Senior GRC Analyst
Romania
⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️
Payscale
Navigate market uncertainty with validated, always-on compensation data from multiple sources delivered transparently through our trusted data platform.- Lead security assessments and contribute to continuous improvement of the security program.
- Support internal and external audits and ensure remediation of findings related to cybersecurity.
- Advise on security requirements during design of systems and businesses processes.
- Collaborate with internal teams to conduct cybersecurity risk assessments.
- Support maintenance of risk register and POA&M tracking.
- Collaborate with stakeholders to evaluate and address identified risks.
- Update identification & classification schemes for data, system, and business workflows.
- Monitor compliance policies and standards (e.g., phishing tests, training completion)
- Support security-related customer queries and communications (supporting Sales and GTM).
- Conduct reviews and provide guidance on security clauses in contracts.
- Monitor regulatory and compliance requirements (e.g., GDPR, PCI-DSS) to ensure alignment.
- Support KPI and metrics gathering and reporting on an ongoing basis.
- 5+ years of experience in cybersecurity, with at least 3 years focused on GRC in a SaaS company.
- Industry certifications such as CISSP, CRISC, CISM, or CISA strongly preferred.
- Experience in risk management frameworks such as NIST RMF or ISO27005.
- Experience implementing cybersecurity frameworks (e.g., NIST CSF, ISO27001).
- Experience in compliance tracking and monitoring of regulatory frameworks such as GDPR.
- Experience auditing and assessing cybersecurity controls such as NIST 800-53, ISO, or CIS18.
- Experience with GRC tools (e.g., Archer, Drata, ServiceNow GRC).
- Experience with data and system classification schemes.
- Excellent communication, analytical, and problem-solving skills.
- Ability to influence cross-functional teams and drive security initiatives.
- Experience in a regulated industry (finance, healthcare, government, etc.) a plus.
- Knowledge of cloud hosting audits and risk assessments.
- Experience with business continuity and disaster recovery planning.
- High-Speed Internet - A stable broadband or fiber connection (satellite is highly discouraged) with a minimum speed of 100 Mbps in a dedicated workspace that has a reliable Wi-Fi signal.
- Device for Multifactor Authentication (MFA/2FA) - smartphone, tablet, etc.
- Data informed decision making.
- Customer first. Always.
- Succeed together.
- Relentless about results. Obsessed with excellence.
- Lead the change. Shape the standard.
- Monthly company All Hands meetings
- Regular opportunities for executive leadership exposure through things like AMAs
- Access to continued learning & development opportunities
- Our commitment to a continuous feedback culture which allows us to drive performance and career growth
- A growing network of Employee Resource Groups
- Company sponsored volunteer hours
- And more!
- 15 paid Romania public holidays + 2 additional Payscale holidays (Global Mental Health Day & US Independence Day)
- 25 paid days of additional leave
- Supplemental medical covered by Payscale for employees
- Employees can add supplemental for family/spouse/dependents at their own expense
- Additional days of per RO Labor Code that are not included in holidays & additional leave days
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits Banking CISA CISM CISSP Cloud Compliance CRISC Finance GDPR Governance ISO 27001 ISO 27005 Monitoring NIST NIST 800-53 POA&M Privacy Risk assessment Risk management RMF SaaS Security assessment
Perks/benefits: Career development Gear Health care Medical leave Startup environment Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.