Skip to content

Open nowPosted 5 days agoWe saw it 31 min after it went up

Governance, Risk and Compliance (GRC) Analyst

Nasuni34 open roles

Where
England, United Kingdom
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowGovernance, Risk and Compliance (GRC) AnalystNasuni · England, United Kingdom
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Nasuni's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Nasuni postings stay open a median of 28 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 5 days ago

Nasuni median: 28 days open

The posting

Governance, Risk & Compliance (GRC) Analyst

Location: EMEA/UK Remote

Summary of Role

Nasuni is looking for a Governance, Risk & Compliance (GRC) Analyst to help operate and strengthen the programs that support our security, compliance, and risk posture. You will take hands-on ownership of defined GRC workflows including third-party risk assessments, customer security requests, security awareness activities, and user access reviews. You will also support audits, enterprise risk management, policy governance, and continuous improvement across our GRC program. This opportunity is suited to an early-career GRC or security professional who has moved beyond observation and is ready to independently execute recurring processes, coordinate with stakeholders, analyze evidence, maintain accurate records, and know when a risk or exception requires escalation.

You will independently execute defined GRC processes using established controls, criteria, and escalation paths. You will work across Security, Legal, Procurement, Sales, Customer Success, IT, and other business teams while partnering closely with senior GRC colleagues on higher-complexity risk and compliance matters. Success means delivering reliable GRC operations, maintaining audit-ready information, identifying issues early, and continuously finding practical ways to make recurring work more efficient.

Primary Responsibilities

  • Conduct third-party security and compliance assessments, reviewing SOC reports, ISO certifications, questionnaires, and other evidence; document findings and track remediation or approved risk treatment.
  • Coordinate vendor assessments from intake and due diligence through reassessment using established risk criteria.
  • Respond to customer security questionnaires, RFPs, and due-diligence requests, maintaining accurate reusable security and control content.
  • Coordinate approved security and compliance artifacts for customers and support internal teams with security-related contractual requests.
  • Administer security awareness activities, including training campaigns, phishing simulations, completion tracking, communications, and program metrics.
  • Plan and execute periodic user access reviews, coordinate with system owners, identify inappropriate or orphaned access, and track remediation and exceptions.
  • Support SOC 1, SOC 2, ISO 27001, and other assessments by gathering and validating evidence, maintaining documentation, and tracking corrective actions.
  • Maintain accurate risk, policy, exception, finding, and remediation records and support reporting for GRC stakeholders and leadership.
  • Identify opportunities to simplify or automate recurring GRC activities while maintaining appropriate controls and human review.
  • Use approved AI-enabled tools where appropriate to accelerate research, analysis, drafting, summarization, and workflow improvement while validating outputs and protecting confidential information.

Qualifications

  • 2+ years of hands-on experience in GRC, information security, IT audit, risk, compliance, or a closely related discipline.
  • Practical experience executing at least two GRC activities such as third-party risk reviews, access reviews, audit evidence collection, security questionnaires, security awareness, risk tracking, or compliance operations.
  • Working knowledge of security or compliance frameworks such as SOC 1/2, ISO 27001, NIST, GDPR, HIPAA, or comparable standards.
  • Ability to review evidence, document findings clearly, manage deadlines, and follow issues through resolution.
  • Strong written communication and ability to work effectively with technical and non-technical stakeholders.
  • Sound judgment around confidential information, risk escalation, and quality control.
  • Experience supporting external audits or formal certification programs.
  • Experience using a GRC platform such as LogicGate, OneTrust, Vanta, Drata, or a comparable system.
  • Experience in a SaaS, cloud, technology, or other fast-moving environment.
  • Practical use of AI-enabled tools to improve analysis, documentation, reporting, or workflow efficiency with appropriate validation.
  • Experience across three or more GRC operational areas.
  • Exposure to cloud/SaaS security and customer assurance processes.
  • Security+, GSEC, or similar certification, or progress toward CISA, CRISC, CISM, or ISO 27001 credentials.
  • Evidence of improving or automating a recurring GRC workflow.

About Nasuni

Nasuni is the unstructured data foundation for enterprise teams—and the AI that supports them. We manage, protect, and activate the world’s unstructured data so organizations can work smarter, spend wisely, and create safely without limits. Our AI-ready platform modernizes enterprise file infrastructure—supporting secure collaboration, resilience, and intelligent automation for globally distributed organisations.

Why Work at Nasuni (London/EMEA — Remote)

You’ll join an international team solving complex infrastructure challenges for enterprise customers across regions and time zones. Our remote roles in Europe are built for high ownership, clear communication, and cross-functional collaboration—delivering outcomes that improve how organisations store, protect, and activate unstructured data. If you enjoy working across cultures, building scalable systems, and partnering closely with stakeholders to deliver customer value, Nasuni offers the platform and mission to do it.

About Nasuni.

Nasuni is the leading hybrid cloud storage solution that powers business growth with effortless scalability, built-in security, and fast edge performance using a unique cloud-native architecture. The Nasuni File Data Platform delivers operational excellence by consolidating NAS and backup, eliminating data silos, and making management easy and flexible without changes to apps or workflows. Its built-in security offers proactive defense and rapid recovery, lowering organization’s risk from the detrimental effects of ransomware attacks and other disasters. Synchronized access to file data everywhere ensures user productivity by supporting remote and hybrid work.

Why work at Nasuni?

As part of our commitment to your well-being, we are pleased to offer comprehensive benefits packages to employees across the world. Benefits packages generally include:

  • Best in class employee onboarding and training
  • Comprehensive health, dental and vision plans
  • Life and disability insurance
  • Retirement plan
  • Generous employee referral bonuses
  • Flexible remote work policy
  • Collaborative workspaces

To all recruitment agencies: Nasuni does not accept agency resumes. Please do not forward resumes to our job boards, Nasuni employees or any other company location. Nasuni is not responsible for any fees related to unsolicited resumes.

Nasuni is an equal opportunity employer. The equal employment opportunity policy at Nasuni protects employees and job applicants from discrimination on the bases of race, religion, color, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, family medical history or genetic information, political affiliation, military service, or other non-merit based factors. These protections extend to all management practices and decisions, including recruitment and hiring practices, appraisal systems, promotions, and training and career development programs.

This privacy notice relates to information collected (whether online or offline) by Nasuni Corporation and our corporate affiliates (collectively, “Nasuni”) from or about you in your capacity as a Nasuni employee, independent contractor/service provider or as an applicant for an employment or contractor relationship with Nasuni.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Nasuni's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Nasuni's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Nasuni's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.