GRC Security Analyst - Information Security

1 day, 1 hour ago
Full-time
Junior
Cybersecurity
Appfire

Appfire

Appfire specializes in providing enterprise collaboration software solutions that enhance workflow and productivity for teams using platforms like Atlassian, Microsoft, and Salesforce, while also offering tools for IT service management and agile work ...

Internet Software & Services
251-1K
$149M raised

Description

  • Coordinate and facilitate security governance goals and initiatives.
  • Support sales teams with customer security questions, assessments, audits, technical controls, and risk mitigation options.
  • Conduct vendor risk assessments and follow up on findings.
  • Support ISO 27001, SOC 2, GDPR, and other regulatory compliance initiatives.
  • Identify, document, and track policy nonconformities, risks, exceptions, and corrective action plans.
  • Track audit and risk assessment findings through timely resolution.
  • Monitor business continuity and disaster recovery testing.
  • Perform periodic organizational compliance checks and support policy reviews.
  • Support security integration plans for acquisitions and annual security awareness campaigns.
  • Handle sensitive information with appropriate discretion.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Engineering, a related field, or equivalent experience.
  • 2+ years of experience in information security risk or compliance roles.
  • Knowledge of security frameworks including CIS, ISO 27001, and SOC 2.
  • Experience with cloud security tools, technologies, and controls such as AWS, Azure, Heroku, or GCP is preferred.
  • Strong interpersonal, written, and verbal communication skills.
  • Ability to work effectively in a fast-paced, rapidly changing environment.
  • Self-starter with initiative and the ability to identify issues or opportunities and recommend actions.
  • Creative problem-solving skills.
  • CISA, CISSP, or similar security/GRC certification is preferred.

Benefits

  • Company equity eligibility for every team member.
  • 25 days of annual leave, with up to 10 unused days eligible for carryover.
  • Fully remote work within Spain, with access to the Bilbao office; reduced summer hours and flexible bank holidays.
  • Access to Appfire University for professional development.
  • Company-paid private health insurance, with discounted family coverage available.
  • €400 gross annual sport and wellness allowance.
  • €50 monthly home-office and remote-work expense allowance.
  • Three paid volunteering days annually.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Incident Response & DFIR Lead

JustMarkets 1-10 Capital Markets

Lead incident response and digital forensics investigations for a fintech company, coordinating containment, recovery, evidence preservation, and improvements to cyber defense capabilities.

Active Directory AWS Linux Network Security PowerShell Python SIEM
1 hour, 26 minutes ago

Cyber Security Specialist

RecargaPay 251-1K Capital Markets

RecargaPay is hiring a Cyber Security Specialist to join its remote CSIRT team and lead detection, response, containment, and automation for security incidents across its cloud-native payments platform.

AWS Bash CrowdStrike Cybersecurity Elasticsearch Kibana Linux Python
2 hours, 26 minutes ago

IT SOX Admin

CareDx 251-1K Pharmaceuticals

CareDx is seeking an IT compliance and systems documentation professional to strengthen system governance, access controls, audit readiness, and operational integrity in its regulated precision-medicine diagnostics environment.

Active Directory Git NetSuite
6 days, 2 hours ago

Information Systems Security Officer (ISSO), Senior

Lever 251-1K Professional Services

AnaVation is seeking a senior Information Systems Security Officer (ISSO) to lead the Risk Management Framework (RMF) and accreditation of a new digital evidence platform supporting a U.S. Federal Government client, working remotely with occasional travel to Washington, DC.

AWS Azure DevSecOps Penetration Testing
1 week, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers