About the Role
We are looking for a GRC & Third-Party Risk Analyst to execute and run our governance, risk, and compliance (GRC) and third-party risk management (TPRM) activities within a global, decentralized organization. This is a confirmed individual-contributor role, not a people-management or program-ownership position: we need someone with solid, hands-on experience who can operate autonomously on day-to-day GRC and vendor risk work, escalating or seeking support on the most complex cases, while working within a broader team and reporting into GRC leadership. The ideal candidate brings good practical experience across security frameworks and regulatory compliance, and demonstrated experience directly handling external supplier and vendor risk in multi-jurisdictional environments.
Key Responsibilities
- Execute day-to-day GRC activities: risk assessments, control testing, policy reviews, gap analyses, and compliance monitoring, ensuring alignment with international security frameworks and regulatory obligations.
- Conduct end-to-end third-party / vendor risk assessments, including due diligence reviews, security questionnaires, risk scoring, contractual security requirement checks, and ongoing monitoring of external suppliers.
- Assess and document compliance with DORA, NIS2, the EU AI Act, and GDPR, tracking regulatory developments and flagging gaps or required remediation actions to stakeholders.
- Maintain and support the organization's alignment with recognized frameworks such as ISO 27001/27005, NIST CSF/800-53, and PCI DSS, including preparing evidence and supporting audits and certification cycles.
- Evaluate risks related to emerging and intrusive technologies, including AI/ML systems, applying existing governance frameworks and contributing risk analysis and recommendations.
- Work directly with stakeholders across a globally distributed, decentralized architecture, adapting GRC and TPRM practices to different business units and regions.
- Prepare clear, accurate risk assessment reports, findings, and remediation recommendations for review by GRC leadership and business stakeholders.
- Support incident response and business continuity activities from a risk and compliance perspective, particularly where third parties are involved.
- Contribute to the maintenance and improvement of GRC/TPRM processes, templates, and documentation.
- Respond to internal and external audit requests, providing accurate documentation and evidence as needed.
- Maintain and update the organization's risk register, ensuring risks are accurately logged, scored, tracked, and reviewed on an ongoing basis.
- Develop and follow through on risk mitigation and remediation plans, actively managing risk surface and risk levels over time.
- Contribute to presenting risk exposure, business impact, and mitigation plans to business and security committees, providing clear, actionable input to support decision-making.
- Engage with a wide range of stakeholders and teams — including non-IT/non-security business functions — to gather context, share findings, and drive risk-informed decisions.
- Analyze risks from both a technical and non-technical perspective, providing clarity on how identified risks affect specific business scopes and functions.
- Translate business priorities into security risk terms, articulating the related impacts in language that resonates with both technical and business audiences.
Required Qualifications
Experience
- Minimum 2 years of experience in Governance, Risk & Compliance (GRC), in an individual-contributor or analyst capacity.
- Minimum 1 year of experience in risk management directly involving external suppliers and third-party/vendor risk (assessments, due diligence, monitoring).
- Experience working within global organizations with distributed or decentralized architectures, comfortable adapting practices across multiple business units and regions.
- Ability to work autonomously on day-to-day GRC/TPRM cases, escalating the most complex ones, while operating within a team structure (this role does not involve managing people or owning a program).
- Proven experience maintaining and working with a risk register, including risk scoring, tracking, and periodic review.
- Demonstrated experience designing and executing risk mitigation and remediation plans to actively manage risk surface and risk levels.
- Experience contributing risk findings, business impact, and mitigation input to business and security committees.
- Experience collaborating with diverse stakeholders and teams, including non-IT/non-security business units.
- Ability to analyze and communicate risk from both technical and non-technical perspectives, tailored to the audience and business scope in question.
- Experience translating business priorities into security risk considerations and articulating the associated impacts.
Technical & Regulatory Knowledge
- Solid, hands-on working knowledge of major security frameworks: ISO 27001/27005, NIST (CSF, 800-53), PCI DSS.
- Solid, practical knowledge of regulatory requirements including DORA, NIS2, the EU AI Act, and GDPR.
- Solid understanding of AI/ML technologies and associated risks, governance considerations, and management approaches.
Education
- Master's degree required, with a focus on cybersecurity or a closely related field.
Languages
- Bilingual French / English (written and spoken), required.
Certifications
- Relevant security or GRC certifications are a plus but not mandatory.
Preferred Skills & Attributes
- Strong analytical and critical thinking skills, with the ability to work through complex regulatory and technical material.
- Meticulous attention to detail and strong documentation skills.
- Excellent stakeholder communication skills, comfortable engaging with technical teams and business stakeholders (no direct line-management responsibility).
- Strong written and verbal communication skills in both French and English.
- Self-directed, with sound judgment and the ability to prioritize a varied caseload in a fast-evolving regulatory and technological environment.
- Comfortable operating in ambiguity, across time zones, and within a decentralized organizational structure.