At a Glance
- Tasks: Join our team to support compliance initiatives and customer security assessments.
- Company: CyberArk is a leader in Identity Security, trusted by top organisations worldwide.
- Benefits: Enjoy a hybrid work model with flexible office attendance and a diverse workplace culture.
- Why this job: Be part of a fast-paced environment that values cybersecurity and regulatory compliance.
- Qualifications: 3+ years in Governance, Risk, and Compliance; strong communication and organisational skills required.
- Other info: We celebrate diversity and are committed to creating an inclusive workplace for all.
The predicted salary is between 36000 - 60000 Β£ per year.
About CyberArk: CyberArk (NASDAQ: CYBR) is the global leader in Identity Security. Centered on privileged access management, CyberArk provides the most comprehensive security offering for any identity β human or machine β across business applications, distributed workforces, hybrid cloud workloads and throughout the DevOps lifecycle. The worldβs leading organizations trust CyberArk to help secure their most critical assets.
About the Role: We are seeking a highly motivated and detail-oriented GRC Compliance Expert to join our Governance, Risk, and Compliance team. This role is pivotal in supporting customer security assessments during RFx processes, driving compliance initiatives including DORA, NIS2, and other regulatory frameworks, and assisting with broader GRC activities across the organization. The ideal candidate is a self-starter with strong communication skills, who thrives in a fast-paced environment and is passionate about cybersecurity, regulatory compliance, and risk management. Please note that this is a hybrid role located in our office in London. We ask to come to the office twice per week.
- Support the sales and legal teams during RFx processes by responding to customer security questionnaires, assessments, and due diligence requests.
- Coordinate and manage responses to customer security audits and assurance inquiries.
- Monitor regulatory changes and contribute to compliance initiatives such as DORA, NIS2, and other applicable standards and frameworks (e.g., ISO 27001, SOC 2, GDPR).
- Assist in the development, maintenance, and improvement of internal GRC processes, policies, and documentation.
- Collaborate with cross-functional teams (Security, Legal, IT, Product, etc.) to gather information and ensure compliance obligations are met.
- Participate in risk assessments, control testing, and continuous monitoring activities to support the overall risk and compliance program.
- Support customer contract negotiations by providing expert input on security and compliance clauses.
- Help prepare evidence and documentation for internal and external audits.
- Track and report on compliance project status and risks to leadership.
Qualifications:
- 3+ years of experience in Governance, Risk, and Compliance, Information Security, or a related field.
- Experience supporting sales processes, including responding to RFx security assessments.
- Solid understanding of cybersecurity principles, information security best practices, and regulatory requirements (DORA, NIS2, GDPR, ISO 27001, SOC 2, etc.).
- Excellent written and verbal communication skills; able to translate technical concepts for non-technical audiences.
- Strong organizational skills with the ability to manage multiple priorities in a dynamic environment.
- Self-motivated with a proactive approach to problem-solving and attention to detail.
- Experience working in a SaaS, cloud, or technology-driven company is preferred.
- Professional certifications (such as CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or similar) are a plus.
Additional Information: We are proud to foster a diverse and inclusive workplace, where every individual's unique background, perspective, and contribution is celebrated. We believe that by embracing diversity, we drive innovation and create a stronger, more united team. Inclusion is at the heart of who we are and how we succeed. All qualified applicants will receive consideration for employment without regard to race, colour, age, religion, sex, sexual orientation, gender identity, or disability. Upon conditional offer of employment, candidates are required to complete a comprehensive background check as per our internal policy. CyberArk is an equal opportunities employer. If you would like any special arrangements made for your interview, please inform the EMEA Talent Acquisition team upon your application so that we may take steps to accommodate your needs.
Information Security Risk & Compliance Specialist employer: Cyberark Software
Contact Detail:
Cyberark Software Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Information Security Risk & Compliance Specialist
β¨Tip Number 1
Familiarise yourself with the specific regulatory frameworks mentioned in the job description, such as DORA and NIS2. Understanding these regulations will not only help you during interviews but also demonstrate your commitment to compliance and risk management.
β¨Tip Number 2
Network with professionals in the Governance, Risk, and Compliance (GRC) field, especially those who have experience in cybersecurity. Engaging with industry experts can provide insights into the role and may even lead to referrals.
β¨Tip Number 3
Prepare to discuss your experience with RFx processes and how you've successfully supported sales teams in the past. Be ready to share specific examples that highlight your ability to manage security assessments and audits.
β¨Tip Number 4
Showcase your communication skills by practising how to explain complex cybersecurity concepts in simple terms. This is crucial for collaborating with cross-functional teams and ensuring compliance obligations are met.
We think you need these skills to ace Information Security Risk & Compliance Specialist
Some tips for your application π«‘
Understand the Role: Before applying, make sure you fully understand the responsibilities and qualifications required for the Information Security Risk & Compliance Specialist position. Tailor your application to highlight relevant experience in Governance, Risk, and Compliance.
Highlight Relevant Experience: In your CV and cover letter, emphasise your 3+ years of experience in GRC or Information Security. Provide specific examples of how you've supported sales processes, responded to RFx security assessments, or contributed to compliance initiatives like DORA or NIS2.
Showcase Communication Skills: Since excellent written and verbal communication skills are crucial for this role, ensure your application reflects your ability to convey complex technical concepts clearly. Use concise language and avoid jargon where possible.
Tailor Your Documents: Customise your CV and cover letter for CyberArk by incorporating keywords from the job description. Mention your familiarity with regulatory frameworks and any professional certifications you hold, such as CISM or ISO 27001, to stand out.
How to prepare for a job interview at Cyberark Software
β¨Understand the Regulatory Landscape
Familiarise yourself with key regulations such as DORA, NIS2, GDPR, and ISO 27001. Be prepared to discuss how these frameworks impact the role and how you can contribute to compliance initiatives.
β¨Showcase Your Communication Skills
Since the role requires translating technical concepts for non-technical audiences, practice explaining complex security topics in simple terms. This will demonstrate your ability to communicate effectively with cross-functional teams.
β¨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills in real-world scenarios. Think of examples from your past experience where you successfully managed compliance challenges or responded to security assessments.
β¨Highlight Your Organisational Skills
The role involves managing multiple priorities in a dynamic environment. Be ready to share specific examples of how you've effectively organised tasks or projects in previous roles, showcasing your attention to detail and proactive approach.