
Senior GRC Analyst II, ISO 27001
Posted Jun 22

Posted Jun 22
This is a fully remote position, open to applicants in Ireland.
• Lead ISO 27001 readiness engagements, Stage 1 / Stage 2 certification audits, surveillance audits, and recertification audits in accordance with ISO/IEC 27001:2022.
• Take ownership of engagement planning, scoping, timelines, client relationships, and execution across multiple simultaneous ISO 27001 clients.
• Conduct audits on ISMS design, control selection, and implementation aligned with ISO 27001 clauses and Annex A controls while considering organizational risk context.
• Serve as both an internal and external subject matter expert on GRC and compliance automation platforms (e.g., Drata, Vanta, Secureframe, OneTrust, or similar tools) in relation to ISO 27001.
• Configure and optimize client platform environments, which include:
• - Mapping ISO 27001 controls to Annex A and the organizational risk register.
• - Managing evidence workflows and documentation.
• - Setting up automated integrations (cloud providers, ticketing systems, HRIS, code repositories, etc.).
• - Establishing continuous monitoring settings that align with ISMS objectives.
• Review automated control outputs and exception reporting to ensure audit defensibility.
• Identify opportunities to enhance automation coverage and decrease manual evidence collection.
• Collaborate with clients to advance their ISMS operations utilizing platform analytics and reporting.
• Review, document, and test IT general controls (logical access, change management, system operations) mapped to ISO 27001 Annex A domains.
• Evaluate technical and organizational controls within SaaS, cloud-native, and hybrid environments.
• Assess controls related to infrastructure environments (AWS, Azure, GCP), identity management, and DevOps workflows in accordance with ISO 27001 requirements.
• Validate the sufficiency and completeness of evidence within compliance platforms to support certification conclusions.
• Assist in risk assessment and risk treatment processes central to ISMS implementation.
• Act as the primary point of contact for ISO 27001 clients, including executive-level stakeholders.
• Present audit findings, risk insights, and general advisory recommendations to client leadership.
• Provide general advisory services to high-growth SaaS and technology clients on developing scalable, certification-ready ISMS programs.
• Support sales and go-to-market efforts for ISO 27001 services, including scoping and offering technical input on proposals.
• Mentor junior analysts on ISO 27001 methodology, platform navigation, and control testing best practices.
• Contribute to the refinement of ISO 27001 templates, testing programs, risk assessment frameworks, and platform playbooks.
• Identify efficiencies to standardize and scale ISO 27001 engagements across the practice.
• Support training initiatives to enhance internal ISO 27001 platform expertise.
• 4+ years of experience in ISO 27001, IT audit, or GRC, preferably in public accounting or consulting.
• Bachelor’s degree in Information Systems, Computer Science, Accounting, or a related field; an advanced degree is a plus.
• Proven experience in leading ISO 27001 certification engagements (Stage 1 and Stage 2).
• Practical experience administering or auditing within GRC/compliance automation platforms (e.g., Drata, Vanta, Secureframe, OneTrust, or similar) in an ISO 27001 context.
• Comprehensive understanding of:
• - The ISO/IEC 27001:2022 standard and Annex A controls.
• - ISMS risk assessment and risk treatment methodologies.
• - IT General Controls (ITGCs).
• - Cloud environments (AWS, Azure, GCP).
• - SaaS operational environments.
• Experience in reviewing automated evidence and continuous monitoring outputs in support of certification.
• Strong client advisory and presentation skills, including the ability to communicate effectively with executive-level personnel.
• Capability to manage multiple engagements in fast-paced, high-growth settings.
• Preferred:
• Experience with venture-backed or high-growth SaaS companies.
• Familiarity with related frameworks (SOC 2, NIST CSF, ISO 27701, ISO 27017/27018).
• Experience with ISO 27001 internal auditor or lead auditor programs.
• Professional certifications such as ISO 27001 Lead Auditor/Lead Implementer, CISA, CISSP, CISM, or CRISC.
• There are numerous reasons to join the Sensiba team: generous benefits, competitive compensation, opportunities for professional advancement, and above all — our people. If you seek an environment that fosters growth, success, and professionalism without compromising your family, passions, and life outside of work, apply today!
• Sensiba offers a comprehensive benefits package, which includes:
• - **Comprehensive Health Coverage** – Medical, dental, and vision.
• - **Generous Paid Time Off** – Vacation, sick leave, holidays, parental leave, and volunteer days.
• - **Flexible Work Arrangements** – Options for hybrid or remote work, along with flexible hours.
• - **Performance-Based Bonus** – Recognition of your contributions through discretionary bonuses.
• - **Professional Development Opportunities** – Tuition reimbursement, certifications, and mentorship.
• - **Career Growth & Internal Mobility** – Clear paths for advancement and role transitions.
• - **Inclusive & Supportive Culture** – DEI initiatives, employee resource groups, and wellness programs.
ZoomInfo
Lifelancer
unybrands
Get handpicked remote jobs straight to your inbox weekly.