At a Glance
- Tasks: Own and improve our GRC program while collaborating with technical teams.
- Company: Join a hypergrowth AI unicorn with a dynamic culture.
- Benefits: Remote work, competitive salary, and opportunities for professional growth.
- Other info: Full-time remote role available from the UK or EU.
- Why this job: Make a real impact in compliance and risk management while learning and growing.
- Qualifications: Hands-on technical background and experience in audit cycles.
The predicted salary is between 50000 - 65000 ÂŁ per year.
We are looking for a GRC Analyst to help us run and evolve our governance, risk, and compliance program in a way that is credible with technical teams and useful for the business. We are not looking for a traditional “paper compliance” role. The ideal candidate has a strong technical foundation – whether from engineering, IT management, DevOps, SRE, or a similar hands‑on background – and can bridge the gap between how systems are actually built and operated (GitHub, CI/CD, Kubernetes, cloud, observability) and what we need to demonstrate for audits, customers, and leadership.
You will work closely with Engineering, DevOps/Platform, Security, Legal, and customer‑facing teams to keep us audit‑ready, reduce risk in practical ways, and support the next wave of compliance efforts (for example ISO 22301, and longer‑term options like HITRUST and FedRAMP). You don’t need to be a compliance expert, but if you have a solid background in security, are eager to learn, and are ready to be bold and take ownership, this role offers a great opportunity to grow quickly and actually have a real impact in a hypergrowth AI unicorn.
What you’ll be doing:
- GRC Program Ownership: Own and continuously improve our GRC program across ISO 27001, SOC 2, ISO 27701, and ISO 42001, including control mapping and evidence expectations. Partner with control owners to make compliance repeatable and low‑friction – evidence as a habit, not a scramble. Drive audit readiness: artifacts, timelines, action tracking, and clear control demonstration. Improve policies, standards, and procedures so they reflect how we actually operate.
- Technical‑to‑Compliance Translation: Build strong working relationships with DevOps/Platform and engineering teams. Evaluate technical implementations – branch protection, CI/CD, Kubernetes, cloud architecture, monitoring – well enough to ask good questions and validate evidence. Translate technical reality into clear audit narratives without losing accuracy.
- Risk Management: Contribute to risk identification and assessment across technical, operational, and vendor domains. Maintain risk registers and track mitigations to closure. Support leadership reporting by surfacing themes and trends that lead to real decisions.
- Growth into Future Certifications: Evaluate and prepare for ISO 22301, and potentially HITRUST and FedRAMP as business needs evolve. Identify gaps early and propose pragmatic roadmaps that engineering teams can execute.
We’d love to hear from you if you:
- Have a hands‑on technical background (engineering, DevOps/SRE, IT management, or similar) and understand how cloud environments work, especially AWS.
- Can follow technical conversations well beyond what a traditional auditor can – you understand how the sausage is made.
- Have experience supporting audit cycles and know what good evidence looks like.
- Are organised, proactive, and can drive multiple workstreams independently – with clear, thoughtful communication across both technical and business audiences.
- Have technical aptitude: comfortable writing a simple script when needed, and experienced using AI and LLM tools in your work.
Bonus points if you:
- Have direct experience with ISO 27001, SOC 2, ISO 42001, or ISO 27701, or have worked in ISO 22301, HITRUST, or FedRAMP environments.
- Have used GRC tooling such as Vanta, Drata, or OneTrust.
- Have built lightweight automation to reduce compliance toil.
- Have worked in a fast‑growing SaaS company and supported an external audit.
Other important info: This is a remote role from the UK OR an EU country. This is full‑time employment only – no contractors possible.
GRC Analyst employer: Synthesia
Contact Detail:
Synthesia Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land GRC Analyst
✨Tip Number 1
Network like a pro! Reach out to folks in the industry on LinkedIn or at meetups. A friendly chat can lead to opportunities that aren’t even advertised yet.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repo showcasing your projects and technical know-how. This gives potential employers a taste of what you can do beyond just a CV.
✨Tip Number 3
Prepare for interviews by practising common GRC scenarios. Think about how you’d handle real-world compliance challenges and be ready to discuss your thought process.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are keen to join us directly!
We think you need these skills to ace GRC Analyst
Some tips for your application 🫡
Show Your Technical Side: Make sure to highlight your hands-on technical experience in your application. We want to see how you understand cloud environments and can bridge the gap between tech and compliance.
Be Clear and Concise: When writing your application, keep it straightforward. Use clear language to explain your experiences and how they relate to the GRC role. We appreciate thoughtful communication!
Demonstrate Your Proactivity: Share examples of how you've taken ownership in past roles. We love candidates who are organised and can drive multiple workstreams independently, so let us know how you've done this before.
Apply Through Our Website: Don't forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity with StudySmarter.
How to prepare for a job interview at Synthesia
✨Know Your Tech Inside Out
Make sure you brush up on your technical knowledge, especially around cloud environments like AWS, CI/CD, and Kubernetes. Being able to discuss these topics confidently will show that you can bridge the gap between technical teams and compliance needs.
✨Understand the GRC Landscape
Familiarise yourself with the specific compliance frameworks mentioned in the job description, such as ISO 27001 and SOC 2. Even if you're not a compliance expert, having a solid understanding of what these entail will help you speak more credibly during the interview.
✨Prepare Real-World Examples
Think of instances where you've successfully navigated compliance challenges or improved processes in a previous role. Be ready to share these stories, as they demonstrate your hands-on experience and problem-solving skills.
✨Show Your Proactive Side
Highlight your ability to drive multiple workstreams independently. Discuss how you've taken ownership of projects in the past and how you plan to do the same in this role. This will resonate well with the company's desire for someone who is organised and proactive.