We are looking for an IT Compliance Analyst/Information Security GRC Analyst to join our Security team and help strengthen the effectiveness and transparency of our security controls.
In this role, you will work across security compliance, control assurance, third-party risk, and security awareness. You will collaborate with Security, Legal, Procurement, technical and business teams to ensure controls are supported by reliable evidence, risks are identified and tracked, and the organization remains ready for audits and regulatory requirements.
This is a great opportunity for someone who enjoys hands-on GRC work, wants to take ownership of processes, and is interested in developing expertise across multiple areas of information security compliance.
Requirements
- Experience in IT compliance, Information Security GRC, IT risk, IT audit, third-party security risk, or a related field
- Hands-on experience collecting, validating, and maintaining audit and control evidence
- Understanding of security controls and experience with control testing, gap identification, and remediation tracking
- Knowledge of information security and assurance frameworks such as SOC 2, ISO 27001, NIST, CIS Controls, or similar
- Understanding of risk assessment and risk treatment principles
- Ability to maintain accurate control records, findings, remediation actions, owners, and deadlines
- Strong attention to detail and ability to work with sensitive information
- Clear written and verbal communication skills with both technical and non-technical stakeholders
- Good English communication skills
Will be a plus
- Experience with SOC 2, DORA, CySEC, or other financial-services regulatory requirements
- Experience with third-party/vendor security risk management, including supplier assessments, security questionnaires, and due diligence
- Experience with GRC platforms such as ServiceNow GRC, OneTrust, Archer, Vanta, Drata, Hyperproof, or similar
- Experience preparing or delivering security awareness activities, phishing simulations, onboarding, or role-based security training
- Relevant certifications such as CISA, CRISC, CISM, ISO 27001 Lead Auditor/Implementer, or similar
- Experience supporting internal or external audits
- Experience working in FinTech, financial services, SaaS, or another regulated environment
Responsibilities
- Collect, validate, organize, and maintain audit and security-control evidence
- Test assigned security controls, identify gaps, and prepare clear and traceable evidence packages
- Support internal and external audits, including SOC 2, DORA, and CySEC-related assurance activities
- Maintain control records, evidence repositories, findings, remediation actions, owners, and deadlines
- Perform third-party security assessments, including supplier tiering, due diligence, questionnaire reviews, and analysis of assurance evidence
- Assess security risks related to SaaS providers, ICT providers, outsourced services, and critical vendors
- Track supplier findings, treatment plans, reassessment dates, and remediation progress
- Collaborate with Security, Procurement, Legal, technical teams, and business stakeholders
- Support security-awareness campaigns, employee onboarding, phishing simulations, and role-based training
- Maintain awareness and training completion data and follow up on outstanding actions
- Prepare clear, evidence-based compliance and security-risk reporting
- Escalate control gaps, overdue evidence, critical supplier findings, and other significant risks through established processes
We offer
- Tax expenses coverage for private entrepreneurs in Ukraine
- Expert support and guidance for Ukrainian private entrepreneurs
- 20 paid vacation days per year
- 10 paid sick leave days per year
- Public holidays as per the company's approved Public holiday list
- Medical budget
- Opportunity to work remotely
- Professional education budget
- Language learning budget
- Wellness budget (gym membership, sports gear and related expenses)
Seen 5 hours ago · JustMarkets postings close after a median of 14 days.
Original posting on JustMarkets's site ↗
Posting text belongs to the employer. Removal requests: contact us.
Nearby
Live postings like this one
Same employer first, then the same role elsewhere.
- 5h ago
- 5h ago
- 1d ago
- 1d ago
- Remote2d ago
- 2d ago
- 5d ago
- Remote7d ago
One job at a time
One posting. One CV. $25.
Pick the job you actually want and we write for it.