Information Security Risk & Compliance Specialist
Information Security Risk & Compliance Specialist

Information Security Risk & Compliance Specialist

London Full-Time 36000 - 60000 Β£ / year (est.) No home office possible
C

At a Glance

  • Tasks: Join our team to support compliance initiatives and customer security assessments.
  • Company: CyberArk is a leader in Identity Security, trusted by top organisations worldwide.
  • Benefits: Enjoy a hybrid work model with flexible office attendance and a diverse workplace culture.
  • Why this job: Be part of a fast-paced environment that values cybersecurity and regulatory compliance.
  • Qualifications: 3+ years in Governance, Risk, and Compliance; strong communication and organisational skills required.
  • Other info: We celebrate diversity and are committed to creating an inclusive workplace for all.

The predicted salary is between 36000 - 60000 Β£ per year.

About CyberArk: CyberArk (NASDAQ: CYBR) is the global leader in Identity Security. Centered on privileged access management, CyberArk provides the most comprehensive security offering for any identity – human or machine – across business applications, distributed workforces, hybrid cloud workloads and throughout the DevOps lifecycle. The world’s leading organizations trust CyberArk to help secure their most critical assets.

About the Role: We are seeking a highly motivated and detail-oriented GRC Compliance Expert to join our Governance, Risk, and Compliance team. This role is pivotal in supporting customer security assessments during RFx processes, driving compliance initiatives including DORA, NIS2, and other regulatory frameworks, and assisting with broader GRC activities across the organization. The ideal candidate is a self-starter with strong communication skills, who thrives in a fast-paced environment and is passionate about cybersecurity, regulatory compliance, and risk management. Please note that this is a hybrid role located in our office in London. We ask to come to the office twice per week.

  • Support the sales and legal teams during RFx processes by responding to customer security questionnaires, assessments, and due diligence requests.
  • Coordinate and manage responses to customer security audits and assurance inquiries.
  • Monitor regulatory changes and contribute to compliance initiatives such as DORA, NIS2, and other applicable standards and frameworks (e.g., ISO 27001, SOC 2, GDPR).
  • Assist in the development, maintenance, and improvement of internal GRC processes, policies, and documentation.
  • Collaborate with cross-functional teams (Security, Legal, IT, Product, etc.) to gather information and ensure compliance obligations are met.
  • Participate in risk assessments, control testing, and continuous monitoring activities to support the overall risk and compliance program.
  • Support customer contract negotiations by providing expert input on security and compliance clauses.
  • Help prepare evidence and documentation for internal and external audits.
  • Track and report on compliance project status and risks to leadership.

Qualifications:

  • 3+ years of experience in Governance, Risk, and Compliance, Information Security, or a related field.
  • Experience supporting sales processes, including responding to RFx security assessments.
  • Solid understanding of cybersecurity principles, information security best practices, and regulatory requirements (DORA, NIS2, GDPR, ISO 27001, SOC 2, etc.).
  • Excellent written and verbal communication skills; able to translate technical concepts for non-technical audiences.
  • Strong organizational skills with the ability to manage multiple priorities in a dynamic environment.
  • Self-motivated with a proactive approach to problem-solving and attention to detail.
  • Experience working in a SaaS, cloud, or technology-driven company is preferred.
  • Professional certifications (such as CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or similar) are a plus.

Additional Information: We are proud to foster a diverse and inclusive workplace, where every individual's unique background, perspective, and contribution is celebrated. We believe that by embracing diversity, we drive innovation and create a stronger, more united team. Inclusion is at the heart of who we are and how we succeed. All qualified applicants will receive consideration for employment without regard to race, colour, age, religion, sex, sexual orientation, gender identity, or disability. Upon conditional offer of employment, candidates are required to complete a comprehensive background check as per our internal policy. CyberArk is an equal opportunities employer. If you would like any special arrangements made for your interview, please inform the EMEA Talent Acquisition team upon your application so that we may take steps to accommodate your needs.

Information Security Risk & Compliance Specialist employer: Cyberark Software

CyberArk is an exceptional employer that prioritises employee growth and development within a dynamic and inclusive work culture. Located in the vibrant city of London, our hybrid work model allows for flexibility while fostering collaboration among teams. With a strong commitment to diversity and innovation, CyberArk offers unique opportunities to engage in meaningful work that directly impacts the security landscape, making it an ideal place for passionate professionals in the cybersecurity field.
C

Contact Detail:

Cyberark Software Recruiting Team

StudySmarter Expert Advice 🀫

We think this is how you could land Information Security Risk & Compliance Specialist

✨Tip Number 1

Familiarise yourself with the specific regulatory frameworks mentioned in the job description, such as DORA and NIS2. Understanding these regulations will not only help you during interviews but also demonstrate your commitment to compliance and risk management.

✨Tip Number 2

Network with professionals in the Governance, Risk, and Compliance (GRC) field, especially those who have experience in cybersecurity. Engaging with industry experts can provide insights into the role and may even lead to referrals.

✨Tip Number 3

Prepare to discuss your experience with RFx processes and how you've successfully supported sales teams in the past. Be ready to share specific examples that highlight your ability to manage security assessments and audits.

✨Tip Number 4

Showcase your communication skills by practising how to explain complex cybersecurity concepts in simple terms. This is crucial for collaborating with cross-functional teams and ensuring compliance obligations are met.

We think you need these skills to ace Information Security Risk & Compliance Specialist

Governance, Risk, and Compliance (GRC)
Information Security
Cybersecurity Principles
Regulatory Compliance (DORA, NIS2, GDPR, ISO 27001, SOC 2)
Risk Assessment
Control Testing
Attention to Detail
Excellent Written and Verbal Communication Skills
Organisational Skills
Proactive Problem-Solving
Experience with RFx Processes
Collaboration with Cross-Functional Teams
Documentation and Policy Development
Experience in SaaS or Cloud Environments
Professional Certifications (CISM, CRISC, ISO 27001 Lead Implementer/Auditor)

Some tips for your application 🫑

Understand the Role: Before applying, make sure you fully understand the responsibilities and qualifications required for the Information Security Risk & Compliance Specialist position. Tailor your application to highlight relevant experience in Governance, Risk, and Compliance.

Highlight Relevant Experience: In your CV and cover letter, emphasise your 3+ years of experience in GRC or Information Security. Provide specific examples of how you've supported sales processes, responded to RFx security assessments, or contributed to compliance initiatives like DORA or NIS2.

Showcase Communication Skills: Since excellent written and verbal communication skills are crucial for this role, ensure your application reflects your ability to convey complex technical concepts clearly. Use concise language and avoid jargon where possible.

Tailor Your Documents: Customise your CV and cover letter for CyberArk by incorporating keywords from the job description. Mention your familiarity with regulatory frameworks and any professional certifications you hold, such as CISM or ISO 27001, to stand out.

How to prepare for a job interview at Cyberark Software

✨Understand the Regulatory Landscape

Familiarise yourself with key regulations such as DORA, NIS2, GDPR, and ISO 27001. Be prepared to discuss how these frameworks impact the role and how you can contribute to compliance initiatives.

✨Showcase Your Communication Skills

Since the role requires translating technical concepts for non-technical audiences, practice explaining complex security topics in simple terms. This will demonstrate your ability to communicate effectively with cross-functional teams.

✨Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving skills in real-world scenarios. Think of examples from your past experience where you successfully managed compliance challenges or responded to security assessments.

✨Highlight Your Organisational Skills

The role involves managing multiple priorities in a dynamic environment. Be ready to share specific examples of how you've effectively organised tasks or projects in previous roles, showcasing your attention to detail and proactive approach.

Information Security Risk & Compliance Specialist
Cyberark Software
Location: London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

C
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>