Senior InfoSec GRC Analyst

Camunda
Anywhere
Workplace: RemoteFull timeFunction: CybersecuritySkills: ["Collaboration","Project management","Communication","Judgement"]

Own and continuously improve the InfoSec Governance, Risk & Compliance practice by maintaining Camunda’s ISMS and driving ISO 27001 and SOC 2 audit cycles. Review customer security requirements, lead responses to security questionnaires, and serve as a trusted InfoSec point of contact. Build and automate GRC tooling with continuous monitoring, and translate emerging regulations like the Cyber Resilience Act and AI Act into actionable work with cross-functional partners.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Camunda
Camunda
2 days ago

Senior InfoSec GRC Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Own and continuously improve the InfoSec Governance, Risk & Compliance practice by maintaining Camunda’s ISMS and driving ISO 27001 and SOC 2 audit cycles. Review customer security requirements, lead responses to security questionnaires, and serve as a trusted InfoSec point of contact. Build and automate GRC tooling with continuous monitoring, and translate emerging regulations like the Cyber Resilience Act and AI Act into actionable work with cross-functional partners.
Location: Anywhere
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Own and continuously improve Camunda’s ISMS by spotting gaps, closing them, and making measurable improvements.
  • •Drive the security audit cycle for ISO 27001, SOC 2, and future frameworks with external auditors and internal control owners.
  • •Review customer security requirements in contracts, redline unmet items, and provide actionable recommendations to negotiators.
  • •Lead responses to complex customer security questionnaires and act as a trusted point of contact for InfoSec topics from PreSales and PostSales.
  • •Run and improve GRC tooling with automation and continuous monitoring, and translate emerging compliance topics like the Cyber Resilience Act and AI Act into implementation work.

Pay and Benefits

Equity and Bonus:Equity
Perks:Remote WorkHealth InsurancePensionLearning Budget

Key Requirements

  • •Hands-on experience implementing and maintaining ISO 27001 and/or SOC 2 certifications, including managing external audits from evidence gathering through to closing findings.
  • •Substantial experience across information security, risk management, and compliance with a focus on GRC, ideally in a SaaS or cloud software company.
  • •Practical experience reviewing information security requirements in customer contracts and leading responses to security questionnaires, with sound judgment on real risk vs. negotiable clauses.
  • •Experience working with GRC tools, compliance automation, and continuous monitoring, with a preference for automating repetitive work.
  • •Strong project management and collaboration skills to move multiple workstreams and explain security topics clearly to technical and non-technical stakeholders.
Experience:SaaSCloud softwareInformation securityGovernance risk and compliance (GRC)
Skills:CollaborationProject managementCommunicationJudgement
Tech Stack:ISMSISO 27001SOC 2GRC toolsContinuous monitoringCyber Resilience ActAI ActNIS2

Company Brief

Camunda
Provides an open-source and commercial platform for process orchestration and workflow automation, enabling enterprises to design, execute, and monitor business processes across people, systems, and AI agents.
Industry: SaaS
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Funding: Series B
Headquarters: Berlin, Germany
Founded: 2008
Glassdoor
Glassdoor: 3.4
WebsiteLinkedInGlassdoor