GRC Analyst
Summary
The GRC Analyst will manage the Information Security Program by ensuring regulatory compliance, conducting risk assessments, and performing control testing. The role involves working with global frameworks like ISO27001 and NIST to support the security of an online trading platform.
Fancy helping to shape the future of FinTech?
We have always been innovators. In 1996 we were the first company to share exchange rate information, free of charge on the internet. Today, we are a world leading online trading group.
Join us to:
- Help build the future of online trading
- Be part of a culture driven by integrity and global impact
- Become part of an award-winning company - check out our full list of awards here
We are only as good as our people. Luckily, our people are the best. Join us!
How do we work?
Hi Everyone!
We build, maintain, and drive the evolution of our Information Security Program - ensuring strong governance, risk management, and regulatory compliance across the organization. From aligning with global frameworks like NIST CSF and ISO27001:2022 to seamlessly integrating Cyber Risk into Enterprise Risk Management, we keep our operations secure, resilient, and audit-ready. Working closely with internal teams, external auditors, and regulatory bodies, we protect our ecosystem while enabling continuous growth.
We work in a hybrid model - we'd love to meet you in the office 2 times a week with respect to your own commitments.
In this role, you will:
Collect and analyze cybersecurity requirements to ensure alignment with GDPR, DORA, ISO27001, and financial regulations.
Monitor key controls, KRIs, and KPIs, tracking ongoing cyber risks and supporting remediation plans across teams.
Participate in scheduled control testing, policy reviews, and documentation updates for the security program.
Assist in creating engaging training materials to defend employees against malware, phishing, and physical security threats.
Help gather supporting evidence for internal/external audits and assist in responding to regulatory questionnaires.
What skillset do you need to be successful in this role?
Min. 2 years of experience specifically within Information Security, Risk Management, or GRC, but impact matters more than years.
Good working knowledge of major security frameworks (ISO27001, NIST, SOC2, PCI-DSS).
Understanding of key regulations, particularly GDPR, DORA, and financial sector standards.
Hands-on experience with policy reviews, risk tracking, or control testing.
Good analytical and communication skills, with a proactive and solution-oriented mindset.
Nice to have:
Relevant industry certifications e.g., Security+, ISO27001 Auditor/Implementer, CRISC.
Prior experience in the Financial Services or Trading industry.
Your perspective matters. We encourage you to apply even if you are hesitant about meeting every single qualification. We are excited to see what you can bring to the team!
___
At OANDA, to help us efficiently process applications, we use AI-driven tools to help source and rank candidates based on professional experience and skills. While these tools provide recommendations, our recruitment process remains human-centric: all final shortlisting and hiring decisions are made by OANDA team. You have the right to request a human review of your application.
OANDA Global Corporation is a diverse and global team with offices around the world. We value the unique skills and experiences each individual brings to OANDA. We are committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide an inclusive and accessible environment for everyone. Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment and selection process, please let us know. We will work with you to provide as seamless a recruitment experience as possible.
Learn more about our culture here.
Review OANDA Privacy Policy and learn more about how we treat your personal data and protect your privacy.