Senior GRC Analyst (m,f,x)

HelloFresh
Berlin
Workplace: HybridFull timeFunction: Solutions Engineering & Sales EngineeringExperience: 3+ yearsSkills: ["Organization","Detail-oriented","Communication","Problem-solving","Teamwork"]

Lead and implement information security compliance programs (NIS2, PCI DSS, CSRD, ISO/SOC, EU AI Act) within a SaaS environment. Drive internal control assessments, external audits, data privacy, vendor risk, and continuous GRC maturity while coordinating cross-functional teams from a Berlin-based office.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
HelloFresh
HelloFresh
3 months ago

Senior GRC Analyst (m,f,x)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Lead and implement information security compliance programs (NIS2, PCI DSS, CSRD, ISO/SOC, EU AI Act) within a SaaS environment. Drive internal control assessments, external audits, data privacy, vendor risk, and continuous GRC maturity while coordinating cross-functional teams from a Berlin-based office.
Location: Berlin
Workplace: Hybrid
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering

Key Responsibilities

  • •Lead end-to-end compliance readiness for NIS2 and support alignment across other key frameworks (e.g., PCI DSS, CSRD, ISO/SOC and EU AI Act).
  • •Plan and execute internal control assessments and coordinate external compliance audits on a defined cadence.
  • •Translate regulatory requirements into practical controls; drive cross-functional implementation across international teams.
  • •Own remediation management: track findings, evidence, owners, deadlines, and report status to stakeholders.
  • •Improve GRC maturity through continuous monitoring, clear documentation, and mentoring junior team members.

Pay and Benefits

Perks:RelocationPensionMeal AllowanceGym MembershipSabbatical Leave

Key Requirements

  • •3+ years' experience in compliance activities in a corporate environment related to IT General Controls (ITGC), SOC 2, ISO 27001, PCI DSS, EU NIS2, and various data privacy directives (GDPR, CCPA/CPRA, etc.)
  • •Ability to interpret compliance regulations and map them to the actual implementation of systems, whilst referencing various security frameworks
  • •Experience supporting data privacy regulations (GDPR, CCPA) and third-party risk management programs
  • •Experience with developing and executing security awareness programs and trainings
  • •Prior experience working in a SaaS environment, mainly Cloud and AWS-based
Experience:3+ yearsSaaSCloudInformation securityCompliance
Skills:OrganizationDetail-orientedCommunicationProblem-solvingTeamwork
Certifications:CISACISMCISSP
Languages:English
Tech Stack:AWSCloudITGCSOC 2ISO 27001PCI DSSGDPRCCPACSRDEU AI Act

Company Brief

HelloFresh
HelloFresh is a meal-kit and food subscription company that delivers fresh ingredients and recipes to consumers, offering convenient home-cooked meals through weekly subscription boxes across multiple international markets.
Industry: FoodTech
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Berlin, Germany
Founded: 2011
Glassdoor
Glassdoor: 3.6
WebsiteLinkedIn