
Information Security Analyst, GRC
Posted Sep 11

Posted Sep 11
This is a fully remote position, open to applicants in United Kingdom.
• Assist customers and prospects by completing technical security questionnaires, risk assessments, and due diligence requests.
• Collaborate with Sales and Customer teams to articulate XBOW’s security controls, architecture, and compliance stance.
• Evaluate and oversee security risks associated with third-party vendors, including SaaS providers and service partners.
• Investigate and address alerts to uphold compliance using Vanta.
• Aid in the maintenance and enhancement of risk assessment frameworks, methodologies, and documentation.
• Monitor and facilitate the remediation of identified risks with internal stakeholders.
• Contribute to compliance efforts aligned with SOC 2, FedRAMP 20x, ISO 27001, and ISO 42001.
• Manage risk registers, policies, and supporting documentation.
• Organize risk management sessions and related processes.
• Discover opportunities to streamline and automate risk and compliance procedures.
• Assist with audits, customer evaluations, and internal assurance activities as necessary.
• Work collaboratively with IT, Security, Engineering, Legal, Sales, and Customer teams as an individual contributor.
• Over 7 years of experience in risk, compliance, security assurance, or similar roles.
• Background in hands-on technical positions, such as Engineering, IT, or operational security.
• Practical experience in completing or reviewing technical security questionnaires and customer risk assessments.
• Knowledge and experience with security compliance and data protection frameworks like SOC 2, ISO 27001, NIST, GDPR, and HIPAA.
• Experience in conducting or aiding vendor/third-party risk assessments.
• Excellent written communication skills with the ability to clarify complex security concepts effectively.
• Highly organized and detail-oriented, adopting a pragmatic approach to risk management.
• Comfortable operating in a dynamic, remote-first startup environment.
• Familiarity with contemporary AI tools to enhance productivity while managing risk.
• Prior experience in a SaaS or security-centric company is a plus.
• Experience with handling Subject Access Requests for GDPR is a plus.
• Security or risk certifications such as CRISC or CISSP are beneficial.
• Knowledge of cloud security best practices is advantageous.
• Meaningful stock options.
• Opportunity to learn from and collaborate with leading security and AI experts.
• Engage in complex technical challenges that underpin the company’s foundation.
• Remote-first work arrangement.
• Flexibility to work from anywhere, with regular opportunities for in-person meetings.
• Supported travel to collaborate with colleagues face-to-face.
Vision Cybersecurity
Stefanini LATAM
Bancorbrás
Kemper
Get handpicked remote jobs straight to your inbox weekly.