JustMarkets
IT Security Governance, Risk & Compliance Analyst
Europe
Apply through hirly
Upload your resume and get a version tailored to this job, plus a cover letter, in about thirty seconds — before you create an account.
Apply with hirlyhirly's read of this role
- Role family
- Supply chain
- Seniority
- Mid level
- Work mode
- Remote-friendly
- First seen by hirly
- 28 Sept 2026
Derived automatically from the posting. Sign up to see how the role scores against your own resume.
the posting
We are looking for an IT Compliance Analyst/Information Security GRC Analyst to join our Security team and help strengthen the effectiveness and transparency of our security controls.
In this role, you will work across security compliance, control assurance, third-party risk, and security awareness. You will collaborate with Security, Legal, Procurement, technical and business teams to ensure controls are supported by reliable evidence, risks are identified and tracked, and the organization remains ready for audits and regulatory requirements.
This is a great opportunity for someone who enjoys hands-on GRC work, wants to take ownership of processes, and is interested in developing expertise across multiple areas of information security compliance.
Responsibilities
Collect, validate, organize, and maintain audit and security-control evidence
Test assigned security controls, identify gaps, and prepare clear and traceable evidence packages
Support internal and external audits, including SOC 2, DORA, and CySEC-related assurance activities
Maintain control records, evidence repositories, findings, remediation actions, owners, and deadlines
Perform third-party security assessments, including supplier tiering, due diligence, questionnaire reviews, and analysis of assurance evidence
Assess security risks related to SaaS providers, ICT providers, outsourced services, and critical vendors
Track supplier findings, treatment plans, reassessment dates, and remediation progress
Collaborate with Security, Procurement, Legal, technical teams, and business stakeholders
Support security-awareness campaigns, employee onboarding, phishing simulations, and role-based training
Maintain awareness and training completion data and follow up on outstanding actions
Prepare clear, evidence-based compliance and security-risk reporting
Escalate control gaps, overdue evidence, critical supplier findings, and other significant risks through established processes
Requirements
Experience in IT compliance, Information Security GRC, IT risk, IT audit, third-party security risk, or a related field
Hands-on experience collecting, validating, and maintaining audit and control evidence
Understanding of security controls and experience with control testing, gap identification, and remediation tracking
Knowledge of information security and assurance frameworks such as SOC 2, ISO 27001, NIST, CIS Controls, or similar
Understanding of risk assessment and risk treatment principles
Ability to maintain accurate control records, findings, remediation actions, owners, and deadlines
Strong attention to detail and ability to work with sensitive information
Clear written and verbal communication skills with both technical and non-technical stakeholders
Good English communication skills
Will be a plus
Experience with SOC 2, DORA, CySEC, or other financial-services regulatory requirements
Experience with third-party/vendor security risk management , including supplier assessments, security questionnaires, and due diligence
Experience with GRC platforms such as ServiceNow GRC, OneTrust, Archer, Vanta, Drata, Hyperproof , or similar
Experience preparing or delivering security awareness activities, phishing simulations, onboarding, or role-based security training
Relevant certifications such as CISA, CRISC, CISM, ISO 27001 Lead Auditor/Implementer , or similar
Experience supporting internal or external audits
Experience working in FinTech, financial services, SaaS, or another regulated environment
We offer
20 paid vacation days per year
10 paid sick leave days per year
Public holidays as per the company's approved Public holiday list
Medical budget
Opportunity to work remotely
Professional education budget
Language learning budget
Wellness budget (gym membership, sports gear and related expenses)
Similar jobs
- Cyber Security Governance SpecialistPrima · MilanFirst seen todayremote
- Cyber Security Governance SpecialistPrima · MadridFirst seen todayremote
- Information Security Governance CoordinatorVirgin Media O2 · Birmingham, United KingdomFirst seen yesterday
- Information Security Governance CoordinatorVirgin Media O2 · Reading, United KingdomFirst seen yesterday
- Global Cybersecurity Governance AnalystUL Solutions · Northbrook, IL, United States; Chicago, IL, United StatesFirst seen yesterday
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job