Staff GRC Analyst: Automation & Compliance

Pleo

United Kingdom

Hybrid

GBP 65,000 - 100,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Your own Pleo card
Lunch provided or lunch allowance
Comprehensive private healthcare
Holiday entitlement + public holidays
Hybrid and remote options
Additional holiday days via salary-sac
Mental health & wellbeing support (MyN
Paid parental leave

Job summary

Pleo is seeking a Staff GRC Analyst to join our Information Security team. You will scale compliance programs, automate governance, risk, and control frameworks (ISO 27001, PCI-DSS, DORA, UK Cyber Essentials) and partner with Risk, Compliance, Legal, and Engineering.

You will translate regulatory requirements into technical specs for engineers, automate vendor assessments, and report on KPIs to leadership. We value AI-driven automation, cloud security experience, and a fintech or payments

Qualifications

  • Significant experience in Security GRC and auditing
  • Experience using AI or coding automation for controls
  • Strong understanding of cloud architectures (AWS or equivalent) and mapping to security controls
  • Experience automating reporting for GRC programs (dashboards, exec summaries)
  • Fintech/payments IT audit background and regulatory familiarity
  • Certifications such as CISM/CISSP/CISA/PCI credentials; degree in related field is a plus

Responsibilities

  • Automate governance, risk, and compliance frameworks (ISO 27001, PCI-DSS, DORA, UK Cyber Essentials)
  • Engineer GRC workflows with internal systems to support compliance by design
  • Design scalable GRC architectures and automation for evidence collection and reporting
  • Draft and maintain security policies aligned with control standards
  • Automate security requests from customers and vendors, ensuring accurate responses
  • Automate third-party vendor assessments against security standards and track gaps
  • Track and report compliance metrics and KPIs for leadership visibility
  • Translate compliance requirements into technical specs for engineering teams
  • Coordinate multi-team workstreams and maintain delivery timelines
  • Collaborate with Cybersecurity to support ongoing initiatives

Skills

Security GRC
AI automation
Cloud security (AWS)
GRC reporting automation
Regulatory knowledge (fintech/payments

Education

Certifications: CISM/CISSP/CISA/PCI
Degree in Cybersecurity/Engineering/CS/Math

Job description

Pleo is seeking a Staff GRC Analyst to join our Information Security team. You will scale compliance programs, automate governance, risk, and control frameworks (ISO 27001, PCI-DSS, DORA, UK Cyber Essentials) and partner with Risk, Compliance, Legal, and Engineering.

You will translate regulatory requirements into technical specs for engineers, automate vendor assessments, and report on KPIs to leadership. We value AI-driven automation, cloud security experience, and a fintech or payments

Get your free, confidential resume review.

or drag and drop your file here.