GRC Security Analyst - Information Security

Appfire

Spain (TX)

Remote

EUR 45,000 - 65,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Private health insurance
Remote within Spain
Home office stipend

Job summary

Appfire is seeking a GRC Security Analyst to manage governance, risk and compliance tasks within the Information Security team. You will partner with business leaders, maintain security controls, and support audits and regulatory requirements.

You will help identify risks, coordinate remediation, and ensure policy adherence across our rapidly growing, fully remote environment in Spain. A proactive, collaborative communicator will thrive here.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent.
  • 2+ years in information security risk or compliance roles.
  • Knowledge of CIS, ISO 27001, SOC 2.
  • Experience with cloud security tools and controls (AWS/Azure/GCP/Heroku).
  • Ability to navigate fast-growing environments and take initiative.
  • CISA/CISSP or similar certifications are a plus.

Responsibilities

  • Coordinate security governance goals and initiatives.
  • Assist sales with security questions, assessments, audits, and risk mitigation.
  • Conduct vendor risk assessments and track findings.
  • Support regulatory and compliance initiatives (ISO 27001, SOC2, GDPR).
  • Document and monitor information security policy non-conformities and corrective actions.
  • Identify and track information security risks and remediation plans.
  • Monitor audit findings and ensure timely resolutions.
  • Support BC/DR testing and annual security awareness campaigns.
  • Coordinate integration plans for acquisitions.

Skills

Risk management
Compliance
GRC
Vendor risk
Security awareness

Education

Bachelor's degree in CS/InfoSec/Engineering

Tools

AWS
Azure
GCP
Heroku

Job description

At Appfire, we believe that great work happens when people get to choose how they work. After 20 years of creating software that empowers teams to break silos and collaborate seamlessly, we've learned that one size does not fit all. We’re a team of 800+ employees, working remotely across 28 countries. Our flagship products include: JXL, Comala Document Management, 7Pace Time Tracker, Jira Misc Workflow Extensions, and BigPicture.

Here you can read some of our customer stories: https://appfire.com/resources/resource-library/customer-stories

About us

We are Appfire, the largest global provider of award-winning Atlassian apps! Our portfolio of trusted product brands includes more than 200+ purpose-built apps loved by thousands of teams and millions of users worldwide.

Amplified by our partnership and strategic investment from private equity powerhouse Silversmith Capital Partners, a recent surge of marquee brand acquisitions, and an additional $100M investment from TA Associates, Appfire is uniquely poised to accelerate our leadership position within the billion-dollar Atlassian app market.

Come be a part of our Appfire family for this amazing journey! Learn more at appfire.com.

Job Purpose & Overview

Do you have a strong understanding of information security GRC operations? Have you built lasting relationships with business owners and vendors? Appfire, the leading provider of Atlassian apps, is looking for a creative problem-solver and a self-starter to join our Information Security team. The GRC Security Analyst will handle diverse security-related tasks and issues for our rapidly growing company, including managing risk through a shared vision with Appfire’s business leaders.

You’ll work within the GRC department managing diverse governance, risk and compliance security-related tasks and issues for our rapidly growing company, with a focus on people, practices, systems, and metrics. You’ll be asked to keep up with the latest industry requirements and will assist in the identification of security risks and the associated execution of remediation and corrective action plans, ensuring we are following up with those steps previously agreed upon by the business. Additionally, you’ll participate in regular vendor reviews and ensure compliance with Appfire policy, as well as provide ISO 27001 and other audit support.

If you’re a highly organized, detail-oriented expert communicator, let’s chat!

You will be expected to engage in professional development to maintain continual growth in professional skills and knowledge essential to the position and thrive in a highly collaborative workplace.

Lists (Requirements & Responsibilities)
  • Work on the coordination and facilitation of Appfire’s security governance goals and initiatives
  • Support our sales channels regarding prospect and customer security questions, assessments, and audits, including speaking to technical controls and their alternatives and appropriate risk mitigation.
  • Conduct assessments related to vendor risk management and following up on associated findings.
  • Provide support for regulatory and compliance initiatives (e.g. ISO 27001, SOC2, GDPR, etc.).
  • Identify, document, and track information security policy related non-conformities and assist in developing and monitoring corrective action plans.
  • Assist in identifying & tracking information security risks, assessing impact, and tracking the execution of mitigation plans.
  • Assist in tracking information security risk acceptances and exceptions and monitoring the execution of remediation plans.
  • Track and ensure adequate and timely resolution to all audit and risk assessment findings/issues relating to information security.
  • Assist in the monitoring of business continuity (BC) and disaster recovery (DR) testing.
  • Perform periodic compliance checks across the Appfire organization.
  • Provide support for the coordination and execution of integration plans for Appfire acquisitions.
  • Support the annual review and update of information security related policies and processes.
  • Participate in and support annual security awareness campaigns.
  • Handle sensitive and/or confidential material and information with suitable discretion.
About You:
  • Bachelor’s Degree in Computer Science, Information Security, Engineering, related curriculum, or equivalent experience.
  • 2+ years of experience working in information security risk and/or compliance roles.
  • Knowledge of common Information Security frameworks such as CIS, ISO 27001 & SOC 2.
  • Prior experience with cloud-based security tools, technologies, and controls a plus (e.g, Amazon AWS, Azure, Heroku, GCP)
  • Ability to work effectively within a fast paced, changing environment that is going through high growth.
  • A self-starter with the demonstrated ability to take initiative, who can proactively identify issues/opportunities and recommend actions.
  • Creative problem solving required
  • Excellent interpersonal and communication skills
  • CISA, CISSP or similar security/GRC focused certifications a plus.
Benefits & Perks
Equity

Every Appfire team member is eligible for company equity, fostering a true sense of ownership and connection to our growth.

Time Off & Flexibility
  • 25 days of annual leave per calendar year (January–December)
  • Up to 10 unused vacation days may be carried over to the following year and must be used by December 31
  • Reduced summer hours to support better work-life balance
  • Flexible bank holidays, allowing employees to exchange one public holiday for another
  • This role is fully remote within Spain, with the option to work from our Bilbao office whenever preferred
Learning & Development

Grow with Appfire University — our custom, on-demand learning platform designed to support continuous learning and professional development.

Health & Wellbeing
  • Private health insurance through IMQ or Adeslas, fully covered by Appfire for enrolled employees
  • Family members may also be added at a discounted rate through payroll deduction
  • €400 gross annual sport allowance for gym memberships, outdoor activities, sports equipment, running gear, and other wellness-related expenses
Work-from-Home Support

Appfire provides €50 per month to help cover home office and remote work expenses.

Community & Volunteering

Employees receive 3 fully paid volunteering days each year through Appfire Town, our Corporate Social Responsibility (CSR) program supporting local communities.

Market recognition

Appfire has been consistently recognized for company growth, culture, corporate social responsibility, and product excellence and has been included among the Deloitte Technology Fast 500, Inc. Best Workplaces, BuiltIn Best Places to Work, and Inc. 5000. Learn more about our accomplishments, which would not be possible without our team members, partners, and customers:https://appfire.com/awards.

Equal Employer Opportunity (EEO)

Appfire is an equal opportunity employer and does not discriminate based on race, color, religion, sex (including pregnancy), sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, veteran status, or any other protected characteristic as defined by applicable law. Our commitment extends to all employment practices, including recruitment, hiring, training, promotion, compensation, benefits, and termination.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vice President, Product Management, Platform & Innovation
Vice President, Product Management, Platform & Innovation

Appfire • Burlington (MA)

On-site
USD 240,000 - 360,000
Equity eligibility
Unlimited PTO & 10 holidays
100% company-paid health insurance
+2
Tech Lead - Fullstack
Tech Lead - Fullstack

Appfire • United States

Remote
USD 47,000 - 62,000
Company equity
26 paid vacation days
Wellness Days
+5
Senior Data Analytics Engineer - Data Insights
Senior Data Analytics Engineer - Data Insights

Appfire • United States

Remote
USD 140,000 - 190,000
Equity
Unlimited PTO
10 paid holidays
+6
Senior Product Marketing Manager
Senior Product Marketing Manager

Appfire • United States

Hybrid
USD 120,000 - 180,000
Equity
Unlimited PTO
Health insurance
+3
Sales Development Representative
Sales Development Representative

Appfire • New York (NY)

Remote
USD 55,000 - 75,000
Base salary + commission
Equity
Unlimited PTO + 10 holidays
+4
Senior GRC Engineer
Senior GRC Engineer

Aircall • New York (NY)

On-site
USD 180,000 - 200,000
Competitive salary package & equity
Medical, dental, and vision insurance 100% covered
Unlimited PTO
+2
Security Engineer
Security Engineer

Air Apps • San Francisco (CA)

On-site
USD 110,000 - 193,000
Annual Bonus
Medical Insurance (vision & dental)
Disability insurance - short and long‑
+6
Senior Application Security Engineer
Senior Application Security Engineer

Intapp • United States

Remote
USD 140,000 - 190,000
Home office stipend
Equity/Stock in Intapp
Travel to other development centers
+2
Senior GRC Specialist
Senior GRC Specialist

Fireworks AI • United States

On-site
USD 110,000 - 150,000
System Administrator
System Administrator

Air Apps • San Francisco (CA)

On-site
USD 90,000 - 140,000
Apple hardware ecosystem
Annual Bonus
Medical Insurance
+6