Information Security Analyst, GRC

XBOW

Deutschland

Remote

EUR 90.000 - 120.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Verschicke keinen 08/15-Lebenslauf — erstelle einen Lebenslauf und ein Anschreiben, die genau auf diese Rolle zugeschnitten sind.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Stock options
Remote-first environment

Zusammenfassung

XBOW is seeking an Information Security Analyst, GRC to scale its security and trust function. You’ll support customers, assess vendor risk, review contracts with legal, and help align with SOC 2, ISO 27001, and GDPR requirements.

The role is an individual contributor with potential growth as the risk function matures. You will collaborate with IT, Security, Engineering, Legal, Sales, and Customer teams to communicate XBOW’s security posture and regulatory readiness.

Qualifikationen

  • 7+ years of experience in risk, compliance, security assurance, or related roles.
  • Hands-on experience in technical roles (Engineering, IT, or security).
  • Experience completing or reviewing security questionnaires and risk assessments.
  • Familiar with SOC 2, ISO 27001, NIST, GDPR, HIPAA frameworks.
  • Experience with vendor/third-party risk assessments.
  • Strong written communication; able to explain security concepts clearly.
  • Organized, detail-oriented, pragmatic approach to risk.

Aufgaben

  • Support customers and prospects with security questionnaires, risk assessments, and due-diligence requests.
  • Explain XBOW's security controls, architecture, and compliance posture to Sales and Customer teams.
  • Assess and manage third-party/vendor security risk and reviews of SaaS providers.
  • Investigate alerts and maintain compliance programs using Vanta.
  • Contribute to risk assessment frameworks, methodologies, and documentation.
  • Track remediation of identified risks with internal stakeholders.
  • Support audits, customer reviews, and internal assurance activities.

Kenntnisse

Risk & Compliance
Security Assurance
Technical Security
Vendor Risk Assessments
Security Questionnaires
Written Communication
Attention to Detail
AI Tools Familiarity
Remote Work Experience

Tools

Vanta

Jobbeschreibung

ABOUT XBOW

At XBOW, we’re redefining the future of cybersecurity by building the world's first autonomous pentester, powered by AI. Today, the gold standard for securing software systems is human pentesters, but with the rise of artificial intelligence, we’re stepping up to scale offensive security to meet the ever-growing demand.

AI is transforming the landscape of both cybersecurity and cyberattacks. While millions of people without security expertise are creating software, bad actors are using AI to launch more effective attacks. XBOW fights back with AI-driven superpowers, enabling security teams to stay one step ahead.

What makes XBOW truly unique? Like human experts, it forges creative attacks, adapts its learnings, and continuously works to find vulnerabilities faster than anyone ever could. We’re not only simulating threats— we’re also finding and responsibly disclosing real-world vulnerabilities, ensuring organizations can fix issues before they’re exploited. XBOW isn’t just a tool; it’s a transformative force in the secure development lifecycle.

Backed by Sequoia Capital and a team that includes the creators of GitHub Copilot and GitHub Advanced Security, XBOW is not just keeping up with the times—we’re shaping the future of cybersecurity. Our mission is simple: to defeat the bad actors before they strike, using AI to revolutionize how we approach offensive security.

We’re building something that must be built, and we’re the team to do it. Join us in shaping the next frontier of autonomous security.

YOUR ROLE: INFORMATION SECURITY ANALYST, GRC

We’re looking for a detail-oriented, Information Security Analyst to help scale our security and trust function as we grow. In this role, you’ll play a key part in supporting customer and prospect security reviews, coordinating with legal on reviewing customer contracts, assessing third-party vendor risk, supporting resolution of compliance alerts and continuously improving how we identify and manage risk across the business.

This is an individual contributor role with no initial people-management responsibilities. However, as the risk and compliance function matures, there is a clear opportunity for this role to grow in scope and responsibility.

You’ll work closely with IT, Security, Engineering, Legal, Sales, and Customer teams, acting as a trusted partner in communicating our security posture and ensuring we meet customer and regulatory expectations.

WHAT YOU'LL DO
  • Support customers and prospects by completing technical security questionnaires, risk assessments, and due-diligence requests
  • Partner with Sales and Customer teams to explain XBOW’s security controls, architecture, and compliance posture
  • Assess and manage third-party and vendor security risk, including reviews of SaaS providers and service partners
  • Investigate and resolve alerts to stay compliant with our compliance programmes using the Vanta product.
  • Help maintain and improve risk assessment frameworks, methodologies, and documentation
  • Track and support remediation of identified risks in collaboration with internal stakeholders
  • Contribute to compliance initiatives aligned with frameworks such as SOC 2, FedRAMP 20x, ISO 27001, and ISO 42001
  • Maintain clear, well-structured risk registers, policies, and supporting evidence
  • Coordinate risk management sessions and processes
  • Identify opportunities to streamline and automate risk and compliance processes as the company scales
  • Support audits, customer reviews, and internal assurance activities as needed
SKILLS AND QUALIFICATIONS
ESSENTIAL
  • 7+ years of experience in risk, compliance, security assurance, or related roles
  • Experience in hands-on technical roles for example in Engineering, IT or operational security
  • Hands-on experience completing or reviewing technical security questionnaires and customer risk assessments
  • Familiarity and experience with common security compliance, and data protection frameworks (e.g. SOC 2, ISO 27001, NIST, GDPR, and HIPAA)
  • Experience conducting or supporting vendor / third-party risk assessments
  • Strong written communication skills, with the ability to explain complex security concepts clearly
  • Highly organized and detail-oriented, with a pragmatic approach to risk
  • Comfortable working in a fast-moving, remote-first startup environment
  • Familiar with using modern AI tooling to improve productivity whilst managing risk
ADVANTAGEOUS
  • Experience working in a SaaS or security-focused company
  • Experience handling Subject Access Requests for GDPR
  • Security or risk certifications (e.g. CRISC or CISSP)
  • Knowledge of cloud security best practices
WHAT WE OFFER
  • Compensation & Equity: Competitive salary and meaningful stock options.
  • Growth: Opportunity to learn from and collaborate with top security and AI experts
  • Impact: Work on complex technical challenges that support the foundation of our …
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Cloud Security Engineer at YGO GmbH
Cloud Security Engineer at YGO GmbH

YGO GmbH • Deutschland

Vor Ort
EUR 90.000 - 120.000
Senior Security Engineer, Offensive Security
Senior Security Engineer, Offensive Security

Jobgether • Deutschland

Vor Ort
EUR 119.000 - 170.000
Fully remote
Equity
Learning stipend
+3
Head of Consulting
Head of Consulting

SoSafe • Köln

Vor Ort
EUR 90.000 - 120.000
Flexible hours
33 vacation days
State-of-the-art tech
+2
Founding Backend Engineer(Go)
Founding Backend Engineer(Go)

Cygrid GmbH • Berlin

Vor Ort
Confidential
Founding Team Member Equity
Competitive Compensation
High Autonomy
+1
Corporate Security Engineer
Corporate Security Engineer

Superhuman • Hub

Vor Ort
EUR 90.000 - 150.000
Head of Consulting
Head of Consulting

SoSafe • Deutschland

Vor Ort
EUR 120.000 - 180.000
Flexible hours
33 vacation days
State-of-the-art tech
+5
Sales Development Representative - US
Sales Development Representative - US

Embedded Shishya • Deutschland

Vor Ort
EUR 39.000 - 56.000
Remote work option
Travel opportunities
Competitive pay
Security Engineer - Platform Security
Security Engineer - Platform Security

SpaceXAI • Deutschland

Remote
EUR 87.000 - 224.000
Equity
Medical coverage
401(k) retirement plan
+3
Product Manager - Device & Behavior
Product Manager - Device & Behavior

oscilar • Deutschland

Vor Ort
EUR 90.000 - 140.000
Remote-first culture
Health insurance
Unlimited PTO
+1
Principal Information Security Manager
Principal Information Security Manager

Staffbase • Dresden

Vor Ort
EUR 70.000 - 90.000
Competitive Compensation
Flexible working time models
31 vacation days annually