GRC Analyst — Information Security GRC



Job Description
Role purpose
Work as a direct extension of the onshore Information Security GRC team in Düsseldorf. You support strategic GRC workstreams led from headquarters: ISMS development, AI governance, NIS2 readiness, supplier risk, policy work, and ad-hoc projects. Suits someone who wants substantive analyst-level work close to a senior GRC function, not back-office task processing.
Key responsibilities
- Take on analyst-level work assigned directly by onshore GRC colleagues across ISMS, AI governance, NIS2, supplier risk, and policy workstreams.
- Draft first versions of documents — policy excerpts, briefing notes, analyses, risk write-ups, audit responses — for review by onshore owners.
- Conduct desk research on frameworks, regulations, vendor capabilities, and benchmarking to support onshore decision-making.
- Prepare data extracts, summaries, and structured inputs for stakeholder meetings, leadership reviews, and audits.
- Maintain shared workspaces, trackers, and registers; coordinate with business entities and group functions on behalf of onshore colleagues when delegated.
- Pick up ad-hoc tasks across the GRC portfolio as they arise; communicate progress, blockers, and risks transparently.
Qualifications
Must-have qualifications
- 2–4 years in GRC, IT audit, information security, or a closely adjacent function.
- Working knowledge of ISO/IEC 27001 or a comparable framework (NIST CSF, SOC 2); understands risk, controls, and good evidence.
- Strong written English; able to draft clear, well-structured notes and analyses for a senior European audience.
- Self-directed: comfortable receiving a task and producing a structured first version without heavy hand-holding.
- Comfortable with Microsoft 365 and at least one GRC platform (ServiceNow GRC, Archer, OneTrust) — or able to learn quickly.
Nice to have
- Foundational certification: ISO 27001 Foundation, CompTIA Security+, or working toward CISA / ISO 27001 LI.
- Exposure to AI governance (ISO 42001, NIST AI RMF), NIS2, DORA, or supplier risk programs.
- Prior experience embedded in or supporting a European team.
