For Employers

Nasuni

Governance, Risk and Compliance (GRC) Analyst

Posted 2 hours ago
2-5 years experience
Apply Now

Please mention DailyRemote when applying

?
Resume Match Score

See how much of this job your resume covers, and what’s missing.

Want a recruiter to go through it line by line?

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

The GRC Analyst will operate and strengthen security, compliance, and risk programs by managing third-party risk assessments, customer security requests, and user access reviews. They will also support internal audits, maintain policy governance, and identify opportunities to automate recurring GRC workflows.

Governance, Risk & Compliance (GRC) Analyst

Location: EMEA/UK Remote

Summary of Role

Nasuni is looking for a Governance, Risk & Compliance (GRC) Analyst to help operate and strengthen the programs that support our security, compliance, and risk posture.
You will take hands-on ownership of defined GRC workflows including third-party risk assessments, customer security requests, security awareness activities, and user access reviews. You will also support audits, enterprise risk management, policy governance, and continuous improvement across our GRC program.
This opportunity is suited to an early-career GRC or security professional who has moved beyond observation and is ready to independently execute recurring processes, coordinate with stakeholders, analyze evidence, maintain accurate records, and know when a risk or exception requires escalation.

You will independently execute defined GRC processes using established controls, criteria, and escalation paths. You will work across Security, Legal, Procurement, Sales, Customer Success, IT, and other business teams while partnering closely with senior GRC colleagues on higher-complexity risk and compliance matters.
Success means delivering reliable GRC operations, maintaining audit-ready information, identifying issues early, and continuously finding practical ways to make recurring work more efficient.

Primary Responsibilities

  • Conduct third-party security and compliance assessments, reviewing SOC reports, ISO certifications, questionnaires, and other evidence; document findings and track remediation or approved risk treatment.
  • Coordinate vendor assessments from intake and due diligence through reassessment using established risk criteria.
  • Respond to customer security questionnaires, RFPs, and due-diligence requests, maintaining accurate reusable security and control content.
  • Coordinate approved security and compliance artifacts for customers and support internal teams with security-related contractual requests.
  • Administer security awareness activities, including training campaigns, phishing simulations, completion tracking, communications, and program metrics.
  • Plan and execute periodic user access reviews, coordinate with system owners, identify inappropriate or orphaned access, and track remediation and exceptions.
  • Support SOC 1, SOC 2, ISO 27001, and other assessments by gathering and validating evidence, maintaining documentation, and tracking corrective actions.
  • Maintain accurate risk, policy, exception, finding, and remediation records and support reporting for GRC stakeholders and leadership.
  • Identify opportunities to simplify or automate recurring GRC activities while maintaining appropriate controls and human review.
  • Use approved AI-enabled tools where appropriate to accelerate research, analysis, drafting, summarization, and workflow improvement while validating outputs and protecting confidential information.

Qualifications

  • 2+ years of hands-on experience in GRC, information security, IT audit, risk, compliance, or a closely related discipline.
  • Practical experience executing at least two GRC activities such as third-party risk reviews, access reviews, audit evidence collection, security questionnaires, security awareness, risk tracking, or compliance operations.
  • Working knowledge of security or compliance frameworks such as SOC 1/2, ISO 27001, NIST, GDPR, HIPAA, or comparable standards.
  • Ability to review evidence, document findings clearly, manage deadlines, and follow issues through resolution.
  • Strong written communication and ability to work effectively with technical and non-technical stakeholders.
  • Sound judgment around confidential information, risk escalation, and quality control.
  • Experience supporting external audits or formal certification programs.
  • Experience using a GRC platform such as LogicGate, OneTrust, Vanta, Drata, or a comparable system.
  • Experience in a SaaS, cloud, technology, or other fast-moving environment.
  • Practical use of AI-enabled tools to improve analysis, documentation, reporting, or workflow efficiency with appropriate validation.
  • Experience across three or more GRC operational areas.
  • Exposure to cloud/SaaS security and customer assurance processes.
  • Security+, GSEC, or similar certification, or progress toward CISA, CRISC, CISM, or ISO 27001 credentials.
  • Evidence of improving or automating a recurring GRC workflow.

 

About Nasuni

Nasuni is the unstructured data foundation for enterprise teams—and the AI that supports them. We manage, protect, and activate the world’s unstructured data so organizations can work smarter, spend wisely, and create safely without limits. Our AI-ready platform modernizes enterprise file infrastructure—supporting secure collaboration, resilience, and intelligent automation for globally distributed organisations.

Why Work at Nasuni (London/EMEA — Remote)

You’ll join an international team solving complex infrastructure challenges for enterprise customers across regions and time zones. Our remote roles in Europe are built for high ownership, clear communication, and cross-functional collaboration—delivering outcomes that improve how organisations store, protect, and activate unstructured data. If you enjoy working across cultures, building scalable systems, and partnering closely with stakeholders to deliver customer value, Nasuni offers the platform and mission to do it.

About Nasuni.

Nasuni is the leading hybrid cloud storage solution that powers business growth with effortless scalability, built-in security, and fast edge performance using a unique cloud-native architecture. The Nasuni File Data Platform delivers operational excellence by consolidating NAS and backup, eliminating data silos, and making management easy and flexible without changes to apps or workflows. Its built-in security offers proactive defense and rapid recovery, lowering organization’s risk from the detrimental effects of ransomware attacks and other disasters. Synchronized access to file data everywhere ensures user productivity by supporting remote and hybrid work.

Why work at Nasuni?   

As part of our commitment to your well-being, we are pleased to offer comprehensive benefits packages to employees across the world.  Benefits packages generally include:   

  • Best in class employee onboarding and training
  • Comprehensive health, dental and vision plans
  • Life and disability insurance
  • Retirement plan
  • Generous employee referral bonuses
  • Flexible remote work policy
  • Collaborative workspaces

To all recruitment agencies: Nasuni does not accept agency resumes. Please do not forward resumes to our job boards, Nasuni employees or any other company location. Nasuni is not responsible for any fees related to unsolicited resumes.

Nasuni is an equal opportunity employer. The equal employment opportunity policy at Nasuni protects employees and job applicants from discrimination on the bases of race, religion, color, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, family medical history or genetic information, political affiliation, military service, or other non-merit based factors. These protections extend to all management practices and decisions, including recruitment and hiring practices, appraisal systems, promotions, and training and career development programs. 

This privacy notice relates to information collected (whether online or offline) by Nasuni Corporation and our corporate affiliates (collectively, “Nasuni”) from or about you in your capacity as a Nasuni employee, independent contractor/service provider or as an applicant for an employment or contractor relationship with Nasuni. 

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Legal jobs →

Full-Time In-house Legal Counsel (Fully Remote)

Full Time Greece Legal

Employment and Compliance Counsel

Full Time United States $220K - $270K per year Legal

Director of Legal @ ClearCo

Full Time United States $200K - $225K per year Legal

Estate Planning Specialist, Wealth Management

Full Time Canada 153K - 192K per year Legal

Strategic Claims Consultant

Full Time United States Legal

Contracts & Compliance Manager

Full Time United States Legal
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 215,488+ Jobs in Legal

Answer easy questions

Answer easy questions

215,488+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified