We are seeking a GRC Analyst to manage our daily risk and control operations, maintain our documentation library and support audit coordination within our Trust Office. In this role, you'll help build and be part of our governance operating model as we scale our compliance and security efforts.
You’ll work closely with the GRC Officer, CTO and partner heavily with the Product Team.
Control Testing & Risk Tracking: Execute routine security control testing and maintain Key Risk Indicators.
Trust Center Maintenance: Keep our public security trust center and standard security documentation up-to-date so existing and potential customers can self-service security reviews.
Customer Compliance: Assist with routine incoming customer inquiries, security questionnaires and vendor assessments.
Audit and Policy Support: Assist with external audit readiness (state certifications such as MitID Broker, NSIS, FTN and our ISMS ISAE 3000) and perform regular policy reviews.
Vendor Risk Management: Evaluate third-party vendors and cloud subprocessors to ensure they meet our security standards before onboarding.
Vulnerability Triage: Serve as the first point of contact for vulnerability disclosures, assessing severity and coordinating remediation with engineering.
3+ years of experience in governance of risk and compliance, IT audit, or risk management.
Solid understanding of core security controls and frameworks (e.g., ISO 27001, SOC 2, risk methodologies).
Ability to translate technical vulnerability data into actionable risk assessments.
Ability to balance security requirements with business agility, finding solutions that work with engineering workflows rather than blocking them.
Strong written and verbal communication skills.
It’s a plus if you are familiar with hyperscalers and cloud platforms, in a SaaS setup like MS Azure, AWS or Google Cloud.
Experience with process automation and configuring AI agents is a plus.
This job comes with several perks and benefits
