GRC Analyst/Consultant

Link Group

Poland

Hybrid

PLN 120,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Link Group in Poland seeks a proactive Cybersecurity GRC Analyst to build core GRC and risk management processes from scratch. You will evaluate security landscape, identify gaps, and translate standards into practical risk methods within ISO/IEC 27001.

The role offers exposure across IT infrastructure, Legal, and leadership, with a focus on designing robust risk assessment methodologies and clear documentation for internal teams.

Qualifications

  • 5+ years in GRC/IS risk or IT compliance.
  • Strong knowledge of ISO/IEC 27001.
  • Experience designing risk methodologies or GRC workflows from the ground up.
  • Excellent analytical skills with attention to detail.
  • Fluent in English, with solid stakeholder management.

Responsibilities

  • Build from scratch the organization's Cybersecurity GRC policies and operating procedures.
  • Map and operationalize end-to-end risk management processes, remediation workflows, and control patterns.
  • Align controls with ISO 27001 standards.
  • Execute risk identification and assessment cycles across assets.
  • Conduct gap analyses against security frameworks to identify vulnerabilities.
  • Maintain the corporate IT/Cyber Risk Register and prioritize remediation.

Skills

GRC experience
ISO/IEC 27001
Analytical mindset
English communication

Job description

About the Opportunity

We are looking for a proactive, hands‑on Cybersecurity GRC (Governance, Risk & Compliance) Analyst to join our team. This is a unique "greenfield" project where you will not just operate within established guidelines, but actively participate in building our core GRC and risk management processes from scratch. If you want a role where your analytical skills will directly shape the company's security posture and framework design, this is the perfect challenge for you.

Core Purpose of the Role

In this position, you will be responsible for evaluating our current security landscape, identifying control gaps, and translating international standards into practical risk processes. Your immediate focus will be supporting the design and roll‑out of a robust risk assessment methodology aligned with the ISO/IEC 27001 framework.

Key Responsibilities
Process Design & Framework Support
  • Build from Scratch: Collaborate on the design, development, and deployment of the organization's corporate Cybersecurity GRC policies and operating procedures.
  • Process Engineering: Help map out and operationalize end‑to‑end risk management processes, remediation workflows, and control patterns.
  • Standard Alignment: Assist in establishing technical and organizational compliance controls aligned with ISO 27001 standards.
Risk Analysis & Mitigation
  • Risk Assessments: Execute comprehensive risk identification and assessment cycles across various business and IT assets.
  • Gap Analysis: Conduct detailed gap analyses against security frameworks to identify vulnerabilities and areas of non‑compliance.
  • Risk Register Management: Own and maintain the corporate IT/Cyber Risk Register, ensuring all identified threats are properly documented, tracked, and prioritized for remediation.
Stakeholder Collaboration & Documentation
  • Cross‑Functional Partnering: Work closely with IT infrastructure teams, Legal, and Business Leaders to ensure compliance requirements are understood and met.
  • Clear Documentation: Translate complex regulatory requirements into plain language, creating clear operating procedures and checkpoints for internal teams.
Required Qualifications & Experience
  • Experience: 5+ years of proven, practical experience in a dedicated GRC Analyst, Information Security Risk, or IT Compliance role.
  • Framework Knowledge: Strong, hands‑on knowledge of the ISO/IEC 27001 standard (familiarity with ISO 27005 or NIST CSF is a strong plus).
  • Proven Track Record: Demonstrable experience in contributing to the design of risk methodologies or implementing GRC workflows from the ground up.
  • Analytical Mindset: Exceptional analytical skills with high attention to detail; able to evaluate complex IT processes and propose pragmatic, risk‑based solutions.
  • Communication: Fluency in English (both written and spoken) with solid stakeholder management skills. You must be able to balance control rigor with business delivery speed.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst: ISO 27001 Risk & Controls Architect
GRC Analyst: ISO 27001 Risk & Controls Architect

Link Group • Poland

Hybrid
PLN 120,000 - 200,000
Security Specialist
Security Specialist

SOFTSWISS • Suchy Las

On-site
PLN 80,000 - 110,000
Private health insurance
Sports benefits
Mental Health Program
+6
GRC - Application Risk Analyst
GRC - Application Risk Analyst

Aristocrat Technologies, Inc. • Poland

On-site
PLN 110,000 - 190,000
Robust benefits package
Global career opportunities
Senior GRC Analyst
Senior GRC Analyst

OANDA Corporation • Kraków

On-site
PLN 180,000 - 230,000
Cybersecurity Risk Manager
Cybersecurity Risk Manager

SEIDOR • Warszawa

On-site
PLN 180,000 - 280,000
Senior Information Security Engineer
Senior Information Security Engineer

Smart Recruitment • Poland

On-site
PLN 85,000 - 120,000
Senior Information Security Engineer
Senior Information Security Engineer

SmartRecruiters • Kraków

On-site
PLN 180,000 - 270,000
Remote Information Security & GRC Analyst
Remote Information Security & GRC Analyst

Scale Up Recruiting Partners • Kraków

On-site
PLN 134,000 - 201,000
Senior Information Security Engineer
Senior Information Security Engineer

SmartRecruiters • Poland

Hybrid
PLN 120,000 - 150,000
Security GRC Specialist: Governance, Risk & Awareness
Security GRC Specialist: Governance, Risk & Awareness

SOFTSWISS • Suchy Las

On-site
PLN 80,000 - 110,000
Private health insurance
Sports benefits
Mental Health Program
+6