
Staff GRC Analyst
Posted Aug 24

Posted Aug 24
This is a fully remote position, open to applicants in United Kingdom, +3 more countries.
• Streamline and automate legacy governance, risk, and compliance systems for ISO 27001, PCI-DSS, DORA, UK Cyber Essentials, and pertinent financial services regulations.
• Develop GRC workflows that integrate ticketing, asset management, identity management, and cloud platforms.
• Create and implement scalable GRC architectures and automation solutions for evidence collection, control testing, and compliance reporting.
• Draft, review, and uphold security policies aligned with relevant control standards.
• Automate the management of incoming security requests, questionnaires, review calls, and documentation from customers and prospects.
• Automate assessments of third-party vendors and monitor the resolution of compliance and security issues.
• Automate compliance metrics and KPI reporting for enhanced visibility for leadership.
• Convert compliance requirements into technical specifications for engineering teams.
• Communicate compliance matters effectively to non-technical stakeholders.
• Manage complex multi-team workstreams, including dependencies, priorities, and delivery timelines.
• Contribute to broader initiatives and objectives of the Cybersecurity team.
• Report to the VP of Fraud & Security and work collaboratively with Risk and Compliance, Procurement, Legal, Finance, Engineering, and other departments.
• Extensive experience in Security GRC.
• Knowledge of auditing processes.
• Hands-on experience with both internal and external audit cycles.
• Proven experience leveraging AI and/or coding automation to develop, implement, and manage controls.
• Strong understanding of cloud architectures, including AWS or equivalent.
• Experience correlating infrastructure decisions with security controls and audit evidence.
• Proven ability to automate reporting for GRC programs, including the creation of dashboards and executive-level summaries.
• Background in fintech, the payments industry, or IT auditing.
• Familiarity with regulatory requirements and payment platform architectures.
• Relevant certifications such as CISM, CISSP, CISA, or PCI-related credentials.
• A degree in Cybersecurity, Engineering, Computer Science, Mathematics, or equivalent experience is advantageous.
• Ability to collaborate effectively with colleagues who do not have engineering backgrounds.
• Applications must be submitted in English.
• Must be physically located in the chosen country with a valid right to work.
• Visa sponsorship is not available.
• Your own Pleo card.
• Catered meals or a lunch allowance based on your local office.
• Comprehensive private healthcare, with coverage options including Vitality, Alan, or Médis depending on location.
• 25–28 days of holiday depending on location, plus public holidays.
• Hybrid and fully remote working options.
• Option to purchase an additional 5 days of holiday through salary sacrifice.
• Free mental health and well-being support through MyndUp.
• Paid parental leave.
• Career development opportunities, including larger projects, leadership roles, and skill acquisition.
ICON plc
CBH
Sysco
International SOS
Get handpicked remote jobs straight to your inbox weekly.