GRC Risk & Security Analyst in Belfast

GRC Risk & Security Analyst in Belfast

Belfast Full-Time 36000 - 60000 € / year (est.) No home office possible
DailyPay

At a Glance

  • Tasks: Assess and mitigate risks in information security while ensuring compliance with regulations.
  • Company: Join DailyPay, a leading worktech company transforming employee payment solutions.
  • Benefits: Competitive pay, equity opportunities, private health insurance, and generous PTO.
  • Other info: Enjoy fun company events and excellent career growth opportunities.
  • Why this job: Make a real impact on data security and compliance in a dynamic environment.
  • Qualifications: 3+ years in GRC or information security, with strong communication skills.

The predicted salary is between 36000 - 60000 € per year.

About Us

DailyPay is transforming the way people get paid. As a worktech company and the industry's leading on demand pay solution, DailyPay uses an award-winning technology platform to help America's top employers build stronger relationships with their employees. This voluntary employee benefit enables workers everywhere to feel more motivated to work harder and stay longer on the job while supporting their financial well-being outside of the workplace. DailyPay is headquartered in New York City, with operations throughout the United States as well as in Belfast.

The Role

The GRC Security Analyst is responsible for assessing, analyzing, and mitigating risks associated with the organization's information security posture. This role will play a crucial part in ensuring compliance with regulatory requirements and protecting sensitive data — both internally and across the third-party ecosystem. This includes evaluating the security posture of vendors and partners that DailyPay relies on, as well as supporting customers and partners when they assess DailyPay as part of their own vendor due diligence processes.

The GRC Security Analyst will also be responsible for assessing, analyzing, and mitigating risks associated with access to information systems, as well as the third-party vendors and partners who interact with those systems. This role will play a crucial part in ensuring the organization's compliance with regulatory requirements, managing third-party risk exposure, and protecting sensitive data across the full scope of DailyPay's internal and external relationships.

If this opportunity excites you, we encourage you to apply even if you do not meet all of the qualifications.

How You Will Make an Impact

  • Risk Assessment
    • Analyze access privileges, segregation of duties, and other control mechanisms to identify potential risks
    • Conduct regular risk assessments to identify and evaluate potential threats and vulnerabilities
    • Analyze security controls, policies, and procedures to identify gaps and weaknesses
    • Develop risk matrices and prioritise risks based on likelihood and impact
    • Perform third-party vendor risk assessments to evaluate the security posture of new and existing vendors, ensuring they meet DailyPay's security and compliance standards
  • Third-Party Risk Management
    • Lead and support DailyPay's third-party risk assessment program, including initial onboarding assessments, periodic reviews, and offboarding of vendors
    • Evaluate vendor security questionnaires, SOC 2 reports, penetration test results, and other security documentation to assess risk exposure
    • Maintain the vendor risk register and track remediation of identified gaps or deficiencies
    • Serve as a point of contact for customers and partners conducting security assessments of DailyPay, responding to security questionnaires, RFPs, and due diligence requests in a timely and accurate manner
    • Collaborate cross-functionally with Legal, Procurement, and Engineering to ensure third-party contracts include appropriate security requirements and data protection clauses
  • Compliance Management
    • Ensure compliance with relevant regulatory and industry frameworks (e.g. SOC2, ISO 27001, PCI DSS, SOX 404, GDPR, CCPA)
    • Develop and maintain compliance documentation and evidence
  • Policy Development and Enforcement
    • Assist in the development, implementation, and maintenance of information security policies including building relevant procedures to meet policy objectives
    • Ensure adherence to established policies and procedures by conducting regular audits and reviews
    • Identify and address non-compliance issues
  • Access Review and Certification
    • Oversee periodic access reviews to ensure that individuals have appropriate access privileges based on their roles and responsibilities
    • Certify access reviews and recommend changes as needed
  • Security Controls
    • Assist in the development, implementation, and maintenance of security controls
    • Review and evaluate the effectiveness of existing controls
    • Identify and address control deficiencies
  • Identify and Access Management (IAM)
    • Collaborate with the IAM team to ensure effective management of user identities and access privileges
    • Assist in the implementation and maintenance of IAM systems and processes
  • Incident Response
    • Contribute to incident response plans and procedures related to information security incidents
    • Assist in the investigation and remediation of security incidents

What You Bring to The Team

  • 3+ years of experience in a GRC or information security role
  • Experience with GRC and Third Party Risk Management tools
  • Experience in a regulated public company is preferred
  • Bachelor's degree in Information Security, Computer Science, or a related field (or equivalent experience)
  • Certification in CISA or CISSP
  • Strong understanding of access governance principles, frameworks, and best practices
  • Knowledge of risk management frameworks (e.g., NIST RMF, FAIR)
  • Strong interpersonal and communication skills, with the ability to collaborate effectively across internal teams, engage with external vendors during risk assessments, and professionally represent DailyPay when responding to customer security inquiries and due diligence requests

What We Offer

  • Competitive compensation
  • Opportunity for equity ownership
  • Private health insurance option
  • Employee Resource Groups
  • Fun company outings and events
  • Generous PTO Allowance
  • 5% Pension contribution

GRC Risk & Security Analyst in Belfast employer: DailyPay

DailyPay is an exceptional employer that prioritises employee well-being and professional growth, offering a dynamic work culture in the heart of New York City. With competitive compensation, opportunities for equity ownership, and a strong focus on compliance and security, employees can thrive in their roles while enjoying generous benefits like private health insurance and a robust pension contribution. Join us to be part of a transformative company that values your contributions and fosters a supportive environment for career advancement.

DailyPay

Contact Detail:

DailyPay Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land GRC Risk & Security Analyst in Belfast

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend events, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching DailyPay and understanding their mission. Tailor your responses to show how your skills align with their goals, especially in risk management and compliance.

Tip Number 3

Practice makes perfect! Conduct mock interviews with friends or use online platforms to get comfortable answering common questions. This will help you articulate your experience in GRC and security confidently.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you’re genuinely interested in being part of the DailyPay team.

We think you need these skills to ace GRC Risk & Security Analyst in Belfast

Risk Assessment
Third-Party Risk Management
Compliance Management
Information Security Policies
Access Governance
GRC Tools
Incident Response

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the GRC Risk & Security Analyst role. Highlight relevant experience and skills that match the job description, especially in risk assessment and compliance management.

Craft a Compelling Cover Letter:Your cover letter should tell us why you're excited about this role at DailyPay. Share specific examples of how your background aligns with our mission and the responsibilities outlined in the job description.

Showcase Your Skills:Don’t just list your qualifications; demonstrate them! Use concrete examples to show how you've successfully managed risks or improved security postures in previous roles.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role without any hiccups!

How to prepare for a job interview at DailyPay

Know Your Stuff

Make sure you brush up on your knowledge of GRC frameworks and risk management principles. Familiarise yourself with the specific regulations mentioned in the job description, like SOC2 and GDPR. This will show that you're not just interested in the role but also understand the landscape.

Prepare for Scenario Questions

Expect to be asked about how you would handle specific risk assessment scenarios or vendor evaluations. Think through some examples from your past experience where you successfully identified and mitigated risks. This will help you demonstrate your practical skills and problem-solving abilities.

Show Your Communication Skills

As a GRC Risk & Security Analyst, you'll need to communicate effectively with various teams and external partners. Practice explaining complex security concepts in simple terms. This will help you convey your ideas clearly during the interview and show that you can bridge the gap between technical and non-technical stakeholders.

Ask Insightful Questions

Prepare some thoughtful questions about DailyPay's current security posture, their approach to third-party risk management, or how they handle compliance challenges. This not only shows your interest in the company but also gives you a chance to assess if it's the right fit for you.