Technology Compliance & Risk Analyst (GRC)

Added
26 days ago
Type
Full time
Salary
Salary not provided

Related skills

gdpr vendor due diligence dora iso 31000 iso 27001:2022

๐Ÿ“‹ Description

  • Own full vendor risk lifecycle: due diligence, security questionnaires, risk ratings
  • Maintain supplier register and drive reassessment cadence
  • Track fourth-party dependencies; align with DORA ICT & ISO 27001
  • Support ISMS policy, control mapping, and evidence for audits
  • Execute ISO 31000-based risk assessments and RCSA activities
  • Support RoPA, DPIAs, and data subject requests with vendors

๐ŸŽฏ Requirements

  • Proven GRC, IT audit, or vendor risk experience
  • Vendor due diligence and security questionnaire expertise (SIG/CAIQ)
  • Knowledge of ISO 27001:2022, ISO 31000, GDPR; DORA familiarity
  • Independent thinker, identify gaps, propose improvements
  • Pragmatic, business-focused GRC with momentum
  • Strong written communication across risk memos and questionnaires

๐ŸŽ Benefits

  • Autonomy to shape third-party risk management
  • Cross-functional collaboration with security, procurement, and product
  • Opportunity to build scalable GRC processes
Share job

Meet JobCopilot: Your Personal AI Job Hunter

Automatically Apply to Legal Jobs. Just set your preferences and Job Copilot will do the rest โ€” finding, filtering, and applying while you focus on what matters.

Related Legal Jobs

See more Legal jobs โ†’