hirly

Xbowcareers

Information Security Analyst, GRC

Europe (Remote) · Remote (UK)

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Xbowcareers first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Seniority
Mid level
Country
GB
Work mode
Remote-friendly
First seen by hirly
11 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

About XBOW

At XBOW, we’re redefining the future of cybersecurity by building the world's first autonomous pentester, powered by AI. Today, the gold standard for securing software systems is human pentesters, but with the rise of artificial intelligence, we’re stepping up to scale offensive security to meet the ever-growing demand.

AI is transforming the landscape of both cybersecurity and cyberattacks. While millions of people without security expertise are creating software, bad actors are using AI to launch more effective attacks. XBOW fights back with AI-driven superpowers, enabling security teams to stay one step ahead.

What makes XBOW truly unique? Like human experts, it forges creative attacks, adapts its learnings, and continuously works to find vulnerabilities faster than anyone ever could. We’re not only simulating threats—we’re also finding and responsibly disclosing real-world vulnerabilities, ensuring organizations can fix issues before they’re exploited. XBOW isn’t just a tool; it’s a transformative force in the secure development lifecycle.

Backed by Sequoia Capital and a team that includes the creators of GitHub Copilot and GitHub Advanced Security, XBOW is not just keeping up with the times—we’re shaping the future of cybersecurity. Our mission is simple: to defeat the bad actors before they strike, using AI to revolutionize how we approach offensive security.

We’re building something that must be built, and we’re the team to do it. Join us in shaping the next frontier of autonomous security.

Your Role: Information Security Analyst, GRC

We’re looking for a detail-oriented, Information Security Analyst to help scale our security and trust function as we grow. In this role, you’ll play a key part in supporting customer and prospect security reviews, coordinating with legal on reviewing customer contracts, assessing third-party vendor risk, supporting resolution of compliance alerts and continuously improving how we identify and manage risk across the business.

This is an individual contributor role with no initial people-management responsibilities. However, as the risk and compliance function matures, there is a clear opportunity for this role to grow in scope and responsibility.

You’ll work closely with IT, Security, Engineering, Legal, Sales, and Customer teams, acting as a trusted partner in communicating our security posture and ensuring we meet customer and regulatory expectations.

What You'll Do

Support customers and prospects by completing technical security questionnaires, risk assessments, and due-diligence requests

Partner with Sales and Customer teams to explain XBOW’s security controls, architecture, and compliance posture

Assess and manage third-party and vendor security risk, including reviews of SaaS providers and service partners

Investigate and resolve alerts to stay compliant with our compliance programmes using the Vanta product.

Help maintain and improve risk assessment frameworks, methodologies, and documentation

Track and support remediation of identified risks in collaboration with internal stakeholders

Contribute to compliance initiatives aligned with frameworks such as SOC 2, FedRAMP 20x, ISO 27001, and ISO 42001

Maintain clear, well-structured risk registers, policies, and supporting evidence

Coordinate risk management sessions and processes

Identify opportunities to streamline and automate risk and compliance processes as the company scales

Support audits, customer reviews, and internal assurance activities as needed

Skills and Qualifications

Essential

7+ years of experience in risk, compliance, security assurance, or related roles

Experience in hands-on technical roles for example in Engineering, IT or operational security

Hands-on experience completing or reviewing technical security questionnaires and customer risk assessments

Familiarity and experience with common security compliance, and data protection frameworks (e.g. SOC 2, ISO 27001, NIST, GDPR, and HIPAA)

Experience conducting or supporting vendor / third-party risk assessments

Strong written communication skills, with the ability to explain complex security concepts clearly

Highly organized and detail-oriented, with a pragmatic approach to risk

Comfortable working in a fast-moving, remote-first startup environment

Familiar with using modern AI tooling to improve productivity whilst managing risk

Advantageous

Experience working in a SaaS or security-focused company

Experience handling Subject Access Requests for GDPR

Security or risk certifications (e.g. CRISC or CISSP)

Knowledge of cloud security best practices

What We Offer

Compensation & Equity: Competitive salary and meaningful stock options.

Growth: Opportunity to learn from and collaborate with top security and AI experts

Impact : Work on complex technical challenges that support the foundation of our company

Remote-First :Work from anywhere, with regular opportunities to meet in person

What Else You Should Know

Location: Remote UK/EU (all team members are remote but we meet regularly and you’re supported to travel to collaborate with colleagues in person)

Contract: Full-time.

Hiring Process:

Talent Introduction

GRC & Security Knowledge Interview

A conversation about your practical security and GRC knowledge and how you apply it in day-to-day compliance work.

Hiring Manager Interview

Final Interview with a member of our leadership team

We’re a security company that builds with AI at the core - so you’ll be protecting a team that moves fast, iterates aggressively, and lives in the command line. If that sounds like your kind of environment, let’s talk.

Original posting on Xbowcareers's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job