2 дня назад
Junior GRC Analyst (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Junior GRC Analyst (AI): Operating risk, exception, ISMS, third-party security, and compliance registers for a clinical AI platform with an accent on ISO 27001, NEN 7510, audit readiness, and sensitive health data. Focus on maintaining evidence packs, tracking vendor and privacy risks, producing leadership metrics, and keeping compliance operations accurate in a regulated healthcare environment.
Location: Must be based in The Netherlands and spend at least 50% of the time at the office
Company
is a European clinical AI lab developing frontier models and a clinical AI workspace for hospital workflows, with operations in Amsterdam and Zurich.
What you will do
- Operate the risk and exception management lifecycle, including intake, tracking, periodic review, and closure.
- Maintain the ISMS policy and SOP library and prepare evidence packs for ISO 27001 and NEN 7510 surveillance audits.
- Support third-party security reviews, including questionnaires, DPA and sub-processor tracking, data residency, and ongoing monitoring.
- Maintain the supplier register, DPIA tracker, incident records, and post-incident action tracking.
- Produce monthly metrics on risks, exceptions, incidents, and audit readiness for leadership.
- Partner with the Compliance System Manager, CISO, DPO, privacy counsel, and engineering stakeholders.
Requirements
- 1–3 years of experience in GRC, information security, internal audit, or a related field; strong recent graduates may also apply.
- Working knowledge of at least one major framework: ISO 27001, NEN 7510, SOC 2, or NIS2.
- Understanding of risk, issue, and exception management and practical ISMS operations.
- Foundational technical literacy, including reading system architecture diagrams, understanding RBAC, and following cloud infrastructure discussions.
- Strong organization, attention to detail, pragmatic judgment, and confidence asking questions or constructively challenging inconsistencies.
Nice to have
- Experience with healthcare, medical devices, GDPR, MDR, HIPAA, or another regulated environment.
- Familiarity with Jira and Confluence for compliance and governance work.
- ISO 27001 Lead Implementer, CompTIA Security+, or an equivalent certification.
Culture & Benefits
- Autonomy, ownership, collaboration, and high standards in an international team.
- Competitive salary, pension plan, and 25 vacation days per year.
- EUR 1,000 annual learning and development budget.
- Flexible work approach and annual commuting subsidy.
- Offsites and team events.
Hiring process
- Screening call covering motivation, professional goals, and initial fit.
- Technical interview involving a governance scenario or role-specific case.
- Optional onsite meeting followed by a final conversation with an executive team member.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Senior Risk Management / GRC Manager (Fintech)
4 дня назад
Senior Cyber Security Internal Auditor
3 дня назад
Senior Security Engineer (AI Safety)
4 дня назад
IT Risk Expert (1st Line)
5 994 - 8 563€
5 дней назад
Customer Success Engineer (AI Security)
3 дня назад