The analyst will collect and validate audit evidence, test security controls, and identify gaps to ensure organizational compliance. They will also perform third-party security assessments and deliver security awareness training to stakeholders.
We are looking for an IT Compliance Analyst/Information Security GRC Analyst to join our Security team and help strengthen the effectiveness and transparency of our security controls.
In this role, you will work across security compliance, control assurance, third-party risk, and security awareness. You will collaborate with Security, Legal, Procurement, technical and business teams to ensure controls are supported by reliable evidence, risks are identified and tracked, and the organization remains ready for audits and regulatory requirements.
This is a great opportunity for someone who enjoys hands-on GRC work, wants to take ownership of processes, and is interested in developing expertise across multiple areas of information security compliance.
Requirements
Experience in IT compliance, Information Security GRC, IT risk, IT audit, third-party security risk, or a related field
Hands-on experience collecting, validating, and maintaining audit and control evidence
Understanding of security controls and experience with control testing, gap identification, and remediation tracking
Knowledge of information security and assurance frameworks such as SOC 2, ISO 27001, NIST, CIS Controls, or similar
Understanding of risk assessment and risk treatment principles
Ability to maintain accurate control records, findings, remediation actions, owners, and deadlines
Strong attention to detail and ability to work with sensitive information
Clear written and verbal communication skills with both technical and non-technical stakeholders
Good English communication skills
Will be a plus
Experience with SOC 2, DORA, CySEC, or other financial-services regulatory requirements
Experience with third-party/vendor security risk management, including supplier assessments, security questionnaires, and due diligence
Experience with GRC platforms such as ServiceNow GRC, OneTrust, Archer, Vanta, Drata, Hyperproof, or similar
Experience preparing or delivering security awareness activities, phishing simulations, onboarding, or role-based security training
Relevant certifications such as CISA, CRISC, CISM, ISO 27001 Lead Auditor/Implementer, or similar
Experience supporting internal or external audits
Experience working in FinTech, financial services, SaaS, or another regulated environment
Responsibilities
Collect, validate, organize, and maintain audit and security-control evidence
Test assigned security controls, identify gaps, and prepare clear and traceable evidence packages
Support internal and external audits, including SOC 2, DORA, and CySEC-related assurance activities
Maintain control records, evidence repositories, findings, remediation actions, owners, and deadlines
Perform third-party security assessments, including supplier tiering, due diligence, questionnaire reviews, and analysis of assurance evidence
Assess security risks related to SaaS providers, ICT providers, outsourced services, and critical vendors
Track supplier findings, treatment plans, reassessment dates, and remediation progress
Collaborate with Security, Procurement, Legal, technical teams, and business stakeholders
Support security-awareness campaigns, employee onboarding, phishing simulations, and role-based training
Maintain awareness and training completion data and follow up on outstanding actions
Prepare clear, evidence-based compliance and security-risk reporting
Escalate control gaps, overdue evidence, critical supplier findings, and other significant risks through established processes
We offer
Tax expenses coverage for private entrepreneurs in Ukraine
Expert support and guidance for Ukrainian private entrepreneurs
20 paid vacation days per year
10 paid sick leave days per year
Public holidays as per the company's approved Public holiday list
Medical budget
Opportunity to work remotely
Professional education budget
Language learning budget
Wellness budget (gym membership, sports gear and related expenses)
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”