GRC Analyst

OANDA Corporation

Warszawa

Hybrid

PLN 140,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

OANDA Global Corporation is seeking a cybersecurity & GRC professional to lead governance, risk management, and regulatory compliance efforts. You will work with internal teams, auditors, and regulators while maintaining a hybrid work pattern requiring office presence twice weekly.

Ideal candidates have hands-on policy reviews, risk tracking, and vendor due diligence experience, with knowledge of GDPR, ISO27001, NIST, and PCI-DSS.

Qualifications

  • Min. 2 years of experience in Information Security, Risk Management, or GRC.
  • Strong knowledge of security frameworks (ISO27001, NIST, SOC2, PCI-DSS).
  • Understanding regulations like GDPR, DORA, financial standards.
  • Hands-on policy reviews, risk tracking, and control testing.
  • Analytical and proactive communication skills.

Responsibilities

  • Collect and analyze cybersecurity requirements to align with GDPR, DORA, ISO27001, and financial regulations.
  • Monitor controls, KRIs, and KPIs, tracking cyber risks and remediation plans.
  • Conduct third-party security due diligence, vendor assessments, and contract reviews.
  • Participate in control testing, policy reviews, and documentation updates.
  • Assist in creating training materials to defend against malware and phishing.
  • Help gather evidence for audits and respond to regulatory questionnaires.

Skills

Information Security
GRC
Regulatory compliance
Risk assessment
Policy reviews
Vendor due diligence

Tools

Vanta

Job description

Fancy helping to shape the future of FinTech?
We have always been innovators. In 1996 we were the first company to share exchange rate information, free of charge on the internet. Today, we are a world leading online trading group.

Join us to:
  • Help build the future of online trading
  • Be part of a culture driven by integrity and global impact
  • Become part of an award-winning company - check out our full list of awards here

We are only as good as our people. Luckily, our people are the best. Join us!

How do we work?

We build, maintain, and drive the evolution of our Information Security Program - ensuring strong governance, risk management, and regulatory compliance across the organization. From aligning with global frameworks like NIST CSF and ISO27001:2022 to seamlessly integrating Cyber Risk into Enterprise Risk Management, we keep our operations secure, resilient, and audit-ready. Working closely with internal teams, external auditors, and regulatory bodies, we protect our ecosystem while enabling continuous growth.

We work in a hybrid model - we'd love to meet you in the office 2 times a week with respect to your own commitments.

In this role, you will:
  • Collect and analyze cybersecurity requirements to ensure alignment with GDPR, DORA, ISO27001, and financial regulations.
  • Monitor key controls, KRIs, and KPIs, tracking ongoing cyber risks and supporting remediation plans across teams.
  • Conduct third-party security due diligence, including vendor assessments, security questionnaires, and contract reviews to mitigate supply chain risks.
  • Participate in scheduled control testing, policy reviews, and documentation updates for the security program.
  • Assist in creating engaging training materials to defend employees against malware, phishing, and physical security threats.
  • Help gather supporting evidence for internal/external audits and assist in responding to regulatory questionnaires.
What skillset do you need to be successful in this role?
  • Min. 2 years of experience specifically within Information Security, Risk Management, or GRC, but impact matters more than years.
  • Good working knowledge of major security frameworks (ISO27001, NIST, SOC2, PCI-DSS).
  • Understanding of key regulations, particularly GDPR, DORA, and financial sector standards.
  • Hands-on experience with policy reviews, risk tracking, or control testing.
  • Good analytical and communication skills, with a proactive and solution-oriented mindset.
Nice to have:
  • Knowledge of GRC tools (preferably Vanta).
  • Relevant industry certifications e.g., Security+, ISO27001 Auditor/Implementer, CRISC.
  • Previous involvement in risk management (evaluation, management of risk treatment plans etc.).
  • Prior experience in the Financial Services or Trading industry.

At OANDA, to help us efficiently process applications, we use AI-driven tools to help source and rank candidates based on professional experience and skills. While these tools provide recommendations, our recruitment process remains human-centric: all final shortlisting and hiring decisions are made by OANDA team. You have the right to request a human review of your application.

OANDA Global Corporation is a diverse and global team with offices around the world. We value the unique skills and experiences each individual brings to OANDA. We are committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide an inclusive and accessible environment for everyone. Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment and selection process, please let us know. We will work with you to provide as seamless a recruitment experience as possible.

Learn more about our culture here.

Review OANDA Privacy Policy and learn more about how we treat your personal data and protect your privacy.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Analyst
Senior GRC Analyst

OANDA • Kraków

On-site
PLN 180,000 - 280,000
GRC Analyst
GRC Analyst

OANDA TMS Brokers S.A. • Warszawa

Hybrid
PLN 180,000 - 260,000
Senior GRC Analyst
Senior GRC Analyst

OANDA Poland sp. z o.o. • Kraków

On-site
PLN 180,000 - 270,000
Senior Application Security Engineer
Senior Application Security Engineer

oanda • Kraków

On-site
PLN 180,000 - 230,000
Senior Application Security Engineer
Senior Application Security Engineer

OANDA Poland sp. z o.o. • Kraków

On-site
PLN 180,000 - 300,000
Senior Application Security Engineer
Senior Application Security Engineer

OANDA Corporation • Kraków

On-site
PLN 180,000 - 260,000
Team Lead Security Engineer
Team Lead Security Engineer

OANDA Poland sp. z o.o. • Kraków

On-site
PLN 250,000 - 420,000
Associate ITSM Process Specialist
Associate ITSM Process Specialist

oanda • Kraków

On-site
PLN 78,000 - 134,000
Financial Risk Lead
Financial Risk Lead

OANDA TMS Brokers S.A. • Warszawa

Hybrid
PLN 260,000 - 380,000
Associate Software Engineer (React.js, Python)
Associate Software Engineer (React.js, Python)

oanda • Kraków

Hybrid
PLN 110,000 - 150,000