
Senior GRC Analyst
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Latvia, +4 more countries.
• Plan and carry out internal and external audit activities in accordance with ISO 27001, SOC 2, and associated frameworks.
• Gather evidence and ensure readiness of controls.
• Engage directly with external auditors.
• Follow up on audit findings until they are resolved.
• Represent the department during audit interactions and professionally decline inappropriate requests when necessary.
• Design and implement automation solutions for evidence gathering and routine compliance tasks.
• Utilize compliance-as-code practices where they provide measurable benefits.
• Employ AI-driven agents and workflows to minimize manual tasks.
• Keep up-to-date with the commercial GRC platform landscape.
• Favor established industry solutions over custom development options.
• Conduct security evaluations of third-party vendors during onboarding and annual assessments.
• Continuously enhance the efficiency of vendor security assessments.
• Maintain the risk register.
• Execute risk assessments and monitor remediation plans.
• Ensure that identified risks are addressed in a timely manner.
• Collaborate with the manager to develop and sustain information security policies and procedures.
• Contribute to creating security awareness materials and delivering training.
• Over 5 years of experience in cybersecurity GRC, IT auditing, or security compliance.
• Direct involvement in comprehensive ISO 27001 and/or SOC 2 audit processes.
• Excellent communication and negotiation abilities.
• Professional confidence to maintain a position under pressure from auditors, vendors, and internal stakeholders.
• Discernment to recognize when refusal is the appropriate response.
• Proven automation skills demonstrated through scripts, integrations, GRC platform implementations, or AI-assisted workflows.
• History of creating effective automation; a software engineering background is not a requirement.
• Self-motivated work style with strong accountability.
• Capability to navigate ambiguous problems to successful outcomes with minimal guidance.
• Proficient written and spoken English.
• Relevant certifications such as ISO 27001 Lead Implementer/Lead Auditor, CISA, CISSP, or CISM are beneficial but not mandatory.
• Practical audit experience is valued more highly than certification.
• A high-trust, compact team with minimal bureaucracy.
• The option to work remotely or from a modern and welcoming office in Riga.
• Flexible working hours (start your day as late as 11 AM).
• Private health insurance.
• Two additional paid days off to prioritize your mental or physical well-being.
• One extra paid day off to celebrate a birthday or any personal occasion of your choice.
• Opportunities for internal and external learning.
• Access to mentorship, internal meetups, and hackathons, both on-site and online.
• Complimentary healthy lunch for those working from the Rīga office.
• Design and order your own merchandise using our platforms with an employee discount.
• Enjoy exciting team-building events and unforgettable parties!
Logic20/20, Inc.
Wavestone
Novartis
AAA
Get handpicked remote jobs straight to your inbox weekly.