Staff GRC Analyst

Pleo

Lisboa

Híbrido

EUR 60 000 - 90 000

Tempo integral

Há 5 dias
Torna-te num dos primeiros candidatos

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Vantagens oferecidas por esta oferta de emprego

Pleo card
Lunch allowance
Private healthcare
Holiday entitlement (25–28 days)
Hybrid/remote work options
Parental leave
Mental health support

Resumo da oferta

Pleo is hiring a Staff GRC Analyst to join our Information Security team as we scale compliance. You’ll help automate governance, risk and compliance processes and partner with Risk, Compliance, Legal, Finance and Engineering to ensure security across the business.

You’ll work on translating regulatory requirements into technical specs, designing scalable GRC architectures, and building automation for evidence collection and control testing in a fast-paced fintech environment.

Qualificações

  • Significant experience in Security GRC, understanding of auditing processes, with direct experience in both internal and external audit cycles.
  • Demonstrated experience using AI and/or coding automation to get controls built, implemented, and operating in practice.
  • A strong understanding of cloud architectures (AWS or equivalent) and how infrastructure decisions map to security controls and audit evidence.
  • Experience automating reporting for GRC programs, including dashboards and executive‑level summaries.
  • Fintech, payments industry or IT audit background, with familiarity with regulatory expectations and payment platform architectures.
  • Certifications such as CISM, CISSP, CISA, or PCI‑related credentials. A degree in Cybersecurity, Engineering, Computer Science, or equivalent experience is a plus.

Responsabilidades

  • Automate our legacy systems relating to governance, risk, and compliance frameworks, including ISO 27001, PCI-DSS, DORA, UK Cyber Essentials and relevant financial services regulations.
  • Engineer GRC workflows with internal systems (e.g., ticketing, asset management, identity, cloud platforms) to support compliance by design.
  • Design and build scalable GRC architectures and automation for evidence collection, control testing, and compliance reporting.
  • Draft, review, and maintain Pleo's security policies, mapping them to relevant control standards and ensuring alignment across frameworks as the business evolves.
  • Automate incoming security requests from customers and prospects, including questionnaires, one-off questions, review calls, and documentation ensuring responses are accurate, thorough, and reflect our actual security posture.
  • Automate third‑party vendor assessments, evaluating suppliers against Pleo's compliance and security standards and ensuring identified gaps are tracked and resolved.
  • Automate tracking and report on compliance metrics and KPIs, giving leadership the data‑driven visibility they need to understand where the programme stands and where it needs to go.
  • Translate compliance requirements into technical specifications that engineering teams can implement, and make the same topics accessible to non‑technical stakeholders.
  • Coordinate complex, multi‑team workstreams, keeping dependencies visible, priorities clear, and delivery on track even when things shift.
  • Contribute to the broader Cybersecurity team, staying connected with ongoing initiatives and supporting shared goals across the function.

Conhecimentos

Security GRC
Auditing
AI automation
Cloud security
GRC reporting
Fintech IT audit
Certifications (CISM CISSP CISA PCI)
Cybersecurity degree

Formação académica

Bachelor's degree in Cybersecurity/CS/Engineering

Descrição da oferta de emprego

About Pleo

Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we're changing that. We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike - with a vision to help all businesses ‘go beyond’. The word ‘Pleo’ actually means ‘more than you’d expect’, and living by that mantra has been the secret to our success over the last 10 years. Now, we’re at a pivotal moment in our journey; every move we make has a direct impact on our 40,000+ customers, our business, and our collective success. We need people who take pride in uncovering customer needs, who turn complex problems into simple solutions, challenge the way things are done (respectfully), and always aim high. With great ambitions driving us forward, we can’t say we’ve got this whole thing figured out. And frankly, that’s half the fun! What we can say is that we’re a driven, progressive, and, importantly, a kind bunch of 850+ people from over 100 nationalities, all committed to delivering the future of business spending, together.



About The Role

We're looking for a Staff GRC Analyst to join our Information Security team at Pleo. In this role, you'll help and be part of our governance operating model as we scale compliance. If you're excited about building compliance automation and are passionate about fast-paced scale ups, then this is the opportunity for you!



Who You’ll Be Working With And Reporting To

You’ll report to our VP of Fraud & Security and work closely with teams in Risk and Compliance, Procurement, Legal, Finance, and Engineers. Our team is highly collaborative and dedicated to ensure compliance and security of the business. You’ll also have the chance to partner with teams across the organization to ensure success.



What You’ll Be Doing

As a Staff GRC Analyst, you will:



  • Automate our legacy systems relating to governance, risk, and compliance frameworks, including ISO 27001, PCI-DSS, DORA, UK Cyber Essentials and relevant financial services regulations.

  • Engineer GRC workflows with internal systems (e.g., ticketing, asset management, identity, cloud platforms) to support compliance by design.

  • Design and build scalable GRC architectures and automation for evidence collection, control testing, and compliance reporting.

  • Draft, review, and maintain Pleo's security policies, mapping them to relevant control standards and ensuring alignment across frameworks as the business evolves.

  • Automate incoming security requests from customers and prospects, including questionnaires, one-off questions, review calls, and documentation ensuring responses are accurate, thorough, and reflect our actual security posture.

  • Automate third‑party vendor assessments, evaluating suppliers against Pleo's compliance and security standards and ensuring identified gaps are tracked and resolved.

  • Automate tracking and report on compliance metrics and KPIs, giving leadership the data‑driven visibility they need to understand where the programme stands and where it needs to go.

  • Translate compliance requirements into technical specifications that engineering teams can implement, and make the same topics accessible to non‑technical stakeholders.

  • Coordinate complex, multi‑team workstreams, keeping dependencies visible, priorities clear, and delivery on track even when things shift.

  • Contribute to the broader Cybersecurity team, staying connected with ongoing initiatives and supporting shared goals across the function.



What You Bring

You’ll thrive in this role if you have:



  • Significant experience in Security GRC, understanding of auditing processes, with direct experience in both internal and external audit cycles.

  • Demonstrated experience using AI and/or coding automation to get controls built, implemented, and operating in practice.

  • A strong understanding of cloud architectures (AWS or equivalent) and how infrastructure decisions map to security controls and audit evidence.

  • Experience automating reporting for GRC programs, including dashboards and executive‑level summaries.

  • Fintech, payments industry or IT audit background, with familiarity with regulatory expectations and payment platform architectures.

  • Certifications such as CISM, CISSP, CISA, or PCI‑related credentials. A degree in Cybersecurity, Engineering, Computer Science, Mathematics, or equivalent experience is a plus.



Why is this role a good fit for you

This role is a good fit for you if:



  • You're equally excited about getting into the details of regulations requirements as you are about writing code.

  • You demonstrate high‑agency and like to take initiative in developing solutions that will save the team time.



This role is not a good fit for you if


  • You are not able to work closely with colleagues who do not have an engineering background.

  • You require a well groomed backlog and task assignment in order to perform at your best.



How You’ll Develop In This Role

In your first 6 months at Pleo, you’ll:



  • Get hands‑on with Pleo's security landscape, learning how our GRC programme operates across frameworks like ISO 27001, PCI‑DSS, and DORA.

  • Build automation for evidence collection, control testing, and policy as code within our existing compliance frameworks, and help shape the long‑term security initiatives that support Pleo's growth, working closely with Engineering, Risk & Compliance, and other key stakeholders.

  • Integrate into the Cybersecurity team, connecting with ongoing initiatives, understanding shared goals, and starting to contribute to the workflows and tooling that keep Pleo secure and compliant.



The location

Please note: We can hire on a remote, hybrid or in‑person set‑up in any of the locations listed on the advert but you will need to be physically based in the country of your choice with a valid right to work. We are unable to offer visa sponsorship for this role in any of the listed locations.



Show me the benefits!


  • Your own Pleo card (no more out‑of‑pocket spending!)

  • Lunch is on us for your work days - enjoy catered meals or receive a lunch allowance based on your local office

  • Comprehensive private healthcare - depending on your location, coverage options include Vitality, Alan or Médis

  • We offer 25-28 days of holiday (depending on your location) + public holidays

  • For our Team, we offer both hybrid and fully remote working options

  • Option to purchase 5 additional days of holiday through a salary sacrifice

  • We use MyndUp to give our employees access to free mental health and well‑being support with great success so far

  • Paid parental leave - we want to make sure that we're supportive of families and help you feel that you don't have to compromise your family due to work



Transparency is important to us so we also wanted to share some insights about what we’re looking for in applications to ensure you can set yourself up for success!



  • CV writing and content: we receive a lot of CVs, and many of them are AI‑generated. We love seeing people leverage AI—it’s a big focus for us internally too—but without human intervention, these CVs can sometimes become generic and fail to show a candidate in the best light. What we're really looking for is the specific details of real impact that only you know from your previous experience. A top tip from us is to use the “Achieved X, as measured by Y, by doing Z” formula (credit: Laszlo Bock, :2014) to give a really clear picture of what you’ve worked on. A final note: including links to your previous companies' websites is a huge help and allows us to truly understand your background!

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Lead Security Operations Engineer
Lead Security Operations Engineer

Pleo • Lisboa

Híbrido
EUR 80 000 - 120 000
Private healthcare
Hybrid/Remote options
Lunch allowance
Senior Manager, Onboarding (high-touch customers)
Senior Manager, Onboarding (high-touch customers)

Pleo • Lisboa

Híbrido
EUR 90 000 - 130 000
Pleo Card
Lunch allowance
Private healthcare
+4
Senior Engineering Manager - Decision Intelligence
Senior Engineering Manager - Decision Intelligence

Pleo • Portugal

Híbrido
EUR 110 000 - 140 000
Pleo card benefits
Lunch provided for work days
Private healthcare
+3
Senior Engineering Manager - Decision Intelligence
Senior Engineering Manager - Decision Intelligence

Pleo • Lisboa

Híbrido
EUR 110 000 - 140 000
Your own Pleo card (no more out-of-p0c
Lunch provided or allowance
Comprehensive private healthcare
+4
Senior Applied AI Engineer
Senior Applied AI Engineer

Pleo • Portugal

Híbrido
EUR 90 000 - 120 000
Private healthcare
Hybrid & remote work
Lunch allowance
+2
Strategic Programme Manager - Customer Experience
Strategic Programme Manager - Customer Experience

Pleo • Lisboa

Presencial
EUR 55 000 - 75 000
Strategic CX & Self-Serve Programs Manager
Strategic CX & Self-Serve Programs Manager

Pleo • Lisboa

Presencial
EUR 55 000 - 75 000
Senior Frontend Engineer (Accounting Integrations)
Senior Frontend Engineer (Accounting Integrations)

Pleo • Lisboa

Híbrido
EUR 45 000 - 65 000
Pleo card
Catered lunches or lunch allowance
Comprehensive private healthcare
+5
Fraud Analyst at Pleo Portugal
Fraud Analyst at Pleo Portugal

Ellenco Estágios e Treinamentos • Portugal

Híbrido
EUR 55 000 - 85 000
Hybrid and remote work options
Private healthcare
Lunch allowance
+1
Staff Analytics Engineer
Staff Analytics Engineer

Pleo • Lisboa

Presencial
EUR 90 000 - 130 000