Skip to content

Open nowPosted 27 days ago

Information Security Analyst, GRC

XBOW6 open roles

Where
Europe (Remote)
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowInformation Security Analyst, GRCXBOW · Europe (Remote)
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on XBOW's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. XBOW postings stay open a median of 18 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.5%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 33.9%30 days
This job: posted 27 days ago

XBOW median: 18 days open

The posting

ABOUT XBOW

At XBOW, we’re redefining the future of cybersecurity by building the world's first autonomous pentester, powered by AI. Today, the gold standard for securing software systems is human pentesters, but with the rise of artificial intelligence, we’re stepping up to scale offensive security to meet the ever-growing demand.

AI is transforming the landscape of both cybersecurity and cyberattacks. While millions of people without security expertise are creating software, bad actors are using AI to launch more effective attacks. XBOW fights back with AI-driven superpowers, enabling security teams to stay one step ahead.

What makes XBOW truly unique? Like human experts, it forges creative attacks, adapts its learnings, and continuously works to find vulnerabilities faster than anyone ever could. We’re not only simulating threats—we’re also finding and responsibly disclosing real-world vulnerabilities, ensuring organizations can fix issues before they’re exploited. XBOW isn’t just a tool; it’s a transformative force in the secure development lifecycle.

Backed by Sequoia Capital and a team that includes the creators of GitHub Copilot and GitHub Advanced Security, XBOW is not just keeping up with the times—we’re shaping the future of cybersecurity. Our mission is simple: to defeat the bad actors before they strike, using AI to revolutionize how we approach offensive security.

We’re building something that must be built, and we’re the team to do it. Join us in shaping the next frontier of autonomous security.

YOUR ROLE: INFORMATION SECURITY ANALYST, GRC

We’re looking for a detail-oriented, Information Security Analyst to help scale our security and trust function as we grow. In this role, you’ll play a key part in supporting customer and prospect security reviews, coordinating with legal on reviewing customer contracts, assessing third-party vendor risk, supporting resolution of compliance alerts and continuously improving how we identify and manage risk across the business.

This is an individual contributor role with no initial people-management responsibilities. However, as the risk and compliance function matures, there is a clear opportunity for this role to grow in scope and responsibility.

You’ll work closely with IT, Security, Engineering, Legal, Sales, and Customer teams, acting as a trusted partner in communicating our security posture and ensuring we meet customer and regulatory expectations.

WHAT YOU'LL DO

- Support customers and prospects by completing technical security questionnaires, risk assessments, and due-diligence requests

- Partner with Sales and Customer teams to explain XBOW’s security controls, architecture, and compliance posture

- Assess and manage third-party and vendor security risk, including reviews of SaaS providers and service partners

- Investigate and resolve alerts to stay compliant with our compliance programmes using the Vanta product.

- Help maintain and improve risk assessment frameworks, methodologies, and documentation

- Track and support remediation of identified risks in collaboration with internal stakeholders

- Contribute to compliance initiatives aligned with frameworks such as SOC 2, FedRAMP 20x, ISO 27001, and ISO 42001

- Maintain clear, well-structured risk registers, policies, and supporting evidence

- Coordinate risk management sessions and processes

- Identify opportunities to streamline and automate risk and compliance processes as the company scales

- Support audits, customer reviews, and internal assurance activities as needed

SKILLS AND QUALIFICATIONS

ESSENTIAL

- 7+ years of experience in risk, compliance, security assurance, or related roles

- Experience in hands-on technical roles for example in Engineering, IT or operational security

- Hands-on experience completing or reviewing technical security questionnaires and customer risk assessments

- Familiarity and experience with common security compliance, and data protection frameworks (e.g. SOC 2, ISO 27001, NIST, GDPR, and HIPAA)

- Experience conducting or supporting vendor / third-party risk assessments

- Strong written communication skills, with the ability to explain complex security concepts clearly

- Highly organized and detail-oriented, with a pragmatic approach to risk

- Comfortable working in a fast-moving, remote-first startup environment

- Familiar with using modern AI tooling to improve productivity whilst managing risk

ADVANTAGEOUS

- Experience working in a SaaS or security-focused company

- Experience handling Subject Access Requests for GDPR

- Security or risk certifications (e.g. CRISC or CISSP)

- Knowledge of cloud security best practices

WHAT WE OFFER

- Compensation & Equity: Competitive salary and meaningful stock options.

- Growth: Opportunity to learn from and collaborate with top security and AI experts

- Impact: Work on complex technical challenges that support the foundation of our company

- Remote-First:Work from anywhere, with regular opportunities to meet in person

WHAT ELSE YOU SHOULD KNOW

- Location: Remote UK/EU (all team members are remote but we meet regularly and you’re supported to travel to collaborate with colleagues in person)

- Contract: Full-time.

- Hiring Process: 1. Talent Introduction 2. GRC & Security Knowledge Interview - A conversation about your practical security and GRC knowledge and how you apply it in day-to-day compliance work. 3. Hiring Manager Interview 4. Final Interview with a member of our leadership team

We’re a security company that builds with AI at the core - so you’ll be protecting a team that moves fast, iterates aggressively, and lives in the command line. If that sounds like your kind of environment, let’s talk.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against XBOW's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on XBOW's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    XBOW's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.