GRC Security Analyst – Information Security

Appfire

United States

Remote

USD 68,000 - 90,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Equity
25 days annual leave
Remote work in Spain
Home office stipend €50/month
Health insurance

Job summary

Appfire, a leading provider of Atlassian apps, seeks a GRC Security Analyst to manage governance, risk and compliance across a fast-growing, globally distributed team. You will collaborate with business owners and vendors to uphold security controls and regulatory requirements.

The role focuses on risk identification, remediation planning, and audit support, ensuring policy compliance and continuous improvement in information security practices across Appfire’s environment.

Qualifications

  • Bachelor’s Degree in Computer Science, Information Security, Engineering, related curriculum, or equivalent experience.
  • 2+ years of experience working in information security risk and/or compliance roles.
  • Knowledge of common Information Security frameworks such as CIS, ISO 27001 & SOC 2.
  • Prior experience with cloud-based security tools, technologies, and controls (AWS, Azure, Heroku, GCP).
  • Ability to work effectively in a fast-paced, high-growth environment.
  • CISA, CISSP or similar security/GRC certifications a plus.

Responsibilities

  • Coordinate and facilitate Appfire’s security governance goals and initiatives.
  • Support sales channels with security questions, assessments, and audits, including controls and risk mitigation.
  • Conduct vendor risk assessments and follow up on findings.
  • Support regulatory and compliance initiatives (ISO 27001, SOC2, GDPR).
  • Identify and track information security policy non-conformities and help develop corrective action plans.
  • Identify and track information security risks, assess impact, and monitor remediation efforts.
  • Track risk acceptances and exceptions and ensure remediation is executed.
  • Monitor audit and risk findings and ensure timely resolution.
  • Support business continuity (BC) and disaster recovery (DR) testing.
  • Perform periodic compliance checks across the organization.
  • Assist integration plans for Appfire acquisitions.
  • Support annual review and updating of security policies and processes.
  • Participate in annual security awareness campaigns.

Skills

2+ years in information security risk
Knowledge of CIS ISO 27001 SOC 2
Strong communication skills
Self-starter with initiative

Education

Bachelor’s Degree in Computer Science, Information Security, or related field

Tools

Amazon AWS
Azure
Heroku
GCP

Job description

GRC Security Analyst - Information Security

At Appfire, we believe that great work happens when people get to choose how they work. After 20 years of creating software that empowers teams to break silos and collaborate seamlessly, we've learned that one size does not fit all. We’re a team of 800+ employees, working remotely across 28 countries. Our flagship products include: JXL, Comala Document Management, 7Pace Time Tracker, Jira Misc Workflow Extensions, and BigPicture.

Here you can read some of our customer stories: https://appfire.com/resources/resource-library/customer-stories

About us

We are Appfire, the largest global provider of award-winning Atlassian apps! Our portfolio of trusted product brands includes more than 200+ purpose-built apps loved by thousands of teams and millions of users worldwide.

Amplified by our partnership and strategic investment from private equity powerhouse Silversmith Capital Partners, a recent surge of marquee brand acquisitions, and an additional $100M investment from TA Associates, Appfire is uniquely poised to accelerate our leadership position within the billion-dollar Atlassian app market.

Come be a part of our Appfire family for this amazing journey! Learn more at appfire.com.

Job Purpose & Overview

Do you have a strong understanding of information security GRC operations? Have you built lasting relationships with business owners and vendors? Appfire, the leading provider of Atlassian apps, is looking for a creative problem-solver and a self-starter to join our Information Security team. The GRC Security Analyst will handle diverse security-related tasks and issues for our rapidly growing company, including managing risk through a shared vision with Appfire’s business leaders.

You’ll work within the GRC department managing diverse governance, risk and compliance security-related tasks and issues for our rapidly growing company, with a focus on people, practices, systems, and metrics. You’ll be asked to keep up with the latest industry requirements and will assist in the identification of security risks and the associated execution of remediation and corrective action plans, ensuring we are following up with those steps previously agreed upon by the business. Additionally, you’ll participate in regular vendor reviews and ensure compliance with Appfire policy, as well as provide ISO 2701 and other audit support. If you’re a highly organized, detail-oriented expert communicator, let’s chat! You will be expected to engage in professional development to maintain continual growth in professional skills and knowledge essential to the position and thrive in a highly collaborative workplace.

Lists (Requirements & Responsibilities)
  • Work on the coordination and facilitation of Appfire’s security governance goals and initiatives
  • Support our sales channels regarding prospect and customer security questions, assessments, and audits, including speaking to technical controls and their alternatives and appropriate risk mitigation
  • Conduct assessments related to vendor risk management and following up on associated findings
  • Provide support for regulatory and compliance initiatives (e.g. ISO 27001, SOC2, GDPR, etc.)
  • Identify, document, and track information security policy related non-conformities and assist in developing and monitoring corrective action plans
  • Assist in identifying & tracking information security risks, assessing impact, and tracking the execution of mitigation plans
  • Assist in tracking information security risk acceptances and exceptions and monitoring the execution of remediation plans
  • Track and ensure adequate and timely resolution to all audit and risk assessment findings/issues relating to information security
  • Assist in the monitoring of business continuity (BC) and disaster recovery (DR) testing
  • Perform periodic compliance checks across the Appfire organization
  • Provide support for the coordination and execution of integration plans for Appfire acquisitions
  • Support the annual review and update of information security related policies and processes
  • Participate in and support annual security awareness campaigns
  • Handle sensitive and/or confidential material and information with suitable discretion
About You:
  • Bachelor’s Degree in Computer Science, Information Security, Engineering, related curriculum, or equivalent experience
  • 2+ years of experience working in information security risk and/or compliance roles
  • Knowledge of common Information Security frameworks such as CIS, ISO 27001 & SOC 2
  • Prior experience with cloud-based security tools, technologies, and controls a plus (e.g, Amazon AWS, Azure, Heroku, GCP)
  • Ability to work effectively within a fast paced, changing environment that is going through high growth
  • A self-starter with the demonstrated ability to take initiative, who can proactively identify issues/opportunities and recommend actions
  • Creative problem solving required
  • Excellent interpersonal and communication skills
  • CISA, CISSP or similar security/GRC focused certifications a plus
Benefits & Perks
  • Equity
  • Every Appfire team member is eligible for company equity, fostering a true sense of ownership and connection to our growth
  • Time Off & Flexibility
  • 25 days of annual leave per calendar year (January–December)
  • Up to 10 unused vacation days may be carried over to the following year and must be used by December 31
  • Reduced summer hours to support better work-life balance
  • Flexible bank holidays, allowing employees to exchange one public holiday for another
  • This role is fully remote within Spain, with the option to work from our Bilbao office whenever preferred
  • Learning & Development
  • Grow with Appfire University — our custom, on-demand learning platform designed to support continuous learning and professional development
  • Health & Wellbeing
  • Private health insurance through IMQ or Adeslas, fully covered by Appfire for enrolled employees
  • Family members may also be added at a discounted rate through payroll deduction
  • €400 gross annual sport allowance for gym memberships, outdoor activities, sports equipment, running gear, and other wellness-related expenses
  • Work-from-Home Support
  • Appfire provides €50 per month to help cover home office and remote work expenses
  • Community & Volunteering
  • Employees receive 3 fully paid volunteering days each year through Appfire Town, our Corporate Social Responsibility (CSR) program supporting local communities
  • Market recognition
  • Appfire has been consistently recognized for company growth, culture, corporate social responsibility, and product excellence and has been included among the Deloitte Technology Fast 500, Inc. Best Workplaces, BuiltIn Best Places to Work, and Inc. 5000. Learn more about our accomplishments, which would not be possible without our team members, partners, and customers: https://appfire.com/awards.
  • Equal Employer Opportunity (EEO)
  • Appfire is an equal opportunity employer and does not discriminate based on race, color, religion, sex (including pregnancy), sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, veteran status, or any other protected characteristic as defined by applicable law. Our commitment extends to all employment practices, including recruitment, hiring, training, promotion, compensation, benefits, and termination
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Site Reliability Engineer – Solution Partners
Site Reliability Engineer – Solution Partners

Appfire • United States

Remote
USD 79,000 - 124,000
Equity
Private health insurance
Gym / sport allowance (€400)
+4
Vice President, Product Management, Platform & Innovation
Vice President, Product Management, Platform & Innovation

Appfire • Burlington (MA)

On-site
USD 240,000 - 360,000
Equity eligibility
Unlimited PTO & 10 holidays
100% company-paid health insurance
+2
Senior Data Analytics Engineer - Data Insights
Senior Data Analytics Engineer - Data Insights

Appfire • United States

Remote
USD 140,000 - 190,000
Equity
Unlimited PTO
10 paid holidays
+6
Tech Lead - Fullstack
Tech Lead - Fullstack

Appfire • United States

Remote
USD 47,000 - 62,000
Company equity
26 paid vacation days
Wellness Days
+5
Senior Field Marketing Manager
Senior Field Marketing Manager

Appfire • United States

Remote
USD 120,000 - 170,000
Equity
Unlimited PTO + CSR days
Health insurance
+2
Senior Product Marketing Manager
Senior Product Marketing Manager

Appfire • United States

Hybrid
USD 120,000 - 180,000
Equity
Unlimited PTO
Health insurance
+3
Senior GRC Specialist
Senior GRC Specialist

Fireworks AI • United States

On-site
USD 110,000 - 150,000
Information Security Lead
Information Security Lead

United States Digital Space LLC • United States

Remote
USD 180,000 - 240,000
Remote work: 100% remote
Equity: generous equity package
Mentorship from top VCs
+6
Senior GRC Engineer
Senior GRC Engineer

Aircall • New York (NY)

On-site
USD 180,000 - 200,000
Competitive salary package & equity
Medical, dental, and vision insurance 100% covered
Unlimited PTO
+2
Senior Information Security Specialist
Senior Information Security Specialist

Secfix • Germany (OH)

Hybrid
EUR 90,000 - 130,000
Remote work
Equity
Mentorship
+7