Senior GRC Analyst

OANDA Poland sp. z o.o.

Kraków

On-site

PLN 180,000 - 270,000

Part time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

OANDA Poland sp. z o.o. is seeking a senior information security professional to govern the security program and ensure compliance with major frameworks. You will quantify cyber risks, map controls to GDPR and DORA, and support auditing processes.

Responsibilities include creating training materials, coordinating with auditors, and advancing GRC automation within a global fintech context. Strong communication and policy-writing skills are essential.

Qualifications

  • 5 to 10 years of hands-on information security experience.
  • Strong working knowledge of major security frameworks and standards (SOC2, ISO27001, NIST, PCI-DSS).
  • Deep understanding of data protection and regulatory requirements (GDPR, DORA).
  • Experience performing risk assessments, writing security policies, and managing compliance.
  • Excellent communication to lead security meetings and report to senior management.

Responsibilities

  • Own the Information Security Program governance and ensure alignment with key frameworks.
  • Quantify and track cyber risks and integrate them into the Enterprise Risk Management framework.
  • Map security program against GDPR, DORA, and global Banking Authority guidelines where FTMO Group operates.
  • Create and deliver training materials to defend against threats.
  • Act as the primary contact for internal and external auditors and lead remediation of gaps.
  • Streamline and automate GRC processes by implementing and supporting modern GRC tools.

Skills

Information security governance
Security frameworks (SOC2, ISO27001, N

Tools

GRC tools

Job description

Fancy helping to shape the future of FinTech? We have always been innovators. In 1996 we were the first company to share exchange rate information, free of charge on the internet. Today, we are a world leading online trading group. Join us to: Help build the future of online trading Be part of a culture driven by integrity and global impact Become part of an award-winning company - check out our full list of awards here We are only as good as our people. Luckily, our people are the best. Join us!

How do we work? We implement governance and assurance of the Information Security Program, including the measurement of its adoption, performance, and maturity. We provide oversight of security stakeholders along with their related processes and documentation, ensuring that the Information Security Program is aligned with regulatory requirements, identified security frameworks (NIST CSF, ISO27001:2022), and relevant data protection requirements. In our daily operations, we oversee FTMO Group’s Cyber Risk Management, ensuring that Cyber Risk processes and metrics are seamlessly integrated into the Enterprise Risk Management Framework. We ensure strict compliance with FTMO Group’s internal controls, regulatory requirements, and information security policies and procedures. To achieve this, we work closely with internal audit, compliance teams, external audit firms, and regulatory agencies to provide supportive documentation as applicable.

This role is available on a B2B contract basis.

In this role, you will:
  • Take ownership of the Information Security Program's governance, ensuring alignment with key frameworks like NIST CSF and ISO27001:2022.
  • Quantify and track cyber risks, seamlessly integrating them into our broader Enterprise Risk Management framework.
  • Stay ahead of the curve by mapping our security program against critical regulatory requirements, including GDPR, DORA, and global Banking Authority guidelines in countries where FTMO Group operates.
  • Champion our security culture by creating and delivering engaging training materials to defend against threats like malware, phishing, and physical security risks.
  • Act as the key point of contact for internal and external auditors, responding to regulatory questionnaires and leading the remediation of any security gaps.
  • Streamline and automate our GRC processes by implementing and supporting modern GRC tools.
What skillset do you need to be successful in this role?
  • 5 to 10 years of hands‑on experience specifically in the information security industry.
  • Strong working knowledge of major security frameworks and standards, such as SOC2, ISO27001, NIST, and PCI-DSS.
  • Deep understanding of data protection and sectorial regulations, specifically GDPR and DORA.
  • Proven experience performing risk assessments, writing security policies, and managing compliance.
  • Excellent communication skills to lead security meetings, present clear action plans to senior management, and persuade stakeholders.
Nice to have:
  • Industry credentials like CISSP, CRISC, CISA, CISM, or ISO27001 Lead Auditor/Implementer, as well as a relevant university degree.
  • Prior experience in the financial industry, especially with regulations surrounding leveraged trading products, is a strong plus.

At OANDA, to help us efficiently process applications, we use AI-driven tools to help source and rank candidates based on professional experience and skills. While these tools provide recommendations, our recruitment process remains human-centric: all final shortlisting and hiring decisions are made by OANDA team.

You have the right to request a human review of your application.

OANDA Global Corporation is a diverse and global team with offices around the world. We value the unique skills and experiences each individual brings to OANDA. We are committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide an inclusive and accessible environment for everyone.

Candidates selected for an interview will be contacted directly.

If you require accommodation during the recruitment and selection process, please let us know.

We will work with you to provide as seamless a recruitment experience as possible.

Review OANDA Privacy Policy and learn more about how we treat your personal data and protect your privacy.

OANDA aims to transform all aspects of how the world interacts with currencies, whether that be trading or utilizing currency data and information. We’ll do this our way - connecting and collaborating with the best and most innovative to grow quickly and globally. We strive to do more than just our jobs, focus our actions on collective goals and dare to seek out innovation and creativity. All this to continue our obsession with providing the best experience for our customers. Innovation has been at the heart of everything we do! From our roots in 1997 providing free currency exchange information over the internet to launching an award-winning global trading business. We work together to drive the future of currency data solutions and trading technology. Our customers can invest in around 200 financial instruments including currencies, shares (over 1300) and commodities leveraging intelligent support and the newest technologies. What is more, we are now offering a batch of popular cryptocurrencies in the US! - OANDA is now a major global player. We are proud to be recognized! We put our clients at the heart of our innovation and services, which has earned us some of the most recognized awards in the industry. Most Trusted Broker, Compare Forex Brokers’ Awards, 2025 Best in Class for Mobile Trading Apps, ForexBrokers.com Annual Awards, 2025 Best Forex/CFD Broker in AMER, TradingView Broker Awards, 2024 Broker of the Year 2023, TradingView Broker Awards, 2023

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Analyst
Senior GRC Analyst

OANDA • Kraków

On-site
PLN 180,000 - 240,000
Senior Application Security Engineer
Senior Application Security Engineer

OANDA Corporation • Kraków

On-site
PLN 180,000 - 260,000
Senior Application Security Engineer
Senior Application Security Engineer

OANDA Poland sp. z o.o. • Kraków

On-site
PLN 180,000 - 300,000
Compliance Monitoring Specialist
Compliance Monitoring Specialist

OANDA Poland sp. z o.o. • Kraków

On-site
PLN 120,000 - 170,000
Compliance Monitoring Specialist
Compliance Monitoring Specialist

OANDA Corporation • Kraków

On-site
PLN 90,000 - 130,000
Staff Platform Engineer
Staff Platform Engineer

OANDA Poland sp. z o.o. • Warszawa

On-site
PLN 180,000 - 260,000
Senior Application Security Engineer
Senior Application Security Engineer

oanda • Kraków

On-site
PLN 180,000 - 230,000
Senior Software Engineer (C++)
Senior Software Engineer (C++)

OANDA Poland sp. z o.o. • Kraków

On-site
PLN 180,000 - 240,000
Senior Software Engineer (C++)
Senior Software Engineer (C++)

OANDA Corporation • Kraków

On-site
PLN 250,000 - 360,000
Senior React Native Engineer
Senior React Native Engineer

OANDA Corporation • Kraków

Hybrid
PLN 240,000 - 360,000