← Back to list
Job

GRC Security Analyst - Information Security

Security Engineer • On-site • Full-time • Poland Poland

Appfire's Information Security team is hiring a GRC Security Analyst to handle governance, risk and compliance tasks and support ISO 27001 and other audits.

Responsibilities

  • ▹Coordinate and facilitate security governance goals and initiatives
  • ▹Support sales channels with prospect and customer security questions, assessments and audits, speaking to technical controls, their alternatives and risk mitigation
  • ▹Conduct vendor risk management assessments and follow up on findings
  • ▹Support regulatory and compliance initiatives (e.g. ISO 27001, SOC 2, GDPR)
  • ▹Identify, document and track information security policy non-conformities and assist in developing and monitoring corrective action plans
  • ▹Assist in identifying and tracking information security risks, assessing impact and tracking mitigation plans
  • ▹Track risk acceptances and exceptions and monitor remediation plans
  • ▹Ensure adequate and timely resolution of audit and risk assessment findings
  • ▹Assist in monitoring business continuity (BC) and disaster recovery (DR) testing
  • ▹Perform periodic compliance checks across the organization
  • ▹Support coordination and execution of integration plans for Appfire acquisitions
  • ▹Support the annual review of information security policies and processes
  • ▹Participate in annual security awareness campaigns

Requirements

  • ▹Bachelor's degree in Computer Science, Information Security, Engineering or a related field, or equivalent experience
  • ▹2+ years of experience in information security risk and/or compliance roles
  • ▹Knowledge of common information security frameworks such as CIS, ISO 27001 and SOC 2
  • ▹Ability to work effectively in a fast-paced, changing, high-growth environment
  • ▹Self-starter who proactively identifies issues and opportunities
  • ▹Creative problem solving
  • ▹Excellent interpersonal and communication skills

Nice to have

  • ▹Experience with cloud-based security tools, technologies and controls (e.g. AWS, Azure, Heroku, GCP)
  • ▹CISA, CISSP or similar security/GRC certifications

Soft skills

Organization and attention to detailExcellent communication and interpersonal skillsSelf-starter attitudeCreative problem solvingDiscretion with sensitive information

What we offer

  • ▹Company equity for every team member
  • ▹26 paid vacation days annually, regardless of tenure
  • ▹12 Wellness Days: one fully paid day off each month, ad-hoc, not carried over
  • ▹24 hours of paid volunteer time
  • ▹3 fully paid volunteering days a year through Appfire Town, the CSR program
  • ▹Appfire University: custom, on-demand learning platform
  • ▹Fully covered Luxmed private healthcare plan, with the option to extend coverage to a partner or add personalized upgrades
  • ▹UNUM life insurance, fully paid by Appfire
  • ▹MyBenefit Platform with 150 PLN per month (Multisport card, shopping, restaurants, entertainment, experiences)
  • ▹Lunch Card with 300 PLN monthly for groceries or dining out via a virtual prepaid Pluxee card (Google Pay and Apple Wallet supported)
  • ▹200 PLN net per month home office allowance for electricity and internet costs

About the company

Appfire is the largest global provider of Atlassian apps, with 800+ employees working remotely across 28 countries. Its products include JXL, Comala Document Management, 7Pace Time Tracker, Jira Misc Workflow Extensions and BigPicture.

Education: Informatikai, információbiztonsági, mérnöki vagy kapcsolódó egyetemi végzettség, vagy azzal egyenértékű tapasztalat

Similar jobs