HQ - GRC Senior Analyst

 Posted 3 days ago
  
 Spain
  
10+ years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

The GRC Senior Analyst will lead the implementation of ISO 27001 and GDPR compliance frameworks while managing the Information Security Management System. They will act as the primary point of contact for auditors and collaborate with cross-functional teams to embed security controls into business processes.

We are looking for a GRC Senior Analyst to own and scale our Governance, Risk, and Compliance function within a fast-growing product company. This is a key role responsible for ensuring compliance with SOX, ISO 27001, and GDPR, while enabling the business to move fast in a secure and controlled way.

You will act as the main driver of our compliance strategy, working cross-functionally with Engineering, Security, Legal, Finance, and Product teams.

\n


What you will do
  • Own and lead the company’s GRC implementation across ISO 27001 and GDPR.
  • Build and manage the Information Security Management System (ISMS) aligned with ISO 27001.
  • Ensure GDPR compliance across all data processing activities, including data mapping, data leaks, and encryptions.
  • Act as the primary point of contact for auditors and prepare the company for ISO audits.
  • Identify compliance gaps and drive remediation plans with technical and non-technical teams.
  • Develop governance policies, procedures, and risk management frameworks.
  • Partner closely with Engineering and Security teams to embed controls into systems and SDLC processes.
  • Monitor regulatory and compliance changes and translate them into actionable requirements.


Mandatory Requirements
  • 8+ years of experience in GRC, Risk, Compliance, or IT Audit roles
  • 5+ years of strong hands-on experience with ISO 27001 and experience managing or supporting ISMS implementation.
  • 3+ years of practical experience with GDPR data mapping, reviewing systems from the tech side.
  • 5+ years of experience from a product tech company with global client reach in the US & EU (companies above 100 people).
  • Experience working with internal and external auditors
  • Very strong stakeholder management and communication skills across technical and non-technical teams.
  • Fluent English


Nice to have
  • Familiarity with cloud environments (AWS, GCP, Azure).
  • Security certifications (CISA, CISM, ISO 27001 Lead Implementer/Auditor). 
  • Other security experience.


\n

#LI-OK1

Similar Jobs

See all Remote Others jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Others

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified