Information Security Analyst, GRC

Posted Sep 11

This is a fully remote position, open to applicants in United Kingdom.

📋 Description

• Assist customers and prospects by completing technical security questionnaires, risk assessments, and due diligence requests.

• Collaborate with Sales and Customer teams to articulate XBOW’s security controls, architecture, and compliance stance.

• Evaluate and oversee security risks associated with third-party vendors, including SaaS providers and service partners.

• Investigate and address alerts to uphold compliance using Vanta.

• Aid in the maintenance and enhancement of risk assessment frameworks, methodologies, and documentation.

• Monitor and facilitate the remediation of identified risks with internal stakeholders.

• Contribute to compliance efforts aligned with SOC 2, FedRAMP 20x, ISO 27001, and ISO 42001.

• Manage risk registers, policies, and supporting documentation.

• Organize risk management sessions and related processes.

• Discover opportunities to streamline and automate risk and compliance procedures.

• Assist with audits, customer evaluations, and internal assurance activities as necessary.

• Work collaboratively with IT, Security, Engineering, Legal, Sales, and Customer teams as an individual contributor.


⛳️ Requirements

• Over 7 years of experience in risk, compliance, security assurance, or similar roles.

• Background in hands-on technical positions, such as Engineering, IT, or operational security.

• Practical experience in completing or reviewing technical security questionnaires and customer risk assessments.

• Knowledge and experience with security compliance and data protection frameworks like SOC 2, ISO 27001, NIST, GDPR, and HIPAA.

• Experience in conducting or aiding vendor/third-party risk assessments.

• Excellent written communication skills with the ability to clarify complex security concepts effectively.

• Highly organized and detail-oriented, adopting a pragmatic approach to risk management.

• Comfortable operating in a dynamic, remote-first startup environment.

• Familiarity with contemporary AI tools to enhance productivity while managing risk.

• Prior experience in a SaaS or security-centric company is a plus.

• Experience with handling Subject Access Requests for GDPR is a plus.

• Security or risk certifications such as CRISC or CISSP are beneficial.

• Knowledge of cloud security best practices is advantageous.


🏝️ Benefits

• Meaningful stock options.

• Opportunity to learn from and collaborate with leading security and AI experts.

• Engage in complex technical challenges that underpin the company’s foundation.

• Remote-first work arrangement.

• Flexibility to work from anywhere, with regular opportunities for in-person meetings.

• Supported travel to collaborate with colleagues face-to-face.

People also viewed

Vision Cybersecurity3 days ago

Network Cybersecurity Analyst

BR flagBrazil OnlyFull-timeSecurity Analyst
ApplyView job
Stefanini LATAM3 days ago

Analista de Seguridad de la Información – Gestión de Alertas DLP

CO flagColombia OnlyFull-timeSecurity Analyst
ApplyView job
Bancorbrás3 days ago

Security Analyst – Purple Team, Offensive and Defensive Security

BR flagBrazil OnlyFull-timeSecurity Analyst
ApplyView job
Kemper3 days ago

Application Security Analyst

US flagAlabama, +2 more statesFull-timeSecurity Analyst$93.5k – $155.5k/year
ApplyView job
Empeople Credit Union3 days ago

Information Security Analyst

US flagIllinois OnlyFull-timeSecurity Analyst$75.8k – $113.6k/year
ApplyView job
VC33 days ago

IT Security Analyst I – Evening Shift

US flagUnited States OnlyFull-timeSecurity Analyst
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers