Junior GRC / Compliance Analyst (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Junior GRC / Compliance Analyst (Fintech): Supporting the third-party risk management program by assessing and monitoring risks associated with external vendors with an accent on vendor onboarding and risk remediation. Focus on operationalizing TPRM functions, reviewing SOC 2 reports, and managing assessments within GRC platforms.
Location: Tbilisi, Georgia
Company
is an AI-powered platform for finance automation that helps mid-market businesses scale by removing complexities in global payouts, procurement, and tax compliance.
What you will do
- Conduct vendor onboarding risk assessments through security questionnaires and due diligence reviews.
- Maintain and update the vendor risk register and manage the assessment pipeline.
- Review SOC 2 reports, security certifications, and vendor documentation.
- Track risk findings and coordinate remediation commitments with vendors.
- Collaborate with internal Procurement, Legal, and IT stakeholders on vendor reviews.
- Manage GRC assessments and workflows within the Drata platform.
Requirements
- Basic understanding of information security concepts, including the CIA triad, access control, and data classification.
- Familiarity with compliance frameworks such as ISO 27001 and SOC 2.
- Strong organizational and communication skills.
- Ability to read and interpret technical security documentation with high attention to detail.
Nice to have
- Experience using GRC tools like Drata, Vendict, or similar platforms.
- Basic knowledge of data privacy regulations, specifically GDPR and CCPA.
- Progress toward security certifications such as CompTIA Security+ or ISO 27001 Foundation.
Culture & Benefits
- Competitive benefits package and flexible workplace.
- Professional growth through career coaching and mentorship.
- Collaborative and diverse environment that encourages impact and ownership.
- Opportunity to work within a high-growth fintech unicorn.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →