27001, SOC 2, NIST 800-53, GDPR
  • Familiarity with AI governance (ISO 42001, NIST AI RMF) or quick learning
  • Metrics and reporting for GRC, dashboards
  • Cloud environments (AWS, GCP, Azure) risks
  • Strong communication for technical/non-technical audiences
  • Track record maturing GRC programs from ground up
  • Self-motivated in remote-first, fast-paced environment

Nice to have

  • Certifications: CRISC, CISA, CISSP, CCSK
  • Experience with GRC platforms (Anecdotes, ServiceNow GRC, OneTrust)
  • Automation/scripting for risk workflows

Culture & Benefits

  • Remote-first culture with offices in Seattle and Paris
  • Freedom & flexibility to fit work around life
  • Quarterly Whaleness Days plus end-of-year break
  • Home office setup and $100 USD/month tech stipend
  • PTO plan, 16 weeks paid parental leave (after 6 months)
  • Training stipend for conferences/courses
  • Equity for all employees
  • Medical benefits, retirement, holidays vary by country
  • hirify.global swag

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’