Back to Remote jobs   >   Compliance   >   grc analyst
Governance, Risk and Compliance Analyst @Nasuni
Compliance
Salary unspecified
Remote Location
remote UK
Employment Type full-time
Posted 1wk ago

[Hiring] Governance, Risk and Compliance Analyst @Nasuni

1wk ago - Nasuni is hiring a remote Governance, Risk and Compliance Analyst. πŸ’Έ Salary: unspecified πŸ“Location: UK

Role Description

Nasuni is looking for a Governance, Risk & Compliance (GRC) Analyst to help operate and strengthen the programs that support our security, compliance, and risk posture.

You will take hands-on ownership of defined GRC workflows including:

  • Third-party risk assessments
  • Customer security requests
  • Security awareness activities
  • User access reviews

You will also support:

  • Audits
  • Enterprise risk management
  • Policy governance
  • Continuous improvement across our GRC program

This opportunity is suited to an early-career GRC or security professional who has moved beyond observation and is ready to independently execute recurring processes, coordinate with stakeholders, analyze evidence, maintain accurate records, and know when a risk or exception requires escalation.

You will independently execute defined GRC processes using established controls, criteria, and escalation paths. You will work across:

  • Security
  • Legal
  • Procurement
  • Sales
  • Customer Success
  • IT
  • Other business teams

Success means delivering reliable GRC operations, maintaining audit-ready information, identifying issues early, and continuously finding practical ways to make recurring work more efficient.

Qualifications

  • 2+ years of hands-on experience in GRC, information security, IT audit, risk, compliance, or a closely related discipline.
  • Practical experience executing at least two GRC activities such as third-party risk reviews, access reviews, audit evidence collection, security questionnaires, security awareness, risk tracking, or compliance operations.
  • Working knowledge of security or compliance frameworks such as SOC 1/2, ISO 27001, NIST, GDPR, HIPAA, or comparable standards.
  • Ability to review evidence, document findings clearly, manage deadlines, and follow issues through resolution.
  • Strong written communication and ability to work effectively with technical and non-technical stakeholders.
  • Sound judgment around confidential information, risk escalation, and quality control.
  • Experience supporting external audits or formal certification programs.
  • Experience using a GRC platform such as LogicGate, OneTrust, Vanta, Drata, or a comparable system.
  • Experience in a SaaS, cloud, technology, or other fast-moving environment.
  • Practical use of AI-enabled tools to improve analysis, documentation, reporting, or workflow efficiency with appropriate validation.
  • Experience across three or more GRC operational areas.
  • Exposure to cloud/SaaS security and customer assurance processes.
  • Security+, GSEC, or similar certification, or progress toward CISA, CRISC, CISM, or ISO 27001 credentials.
  • Evidence of improving or automating a recurring GRC workflow.

Requirements

  • Conduct third-party security and compliance assessments, reviewing SOC reports, ISO certifications, questionnaires, and other evidence; document findings and track remediation or approved risk treatment.
  • Coordinate vendor assessments from intake and due diligence through reassessment using established risk criteria.
  • Respond to customer security questionnaires, RFPs, and due-diligence requests, maintaining accurate reusable security and control content.
  • Coordinate approved security and compliance artifacts for customers and support internal teams with security-related contractual requests.
  • Administer security awareness activities, including training campaigns, phishing simulations, completion tracking, communications, and program metrics.
  • Plan and execute periodic user access reviews, coordinate with system owners, identify inappropriate or orphaned access, and track remediation and exceptions.
  • Support SOC 1, SOC 2, ISO 27001, and other assessments by gathering and validating evidence, maintaining documentation, and tracking corrective actions.
  • Maintain accurate risk, policy, exception, finding, and remediation records and support reporting for GRC stakeholders and leadership.
  • Identify opportunities to simplify or automate recurring GRC activities while maintaining appropriate controls and human review.
  • Use approved AI-enabled tools where appropriate to accelerate research, analysis, drafting, summarization, and workflow improvement while validating outputs and protecting confidential information.

Benefits

  • Best in class employee onboarding and training
  • Comprehensive health, dental and vision plans
  • Life and disability insurance
  • Retirement plan
  • Generous employee referral bonuses
  • Flexible remote work policy
  • Collaborative workspaces
Before You Apply
️
remote Be aware of the location restriction for this remote position: UK
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Back to Remote jobs   >   Compliance   >   grc analyst
Governance, Risk and Compliance Analyst @Nasuni
Compliance
Salary unspecified
Remote Location
remote UK
Employment Type full-time
Posted 1wk ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: UK
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,533+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later