About the role:
- We're looking for a Staff GRC Analyst to join our Information Security team at Pleo.
- In this role, you'll help and be part of our governance operating model as we scale compliance.
What you’ll be doing:
- Automate our legacy systems relating to governance, risk, and compliance frameworks, including ISO 27001, PCI-DSS, DORA, UK Cyber Essentials and relevant financial services regulations.
- Engineer GRC workflows with internal systems to support compliance by design.
- Design and build scalable GRC architectures and automation for evidence collection, control testing, and compliance reporting.
What you bring:
- Significant experience in Security GRC, understanding of auditing processes, with direct experience in both internal and external audit cycles.
- Demonstrated experience using AI and/or coding automation to get controls built, implemented, and operating in practice.
- A strong understanding of cloud architectures (AWS or equivalent) and how infrastructure decisions map to security controls and audit evidence.
Why this role fits you:
- You're equally excited about getting into the details of regulations requirements as you are about writing code.
- You demonstrate high-agency and like to take initiative in developing solutions that will save the team time.
Pleo
Pleo builds spend solutions that make managing money seamless for finance teams and employees. They are a driven, progressive team of 850+ people from over 100 nationalities, committed to delivering the future of business spending.