GRC Analyst

4 months, 1 week ago
Full-time
Junior
Cybersecurity
Flip App

Flip App

Flip is the employee app reshaping workplace communication by empowering every employee with a digital workspace for effective communication and workflow management.

Internet Software & Services
51-250
Founded 2018

Description

  • Own the day-to-day administration and continuous improvement of the ISMS, TISAX assessments, SOC 2 Type II controls, and Cyber Essentials Plus recertification.
  • Coordinate internal and external audits end to end, including evidence collection, packaging, presentation, auditor walkthroughs, and remediation follow-up.
  • Act as the liaison between security/control owners in Engineering and HR and translate compliance requirements into actionable workflow tasks.
  • Maintain the risk register, coordinate quarterly risk reviews, and track treatment plans to completion.
  • Draft, version-control, and maintain a large policy set across the compliance program.
  • Support data privacy operations, including RoPA, DPAs, and Data Subject Requests under GDPR.
  • Plan and deliver security awareness training and phishing simulations.
  • Maintain and update Trust Centre content for client-facing security and compliance communications.

Requirements

  • 2–4 years of experience in a GRC or Information Security role.
  • Strong hands-on experience with ISO 27001 and at least one additional framework such as TISAX, SOC 2, or Cyber Essentials Plus.
  • Experience managing a substantial policy lifecycle, including 50+ policies, and maintaining risk registers and treatment plans.
  • Solid understanding of how SaaS companies operate and the ability to translate compliance needs for engineering and product teams.
  • Excellent communication skills in both English and German (business fluent).
  • Background in B2B SaaS or tech start-up environments with approximately 100–300 employees (preferred).
  • Familiarity with GRC tooling, audit management platforms, or compliance automation tools (preferred).
  • Experience working directly alongside engineering teams (preferred).

Benefits

  • Remote-first work with flexibility to work from home.
  • Occasional in-person collaboration in the Berlin or Stuttgart offices with advance notice.
  • Company-covered E-Gym-Wellpass membership.
  • Job bike leasing.
  • Regular team events and culture days.
  • Opportunity to work abroad within the European Union.
  • Relaxed working atmosphere with a motivated team.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Manager, SAR Filing — BSA/AML & Sanctions Operations

Pathward 251-1K Diversified Financial Services

Pathward is seeking a Manager, SAR Filing to oversee its SAR and CTR filing operations within the BSA/AML and Sanctions Operations team, ensuring accurate, timely, and defensible regulatory filings.

16 hours, 43 minutes ago

Vice President, BSA/AML Operations – Cases

Pathward 251-1K Diversified Financial Services

Pathward seeks a Vice President, BSA/AML Operations – Cases to lead its Suspicious Activity Monitoring case investigation function and strengthen a compliant, risk-based financial crime program within a regulated financial institution.

16 hours, 43 minutes ago

Manager, Sanctions Operations — BSA/AML & Sanctions Operations

Pathward 251-1K Diversified Financial Services

Pathward is seeking a Manager, Sanctions Operations to lead OFAC, 314(a), and PEP screening operations, ensuring accurate dispositions, balanced workloads, and sustainable service levels.

16 hours, 43 minutes ago

Manager, BSA/AML Operations – Alerts (Alert Operations)

Pathward 251-1K Diversified Financial Services

Pathward is seeking a Manager, Alert Operations to lead its Suspicious Activity Monitoring alert-review function within the BSA/AML and Sanctions Operations team, ensuring compliant, risk-based, and sustainable financial-crime monitoring.

17 hours, 13 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers