Назад
Company hidden
2 дня назад

Junior GRC Analyst (AI)

Формат работы
hybrid
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
Netherlands/Switzerland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Junior GRC Analyst (AI): Operating risk, exception, ISMS, third-party security, and compliance registers for a clinical AI platform with an accent on ISO 27001, NEN 7510, audit readiness, and sensitive health data. Focus on maintaining evidence packs, tracking vendor and privacy risks, producing leadership metrics, and keeping compliance operations accurate in a regulated healthcare environment.

Location: Must be based in The Netherlands and spend at least 50% of the time at the office

Company

hirify.global is a European clinical AI lab developing frontier models and a clinical AI workspace for hospital workflows, with operations in Amsterdam and Zurich.

What you will do

  • Operate the risk and exception management lifecycle, including intake, tracking, periodic review, and closure.
  • Maintain the ISMS policy and SOP library and prepare evidence packs for ISO 27001 and NEN 7510 surveillance audits.
  • Support third-party security reviews, including questionnaires, DPA and sub-processor tracking, data residency, and ongoing monitoring.
  • Maintain the supplier register, DPIA tracker, incident records, and post-incident action tracking.
  • Produce monthly metrics on risks, exceptions, incidents, and audit readiness for leadership.
  • Partner with the Compliance System Manager, CISO, DPO, privacy counsel, and engineering stakeholders.

Requirements

  • 1–3 years of experience in GRC, information security, internal audit, or a related field; strong recent graduates may also apply.
  • Working knowledge of at least one major framework: ISO 27001, NEN 7510, SOC 2, or NIS2.
  • Understanding of risk, issue, and exception management and practical ISMS operations.
  • Foundational technical literacy, including reading system architecture diagrams, understanding RBAC, and following cloud infrastructure discussions.
  • Strong organization, attention to detail, pragmatic judgment, and confidence asking questions or constructively challenging inconsistencies.

Nice to have

  • Experience with healthcare, medical devices, GDPR, MDR, HIPAA, or another regulated environment.
  • Familiarity with Jira and Confluence for compliance and governance work.
  • ISO 27001 Lead Implementer, CompTIA Security+, or an equivalent certification.

Culture & Benefits

  • Autonomy, ownership, collaboration, and high standards in an international team.
  • Competitive salary, pension plan, and 25 vacation days per year.
  • EUR 1,000 annual learning and development budget.
  • Flexible work approach and annual commuting subsidy.
  • Offsites and team events.

Hiring process

  • Screening call covering motivation, professional goals, and initial fit.
  • Technical interview involving a governance scenario or role-specific case.
  • Optional onsite meeting followed by a final conversation with an executive team member.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →