Senior GRC Analyst

OANDA Corporation

Kraków

On-site

PLN 180,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

OANDA Corporation in Krakow is seeking a Senior GRC Analyst to drive governance and assurance of the Information Security Program. You will ensure alignment with NIST CSF and ISO27001:2022, and support risk measurement and reporting across the enterprise.

You will map GDPR and DORA, create engaging security training, liaise with auditors, and help automate GRC processes using modern tools to strengthen regulatory compliance.

Qualifications

  • 5–10 years of hands-on experience in information security.
  • Strong working knowledge of major security frameworks and standards (SOC2, ISO27001, NIST, PCI-DSS).
  • Experience performing risk assessments and managing compliance.

Responsibilities

  • Take ownership of the Information Security Program's governance and alignment with NIST CSF and ISO27001:2022.
  • Quantify and track cyber risks, integrating them into the Enterprise Risk Management framework.
  • Map security requirements to GDPR, DORA, and global regulatory guidelines.

Skills

NIST CSF & ISO27001 Knowledge
PCI-DSS Knowledge
Risk Assessments & Policy Writing
Communication with Stakeholders

Education

Bachelor's degree in Information Security

Tools

GRC Tools

Job description

## Senior GRC AnalystApplylocations: Krakowtime type: Full timeposted on: Posted Todayjob requisition id: JR000839**Fancy helping to shape the future of FinTech?** We have always been innovators. In 1996 we were the first company to share exchange rate information, free of charge on the internet. Today, we are a world leading online trading group. **Join us to:*** Help build the future of online trading* Be part of a culture driven by integrity and global impact* Become part of an award-winning company - check out our full list of awards here **We are only as good as our people. Luckily, our people are the best. Join us!** ****How do we work?****We implement governance and assurance of the Information Security Program, including the measurement of its adoption, performance, and maturity. We provide oversight of security stakeholders along with their related processes and documentation, ensuring that the Information Security Program is aligned with regulatory requirements, identified security frameworks (NIST CSF, ISO27001:2022), and relevant data protection requirements. In our daily operations, we oversee FTMO Group’s Cyber Risk Management, ensuring that Cyber Risk processes and metrics are seamlessly integrated into the Enterprise Risk Management Framework. We ensure strict compliance with FTMO Group’s internal controls, regulatory requirements, and information security policies and procedures. To achieve this, we work closely with internal audit, compliance teams, external audit firms, and regulatory agencies to provide supportive documentation as applicable.**This role is available on a B2B contract basis.******In this role, you will:***** Take ownership of the Information Security Program's governance, ensuring alignment with key frameworks like NIST CSF and ISO27001:2022.* Quantify and track cyber risks, seamlessly integrating them into our broader Enterprise Risk Management framework.* Stay ahead of the curve by mapping our security program against critical regulatory requirements, including GDPR, DORA, and global Banking Authority guidelines in countries where FTMO Group operates.* Champion our security culture by creating and delivering engaging training materials to defend against threats like malware, phishing, and physical security risks.* Act as the key point of contact for internal and external auditors, responding to regulatory questionnaires and leading the remediation of any security gaps.* Streamline and automate our GRC processes by implementing and supporting modern GRC tools.****What skillset do you need to be successful in this role?***** 5 to 10 years of hands-on experience specifically in the information security industry.* Strong working knowledge of major security frameworks and standards, such as SOC2, ISO27001, NIST, and PCI-DSS.* Deep understanding of data protection and sectorial regulations, specifically GDPR and DORA.* Proven experience performing risk assessments, writing security policies, and managing compliance.* Excellent communication skills to lead security meetings, present clear action plans to senior management, and persuade stakeholders.**Nice to have:*** Industry credentials like CISSP, CRISC, CISA, CISM, or ISO27001 Lead Auditor/Implementer, as well as a relevant university degree.* Prior experience in the financial industry, especially with regulations surrounding leveraged trading products, is a strong plus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC & Cyber Risk Lead for FinTech
Senior GRC & Cyber Risk Lead for FinTech

OANDA Corporation • Kraków

On-site
PLN 180,000 - 230,000
Senior Analyst – Cybersecurity (M&A),SITRM
Senior Analyst – Cybersecurity (M&A),SITRM

FHLB Des Moines • Województwo małopolskie

Hybrid
PLN 217,000 - 290,000
Professional development opportunities
Collaborative culture
Hybrid work model
Senior GRC Analyst: FinTech Security & Compliance Architect
Senior GRC Analyst: FinTech Security & Compliance Architect

OANDA Poland sp. z o.o. • Kraków

On-site
PLN 180,000 - 270,000
Senior GRC Analyst
Senior GRC Analyst

OANDA • Kraków

On-site
PLN 180,000 - 240,000
Head of Software Engineering
Head of Software Engineering

OANDA Corporation • Warszawa

Hybrid
PLN 700,000 - 1,000,000
Head of Information Security and Compliance
Head of Information Security and Compliance

PulseRise Technologies LTD • Warszawa

Hybrid
PLN 400,000 - 640,000
Finance Systems Manager
Finance Systems Manager

IG Group • Kraków

Hybrid
PLN 250,000 - 340,000
Head of Information Security and Compliance
Head of Information Security and Compliance

PulseRise Technologies • Warszawa

Hybrid
PLN 320,000 - 520,000
Hybrid work
Lead Security Engineer
Lead Security Engineer

OANDA Corporation • Kraków

On-site
PLN 200,000 - 320,000
Director, Financial Crime - Cracow, Poland
Director, Financial Crime - Cracow, Poland

AML RightSource, LLC. • Kraków

On-site
Comprehensive private medical healthcare
Remote work options
Group private insurance plan
+2