Staff GRC Analyst
PleoRemotely
automationawscloudgrcregulatory complianceiso 27001dorauk cyber essentials
Job Description
📋 Description
- Automate our legacy systems relating to governance, risk, and compliance frameworks, including ISO
- Engineer GRC workflows with internal systems (e.g., ticketing, asset management, identity, cloud
- Design and build scalable GRC architectures and automation for evidence collection, control
- Draft, review, and maintain Pleo's security policies, mapping them to relevant control standards
- Automate incoming security requests from customers and prospects, including questionnaires, one-off
- Automate third-party vendor assessments, evaluating suppliers against Pleo's compliance and
🎯 Requirements
- Significant experience in Security GRC, understanding of auditing processes, with direct experience
- Demonstrated experience using AI and/or coding automation to get controls built, implemented, and
- A strong understanding of cloud architectures (AWS or equivalent) and how infrastructure decisions
- Experience automating reporting for GRC programs, including dashboards and executive-level
- Fintech, payments industry or IT audit background, with familiarity with regulatory expectations
- Certifications such as CISM, CISSP, CISA, or PCI-related credentials. A degree in Cybersecurity
🎁 Benefits
- Your own Pleo card (no more out-of-pocket spending!)
- Lunch is on us for your work days - enjoy catered meals or receive a lunch allowance based on your
- Comprehensive private healthcare - depending on your location, coverage options include Vitality
- We offer 25-28 days of holiday (depending on your location) + public holidays
- For our Team, we offer both hybrid and fully remote working options
- Option to purchase 5 additional days of holiday through a salary sacrifice