Staff GRC Analyst

Staff GRC Analyst

Full-Time No working from home possible
J
  • Automate legacy systems related to governance, risk, and compliance frameworks, including ISO 27001, PCI-DSS, DORA, UK Cyber Essentials, and relevant financial services regulations
  • Engineer GRC workflows integrating ticketing, asset management, identity, and cloud platforms to support compliance by design
  • Design and build scalable GRC architectures and automation for evidence collection, control testing, and compliance reporting
  • Draft, review, and maintain Pleo security policies and map them to relevant control standards
  • Automate incoming security requests from customers and prospects, including questionnaires, one-off questions, review calls, and documentation
  • Automate third-party vendor assessments and track resolution of identified gaps
  • Automate compliance metrics and KPI reporting for leadership
  • Translate compliance requirements into technical specifications for engineering teams and explain them to non-technical stakeholders
  • Coordinate complex, multi-team workstreams and keep dependencies, priorities, and delivery on track
  • Contribute to broader Cybersecurity team initiatives and shared security goals
  • Report to the VP of Fraud & Security and collaborate with Risk and Compliance, Procurement, Legal, Finance, Engineering, and other teams
  • During the first six months, learn Pleo's security landscape, build evidence-collection and control-testing automation, develop policy as code, and integrate with Cybersecurity workflows and tooling

Requirements

  • Significant experience in Security GRC
  • Understanding of auditing processes
  • Direct experience in both internal and external audit cycles
  • Demonstrated experience using AI and/or coding automation to build, implement, and operate controls
  • Strong understanding of cloud architectures, such as AWS or equivalent
  • Experience mapping infrastructure decisions to security controls and audit evidence
  • Experience automating reporting for GRC programs, including dashboards and executive-level summaries
  • Fintech, payments industry, or IT audit background
  • Familiarity with regulatory expectations and payment platform architectures
  • Certifications such as CISM, CISSP, CISA, or PCI-related credentials
  • A degree in Cybersecurity, Engineering, Computer Science, or Mathematics, or equivalent experience, is a plus
  • Ability to work closely with colleagues without engineering backgrounds
  • Ability to work independently and take initiative
  • Valid right to work in the selected country; Pleo cannot offer visa sponsorship
  • Application must be submitted in English

Core Competencies

Demonstrates expertise in Security Governance, Risk, and Compliance (GRC) with a strong focus on automating compliance processes and integrating security frameworks. Proficient in translating compliance requirements into technical specifications while collaborating across teams to ensure effective implementation.

Highest-signal resume keywords

  • Security GRC Experience
  • Cloud Architecture Understanding
  • AI and Automation ImplementationRegulatory Compliance Familiarity
  • CISM, CISSP, or CISA Certification

Hard Skills

  • Governance, Risk, and Compliance Automation
  • Control Testing Automation
  • Evidence Collection Automation
  • Reporting Automation for GRC Programs
  • Mapping Infrastructure to Security Controls
  • Auditing Processes
  • Technical Specification Translation
  • Dashboards and KPI Reporting
  • Policy as Code Development
  • Third-Party Vendor Assessment Automation

Soft Skills

  • Initiative
  • Collaboration
  • Communication with Non-Technical Stakeholders
  • Independent Work

Certifications & Qualifications

  • CISM
  • CISSP
  • CISA
  • PCI-Related Credentials

Industry Keywords

  • Fintech
  • Payments Industry
  • Cybersecurity
  • Compliance Frameworks
  • ISO 27001
  • PCI-DSS
  • DORA
  • UK Cyber Essentials
  • Financial Services Regulations

Tools & Technologies

  • AWS
  • Cloud Platforms
  • Ticketing Systems
  • Asset Management Systems

#J-18808-Ljbffr

Staff GRC Analyst employer: Jobtailor

As a Client Services Coordinator at our dynamic company, you will thrive in a supportive work culture that prioritises employee growth and development. We offer comprehensive training, opportunities for advancement, and a collaborative environment where your contributions are valued. Located in a vibrant area, our team enjoys a healthy work-life balance and the chance to engage with diverse clients, making every day rewarding and meaningful.

J

Contact Details:

Jobtailor Recruitment Team