- Automate legacy systems related to governance, risk, and compliance frameworks, including ISO 27001, PCI-DSS, DORA, UK Cyber Essentials, and relevant financial services regulations
- Engineer GRC workflows integrating ticketing, asset management, identity, and cloud platforms to support compliance by design
- Design and build scalable GRC architectures and automation for evidence collection, control testing, and compliance reporting
- Draft, review, and maintain Pleo security policies and map them to relevant control standards
- Automate incoming security requests from customers and prospects, including questionnaires, one-off questions, review calls, and documentation
- Automate third-party vendor assessments and track resolution of identified gaps
- Automate compliance metrics and KPI reporting for leadership
- Translate compliance requirements into technical specifications for engineering teams and explain them to non-technical stakeholders
- Coordinate complex, multi-team workstreams and keep dependencies, priorities, and delivery on track
- Contribute to broader Cybersecurity team initiatives and shared security goals
- Report to the VP of Fraud & Security and collaborate with Risk and Compliance, Procurement, Legal, Finance, Engineering, and other teams
- During the first six months, learn Pleo's security landscape, build evidence-collection and control-testing automation, develop policy as code, and integrate with Cybersecurity workflows and tooling
Requirements
- Significant experience in Security GRC
- Understanding of auditing processes
- Direct experience in both internal and external audit cycles
- Demonstrated experience using AI and/or coding automation to build, implement, and operate controls
- Strong understanding of cloud architectures, such as AWS or equivalent
- Experience mapping infrastructure decisions to security controls and audit evidence
- Experience automating reporting for GRC programs, including dashboards and executive-level summaries
- Fintech, payments industry, or IT audit background
- Familiarity with regulatory expectations and payment platform architectures
- Certifications such as CISM, CISSP, CISA, or PCI-related credentials
- A degree in Cybersecurity, Engineering, Computer Science, or Mathematics, or equivalent experience, is a plus
- Ability to work closely with colleagues without engineering backgrounds
- Ability to work independently and take initiative
- Valid right to work in the selected country; Pleo cannot offer visa sponsorship
- Application must be submitted in English
Core Competencies
Demonstrates expertise in Security Governance, Risk, and Compliance (GRC) with a strong focus on automating compliance processes and integrating security frameworks. Proficient in translating compliance requirements into technical specifications while collaborating across teams to ensure effective implementation.
Highest-signal resume keywords
- Security GRC Experience
- Cloud Architecture Understanding
- AI and Automation ImplementationRegulatory Compliance Familiarity
- CISM, CISSP, or CISA Certification
Hard Skills
- Governance, Risk, and Compliance Automation
- Control Testing Automation
- Evidence Collection Automation
- Reporting Automation for GRC Programs
- Mapping Infrastructure to Security Controls
- Auditing Processes
- Technical Specification Translation
- Dashboards and KPI Reporting
- Policy as Code Development
- Third-Party Vendor Assessment Automation
Soft Skills
- Initiative
- Collaboration
- Communication with Non-Technical Stakeholders
- Independent Work
Certifications & Qualifications
- CISM
- CISSP
- CISA
- PCI-Related Credentials
Industry Keywords
- Fintech
- Payments Industry
- Cybersecurity
- Compliance Frameworks
- ISO 27001
- PCI-DSS
- DORA
- UK Cyber Essentials
- Financial Services Regulations
Tools & Technologies
- AWS
- Cloud Platforms
- Ticketing Systems
- Asset Management Systems
#J-18808-Ljbffr
Staff GRC Analyst employer: Jobtailor
As a Client Services Coordinator at our dynamic company, you will thrive in a supportive work culture that prioritises employee growth and development. We offer comprehensive training, opportunities for advancement, and a collaborative environment where your contributions are valued. Located in a vibrant area, our team enjoys a healthy work-life balance and the chance to engage with diverse clients, making every day rewarding and meaningful.