IT Security Governance, Risk & Compliance Analyst

7 hours, 19 minutes ago
Full-time
Mid Level
Legal
JustMarkets

JustMarkets

JustMarkets is a leading online trading platform that offers a wide range of financial instruments including Forex, CFDs, Gold, and Oil. With low spreads, high leverage up to 1:3000, and fast execution, JustMarkets provides a next-level trading experie...

Capital Markets
1-10

Description

  • Collect, validate, organize, and maintain audit and security-control evidence.
  • Test assigned security controls, identify gaps, and prepare traceable evidence packages.
  • Support internal and external assurance activities, including SOC 2, DORA, and CySEC-related audits.
  • Maintain control records, findings, remediation actions, owners, deadlines, and evidence repositories.
  • Perform third-party security assessments, including supplier tiering, due diligence, questionnaire reviews, and assurance-evidence analysis.
  • Assess and track risks related to SaaS providers, ICT providers, outsourced services, and critical vendors.
  • Collaborate with Security, Procurement, Legal, technical teams, and business stakeholders.
  • Support security-awareness campaigns, onboarding, phishing simulations, and role-based training.
  • Prepare compliance and security-risk reports and escalate significant gaps, overdue actions, and supplier findings.

Requirements

  • Experience in IT compliance, Information Security GRC, IT risk, IT audit, third-party security risk, or a related field.
  • Hands-on experience collecting, validating, and maintaining audit and control evidence.
  • Understanding of security controls, control testing, gap identification, and remediation tracking.
  • Knowledge of SOC 2, ISO 27001, NIST, CIS Controls, or similar frameworks.
  • Understanding of risk assessment and risk treatment principles.
  • Strong attention to detail and ability to handle sensitive information.
  • Clear written and verbal communication skills with technical and non-technical stakeholders, including good English communication.
  • Experience with SOC 2, DORA, CySEC, or other financial-services regulations is preferred.
  • Experience with vendor security risk management and GRC platforms such as ServiceNow GRC, OneTrust, Archer, Vanta, Drata, or Hyperproof is preferred.
  • Relevant certifications such as CISA, CRISC, CISM, or ISO 27001 Lead Auditor/Implementer are preferred.

Benefits

  • Remote work opportunity.
  • 20 paid vacation days and 10 paid sick leave days annually.
  • Medical budget and wellness budget for gym, sports equipment, and related expenses.
  • Professional education budget and language learning budget.
  • Tax expense coverage and expert support for Ukrainian private entrepreneurs.
  • Paid public holidays according to the company holiday schedule.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Director of Compliance (Remote)

Ennoble Care 51-250 Health Care Providers & Services

Ennoble Care is seeking a Director of Compliance to lead its hospice compliance program, overseeing regulatory strategy, audits, corrective actions, policies, investigations, and external audit responses across its multi-state home-based care operations.

7 hours, 19 minutes ago

Virginia Tech | Compliance Advisory - 2027 Summer Internship

Coalfire 251-1K Internet Software & Services

Coalfire is seeking paid Summer 2027 Compliance Advisory interns to support cybersecurity compliance assessments and advisory projects for public sector, healthcare, and GRC clients in a remote or hybrid setting.

Cybersecurity HIPAA
7 hours, 49 minutes ago

AML Analyst

Rush Street Interactive 251-1K Hotels, Restaurants & Leisure

Rush Street Interactive is seeking a remote AML Analyst to support anti-money laundering compliance, financial-crime investigations, and regulatory reporting across its online casino, sports betting, and retail gaming operations.

8 hours, 4 minutes ago

Forensic Regulatory Data Analyst

UtiliSave 11-50 Professional Services

UtiliSave is hiring a remote Forensic Regulatory Data Analyst to analyze utility billing records for commercial and industrial clients, identify recoverable savings, and pursue claims with utilities and regulators.

Agile Python
1 day, 8 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers