Staff GRC Analyst

Pleo
United Kingdom, Denmark, Portugal, Spain
Workplace: RemoteFull timeFunction: CybersecuritySkills: ["Collaboration","High agency","Initiative","Attention to detail","Data-driven thinking"]

Join the Information Security team as a Staff GRC Analyst, helping scale the governance operating model through compliance automation. You’ll engineer GRC workflows and evidence collection, design scalable GRC architectures for control testing and reporting, and map security policies to frameworks like ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials. Partner cross-functionally across Risk, Compliance, Procurement, Legal, Finance, and Engineering to translate requirements into implementable technical specifications.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Pleo
Pleo
2 days ago

Staff GRC Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 10 hours agoStatus: Live

Job Summary

Join the Information Security team as a Staff GRC Analyst, helping scale the governance operating model through compliance automation. You’ll engineer GRC workflows and evidence collection, design scalable GRC architectures for control testing and reporting, and map security policies to frameworks like ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials. Partner cross-functionally across Risk, Compliance, Procurement, Legal, Finance, and Engineering to translate requirements into implementable technical specifications.
Location: United Kingdom, Denmark, Portugal, Spain
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Automate legacy governance, risk, and compliance systems across frameworks including ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials.
  • •Engineer GRC workflows using internal systems (ticketing, asset management, identity, and cloud platforms) to support compliance by design.
  • •Design and build scalable GRC architectures for evidence collection, control testing, and compliance reporting.
  • •Draft, review, and maintain security policies mapped to control standards, ensuring alignment across frameworks as the business evolves.
  • •Automate security and third-party vendor request flows, and track compliance metrics and KPIs to provide data-driven visibility.

Pay and Benefits

Perks:Remote WorkHealth InsuranceMeal AllowancePaid LeaveParental Leave

Key Requirements

  • •Significant experience in Security GRC, including understanding auditing processes and working across internal and external audit cycles.
  • •Experience using AI and/or coding automation to build and operationalize controls in practice.
  • •Strong understanding of cloud architectures (AWS or equivalent) and how infrastructure decisions map to security controls and audit evidence.
  • •Experience automating GRC reporting (dashboards and executive-level summaries) for GRC programs.
  • •Fintech, payments industry, or IT audit background with familiarity with regulatory expectations; certifications such as CISM, CISSP, CISA, or PCI-related credentials are expected.
Experience:FintechPaymentsIT audit
Skills:CollaborationHigh agencyInitiativeAttention to detailData-driven thinking
Certifications:CISMCISSPCISAPCI-related
Languages:English
Tech Stack:AICoding automationAWSTicketingAsset managementIdentityCloud platformsISO 27001PCI-DSSDORAUK Cyber Essentials

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Pleo
Provides spend management software that helps businesses issue company cards, control expenses, automate reimbursements, and track team spending in one platform. Aims to simplify financial workflows for modern companies.
Industry: Fintech Infrastructure
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: Copenhagen, Denmark
Founded: 2015
WebsiteLinkedIn