Staff GRC Analyst

Pleo
London, Lisbon, Copenhagen, Madrid
Workplace: HybridFull timeFunction: CybersecuritySkills: ["High agency","Initiative","Collaboration","Problem-solving"]

Join Pleo’s Information Security team as a Staff GRC Analyst, helping scale the governance operating model through compliance automation. You’ll build GRC workflows and architectures for evidence collection, control testing, and reporting across frameworks like ISO 27001, PCI-DSS, and DORA. Partnering with Risk & Compliance, Procurement, Legal, Finance, and Engineering, you’ll also automate security requests, vendor assessments, and compliance metrics dashboards.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Pleo
Pleo
2 days ago

Staff GRC Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 11 hours agoStatus: Live

Job Summary

Join Pleo’s Information Security team as a Staff GRC Analyst, helping scale the governance operating model through compliance automation. You’ll build GRC workflows and architectures for evidence collection, control testing, and reporting across frameworks like ISO 27001, PCI-DSS, and DORA. Partnering with Risk & Compliance, Procurement, Legal, Finance, and Engineering, you’ll also automate security requests, vendor assessments, and compliance metrics dashboards.
Location: London, Lisbon, Copenhagen, Madrid
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Automate governance, risk, and compliance frameworks including ISO 27001, PCI-DSS, DORA, UK Cyber Essentials, and relevant financial services regulations.
  • •Engineer GRC workflows using internal systems such as ticketing, asset management, identity, and cloud platforms to support compliance by design.
  • •Design and build scalable GRC architectures for evidence collection, control testing, and compliance reporting.
  • •Draft, review, and maintain security policies mapped to control standards, ensuring alignment across frameworks as the business evolves.
  • •Automate security request intake and third-party vendor assessments, tracking gaps and compliance metrics for leadership visibility.

Pay and Benefits

Perks:Health InsurancePaid ParentalMeal Allowance

Key Requirements

  • •Significant experience in Security GRC, including hands-on work across internal and external audit cycles.
  • •Demonstrated experience using AI and/or coding automation to build and operate controls in practice.
  • •Strong understanding of cloud architectures (AWS or equivalent) and how infrastructure decisions map to security controls and audit evidence.
  • •Experience automating GRC program reporting, including dashboards and executive-level summaries.
  • •Fintech, payments industry, or IT audit background, with familiarity with regulatory expectations and payment platform architectures.
Experience:FintechPaymentsIT audit
Skills:High agencyInitiativeCollaborationProblem-solving
Certifications:CISMCISSPCISAPCI
Languages:English
Tech Stack:ISO 27001PCI-DSSDORAUK Cyber EssentialsAWS

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Pleo
Provides spend management software that helps businesses issue company cards, control expenses, automate reimbursements, and track team spending in one platform. Aims to simplify financial workflows for modern companies.
Industry: Fintech Infrastructure
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: Copenhagen, Denmark
Founded: 2015
WebsiteLinkedIn