Information Security Analyst, GRC
New
X
XBOWCybersecurity
Remote UK/EUFull-TimeMiddle
SalaryCompetitive salary and meaningful stock options.
Apply NowOpens the employer's application page
Job Details
- Experience
- 7+ years
- Required Skills
- HIPAA
Requirements
- 7+ years of experience in risk, compliance, security assurance, or related roles.
- Hands-on experience in technical roles such as Engineering, IT, or operational security.
- Proven experience completing or reviewing technical security questionnaires and customer risk assessments.
- Familiarity with common security compliance and data protection frameworks including SOC 2, ISO 27001, NIST, GDPR, and HIPAA.
- Experience conducting or supporting vendor and third-party risk assessments.
- Strong written communication skills with the ability to explain complex security concepts.
- Highly organized and detail-oriented with a pragmatic approach to risk.
- Comfortable working in a fast-moving, remote-first startup environment.
- Familiar with using modern AI tooling to improve productivity.
- Advantageous: Experience working in a SaaS or security-focused company.
- Advantageous: Experience handling Subject Access Requests for GDPR.
- Advantageous: Security or risk certifications such as CRISC or CISSP.
- Advantageous: Knowledge of cloud security best practices.
Responsibilities
- Complete technical security questionnaires, risk assessments, and due-diligence requests for customers and prospects.
- Partner with Sales and Customer teams to articulate security controls, architecture, and compliance posture.
- Assess and manage third-party and vendor security risk, including reviews of SaaS providers.
- Investigate and resolve alerts to maintain compliance using the Vanta platform.
- Maintain and improve risk assessment frameworks, methodologies, and documentation.
- Track and support remediation of identified risks in collaboration with internal stakeholders.
- Contribute to compliance initiatives aligned with frameworks such as SOC 2, FedRAMP 20x, ISO 27001, and ISO 42001.
- Maintain clear, well-structured risk registers, policies, and supporting evidence.
- Coordinate risk management sessions and processes.
- Support audits, customer reviews, and internal assurance activities.
View Full Description & ApplyYou'll be redirected to the employer's site