Governance, Risk and Compliance (GRC) Analyst
Summary
Passeca is hiring a full-time, remote GRC Analyst (2–4 years' experience) to run day-to-day governance, risk and compliance work: risk assessments, ISMS and policy maintenance, audit evidence collection for ISO 27001/SOC 2/GDPR, and vendor security reviews. Core tools include Excel, GRC platforms, and cloud/IAM fundamentals.
Employment Type: Full-Time
Experience: 2–4 years
About the Role
We are looking for a GRC Analyst to join our Information Security and Compliance team. You will run day-to-day governance, risk and compliance activities — risk assessments, ISMS maintenance, audit evidence, and third-party security reviews — with senior support on the more complex work.
This is a hands-on delivery role rather than a first job in security. You should be comfortable running a vendor assessment or an evidence collection cycle without step-by-step direction.
Key Responsibilities
Governance & Policy
Maintain the ISMS, control register and governance documentation.
Draft and update security policies, standards and procedures.
Coordinate security awareness activities and track governance actions.
Risk Management
Run information security risk assessments and maintain the risk register.
Track risk treatment plans and remediation through to closure.
Manage the security exception process.
Compliance & Audit
Support compliance activities across ISO/IEC 27001, SOC 2 and GDPR.
Collect and organise audit evidence; act as a point of contact during internal and external audits.
Track audit and assessment findings to closure.
Third-Party Risk
Run vendor security assessments and review supplier questionnaires.
Maintain supplier risk records and follow up on third-party remediation.
Reporting
Produce monthly security and compliance reporting for management.
Maintain compliance dashboards and documentation repositories.
What We’re Looking For
2–4 years in information security, risk, compliance, audit or IT governance.
Practical working knowledge of at least one major framework (ISO 27001, SOC 2 or NIST CSF).
Working understanding of GDPR and data protection obligations.
Confident with Excel and structured documentation; able to produce reporting for a management audience.
Strong written communication and attention to detail.
Comfortable working with both technical and non-technical stakeholders.
Degree in cyber security, computer science, IT or a related discipline — or equivalent practical experience.
Nice to Have
Hands-on use of a GRC platform (Vanta, Drata, Hyperproof, OneTrust, ServiceNow GRC or Archer).
Cloud security fundamentals (AWS or Azure), IAM and MFA concepts.
Exposure to Cyber Essentials, CIS Controls or AI governance.
Jira or Azure DevOps; Power BI or Excel dashboards.
A certification such as ISC2 CC, CompTIA Security+, ISO 27001 Foundation / Lead Auditor or SC-900.
German is a strong plus
What We Offer
Ownership of real GRC workstreams across the full lifecycle.
Mentorship from senior security professionals and support for certifications.
Clear progression towards Senior GRC Analyst or Risk & Compliance Specialist.
Collaborative and inclusive working environment.