Information Security Analyst, GRC
jobgether
Switzerland
Vollzeit
Diese Anzeige stammt von Lever
Accountabilities
- Support customers and prospects by completing technical security questionnaires, risk assessments, due-diligence requests, and security reviews.
- Partner with Sales and Customer teams to clearly explain security controls, architecture, compliance posture, and risk management practices.
- Assess and manage security risks associated with third-party vendors, SaaS providers, and service partners.
- Investigate and resolve compliance alerts and support ongoing compliance activities using GRC tooling such as Vanta.
- Maintain and continuously improve risk assessment frameworks, methodologies, processes, and supporting documentation.
- Track identified risks through remediation in collaboration with relevant internal stakeholders.
- Contribute to compliance initiatives aligned with frameworks and standards including SOC 2, FedRAMP 20x, ISO 27001, and ISO 42001.
- Maintain accurate and well-structured risk registers, security policies, evidence, and other compliance documentation.
- Coordinate risk management sessions and support ongoing risk governance processes.
- Identify opportunities to simplify, streamline, and automate risk and compliance activities as the organization grows.
- Support internal assurance activities, audits, customer reviews, and other security-related assessments.
- Collaborate across IT, Security, Engineering, Legal, Sales, and Customer teams to ensure security and compliance requirements are understood and addressed.
- Help strengthen the overall security and trust function through practical, scalable, and risk-based processes.
- 7+ years of experience in information security, risk, compliance, security assurance, or a related discipline.
- Hands-on experience in a technical environment such as Engineering, IT, operational security, or a comparable function.
- Proven experience completing or reviewing technical security questionnaires, customer security assessments, and due-diligence requests.
- Strong knowledge of security, compliance, and data protection frameworks such as SOC 2, ISO 27001, NIST, GDPR, and HIPAA.
- Practical experience conducting or supporting third-party and vendor security risk assessments.
- Strong written and verbal communication skills, with the ability to explain complex security concepts clearly to both technical and non-technical audiences.
- Highly organized and detail-oriented, with a pragmatic approach to identifying and managing risk.
- Comfortable working independently and taking ownership in a fast-moving, remote-first startup environment.
- Familiarity with modern AI tools and the ability to use them productively while appropriately managing associated risks.
- Strong analytical and problem-solving skills, with the ability to balance security requirements against business priorities.
- Experience in a SaaS or cybersecurity-focused organization is advantageous.
- Experience handling GDPR Subject Access Requests is a plus.
- Security or risk certifications such as CRISC or CISSP are valued.
- Knowledge of cloud security best practices is beneficial.
- Competitive compensation: Attractive salary package aligned with experience and responsibilities.
- Equity: Meaningful stock options providing an opportunity to participate in the organization’s growth.
- Remote-first: Work remotely within the eligible European region.
- Flexible environment: Work in a distributed environment designed to support autonomy and ownership.
- Career growth: Opportunity to expand your responsibilities as the risk, compliance, and security function matures.
- Expert collaboration: Learn from and work alongside experienced professionals in cybersecurity, AI, engineering, and security operations.
- Meaningful impact: Contribute to the security and compliance foundation of an organization operating at the forefront of AI-driven cybersecurity.
- Cross-functional exposure: Partner with teams across engineering, IT, legal, sales, customer success, and security.
- International collaboration: Work with a globally distributed team and have regular opportunities to connect with colleagues in person.
Diese Anzeige stammt von Lever. Originalanzeige ansehen ↗