Information Security Governance, Risk and Compliance Analyst
Information Security Governance, Risk and Compliance Analyst

Information Security Governance, Risk and Compliance Analyst

Full-Time 50000 - 60000 £ / year (est.) No home office possible
Trustpilot, Inc.

At a Glance

  • Tasks: Join our team to enhance security and compliance in exciting AI initiatives.
  • Company: Trustpilot, a leading FTSE-250 company focused on building trust.
  • Benefits: Flexible working, competitive pay, 25+ days holiday, and wellness support.
  • Why this job: Make a real impact on security while navigating the future of AI technology.
  • Qualifications: Experience with compliance frameworks and a passion for risk management.
  • Other info: Inclusive culture with great career growth and learning opportunities.

The predicted salary is between 50000 - 60000 £ per year.

At Trustpilot, we are on an incredible journey. We are a profitable, high-growth FTSE-250 company with a big vision: to become the universal symbol of trust. We run the world’s largest independent consumer review platform, and while we have come a long way, there is still so much exciting work to do. Come join us at the heart of trust!

Ready to help us navigate a major shift in technology that brings both exciting opportunities and new security risks? Our Information Security team’s mission is to securely enable Trustpilot to be the universal symbol of trust. As our new Governance, Risk and Compliance Analyst, you will get hands-on with some of our most exciting initiatives yet. You will help mature our core compliance frameworks and play a key role in shaping our approach to AI security and governance. From risk-assessing new AI systems to helping us use AI to automate manual GRC workflows, your work will directly strengthen our security posture.

We are an open, inclusive and collaborative team of security enthusiasts who work closely with engineers and data scientists to solve complex problems. If you are a pragmatic technologist who loves balancing risk with fast-paced innovation, we want you to bring your unique perspective and ideas to our team. You will partner with our security, risk and engineering teams to mature our core compliance programs and safely adopt exciting new AI technologies, directly strengthening the trust millions of people place in our platform.

  • Drive our ongoing compliance efforts for major industry standards, including SOC 2, ISO27001, ISO42001 and PCI DSS, ensuring we consistently meet commitments to our customers.
  • Evaluate and manage the security risks associated with our new artificial intelligence and machine learning systems, allowing our product teams to innovate safely and securely.
  • Streamline how we assess the security of our vendors and third-party tools, paying special attention to how we safely integrate external AI technologies into our business.
  • Help develop our internal standards for artificial intelligence, keeping us ahead of the curve on new global regulations like the EU AI Act.
  • Identify opportunities to replace manual, repetitive risk management tasks with smart, AI-driven automation.
  • Refresh our security policies and public-facing documents to clearly communicate our security posture to our customers, partners and auditors.
  • Act as an advocate for security awareness across the business, helping colleagues understand how balancing risk and innovation leads to better, safer products.

Who you are:

  • You have solid experience managing and auditing against core compliance frameworks, such as SOC 2, ISO27001 and PCI DSS.
  • You are well-versed in risk management processes, including risk identification, third-party risk management and vendor security due diligence.
  • You have practical experience developing, implementing and managing security policies and procedures.
  • You are a pragmatist who knows how to balance security risks with the pace of innovation, bringing a solid understanding of cloud environment risks.
  • Bonus points if you are familiar with emerging AI governance frameworks (like the EU AI Act, NIST AI RMF, and ISO/IEC 42001) or have a strong desire to learn them on the job.
  • Bonus points if you have experience with, or a keen interest in, using AI to automate manual tasks and drive efficiencies in GRC workflows.

What’s in it for you:

  • A range of flexible working options to dedicate time to what matters to you.
  • Competitive compensation package + bonus.
  • 25 days holiday per year, increasing to 28 days after 2 years of employment.
  • Two (paid) volunteering days a year to spend your time giving back to the causes that matter to you and your community.
  • Rich learning and development opportunities are supported through the Trustpilot Academy and Blinkist.
  • Pension and life insurance.
  • Health cash plan, online GP, 24/7, Employee Assistance Plan.
  • Full access to Headspace, a popular mindfulness app to promote positive mental health.
  • Paid parental leave.
  • Season ticket loan and a cycle-to-work scheme.
  • Central office location complete with table tennis, a gaming corner, coffee bars and all the snacks and refreshments you can ask for.
  • Regular opportunities to connect and get to know your fellow Trusties, including company-wide celebrations and events, ERG activities, and team socials.
  • Access to over 4,000 deals and discounts on things like travel, electronics, fashion, fitness, cinema discounts, and more.
  • Independent financial advice and free standard professional mortgage broker advice.
  • Talent acceleration programs: Fast-track your career with our tailored development programs designed to support growth at whatever stage of your career.

Trustpilot is committed to creating an inclusive environment where people from all backgrounds can thrive and where different viewpoints and experiences are valued and respected. Trustpilot will consider all applications for employment without regard to race, ethnicity, national origin, religious beliefs, gender identity or expression, sexual orientation, neurodiversity, disability, age, parental or veteran status. Together, we are the heart of trust.

Information Security Governance, Risk and Compliance Analyst employer: Trustpilot, Inc.

At Trustpilot, we pride ourselves on being an exceptional employer, offering a vibrant and inclusive work culture that fosters collaboration and innovation. With a strong focus on employee growth, our comprehensive benefits package includes flexible working options, generous holiday allowances, and rich learning opportunities through the Trustpilot Academy. Join us in our central office, where you can enjoy a range of amenities and connect with fellow team members while contributing to our mission of becoming the universal symbol of trust.
Trustpilot, Inc.

Contact Detail:

Trustpilot, Inc. Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Governance, Risk and Compliance Analyst

✨Tip Number 1

Network like a pro! Reach out to current employees at Trustpilot on LinkedIn or other platforms. Ask them about their experiences and any tips they might have for landing the role. Personal connections can give you an edge!

✨Tip Number 2

Prepare for the interview by diving deep into Trustpilot's mission and values. Understand how your skills in governance, risk, and compliance align with their goals. Show them you're not just a fit for the role, but for the company culture too!

✨Tip Number 3

Practice common interview questions related to information security and compliance. Think about real-life scenarios where you've managed risks or improved processes. We want to hear your stories that showcase your expertise!

✨Tip Number 4

Don’t forget to follow up after your interview! A simple thank-you email expressing your appreciation for the opportunity can leave a lasting impression. Plus, it shows your enthusiasm for the role!

We think you need these skills to ace Information Security Governance, Risk and Compliance Analyst

Governance, Risk and Compliance (GRC)
SOC 2
ISO 27001
PCI DSS
Risk Management
Third-Party Risk Management
Vendor Security Due Diligence
Security Policy Development
Cloud Environment Risk Assessment
AI Governance Frameworks
NIST AI RMF
ISO/IEC 42001
AI-Driven Automation
Communication Skills
Collaboration

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with compliance frameworks like SOC 2 and ISO27001. We want to see how your skills align with our mission at Trustpilot!

Showcase Your Pragmatism: In your application, emphasise your ability to balance security risks with innovation. We’re looking for someone who can navigate the fast-paced tech landscape while keeping security front and centre.

Highlight AI Experience: If you’ve got experience or a keen interest in AI governance frameworks, make it known! We’re excited about integrating AI into our processes, so any relevant experience will definitely catch our eye.

Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way for us to receive your details and get the ball rolling on your journey with Trustpilot.

How to prepare for a job interview at Trustpilot, Inc.

✨Know Your Compliance Frameworks

Make sure you brush up on your knowledge of SOC 2, ISO27001, and PCI DSS. Be ready to discuss how you've managed and audited against these frameworks in the past, as this will show your practical experience and understanding of compliance.

✨Showcase Your Risk Management Skills

Prepare examples of how you've identified and managed security risks, especially in relation to third-party vendors and AI systems. This will demonstrate your ability to balance risk with innovation, which is crucial for the role.

✨Familiarise Yourself with AI Governance

Since the role involves working with AI technologies, it’s a good idea to get acquainted with emerging AI governance frameworks like the EU AI Act. Even if you're not an expert, showing a willingness to learn can set you apart.

✨Communicate Clearly About Security Policies

Be prepared to discuss how you've developed and implemented security policies in previous roles. Think about how you can articulate your approach to refreshing security documents and communicating security posture to various stakeholders.

Information Security Governance, Risk and Compliance Analyst
Trustpilot, Inc.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>