Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
payabl.

Senior Governance, Risk and Compliance Engineer

payabl.

. Develop, maintain and continuously improve information security policies, standards and procedures aligned with ISO 27001 and applicable regulatory requirements .

Posted 9/18/2026full-timeRemote • Portugal, Poland, CyprusSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in information security governance, risk management, and compliance with regulatory standards such as ISO 27001, DORA, and GDPR. Proficient in managing audits, vendor risk assessments, and GRC platforms to ensure operational resilience and adherence to industry regulations.

Highest-signal resume keywords
ISO/IEC 27001GRC Platform AdministrationRisk ManagementIT Audit CoordinationCompliance Automation

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Information Security PoliciesRisk IdentificationRisk AssessmentAudit ManagementPolicy DraftingEvidence CollectionControl MonitoringAutomated Evidence CollectionWorkflow AutomationGap Analysis
Soft Skills
Strong Written EnglishTime Management
Tools & Technologies
GRC PlatformsVantaServiceNow GRCOneTrustAI Tools
Certifications & Qualifications
CISACRISCCISMCIPP/EISO 27001 Lead Auditor
Industry Keywords
DORAGDPRPCI DSSFCA Operational ResilienceRegulated Financial Services

Tech Stack

Tools & technologies
AssemblyServiceNow

About the role

Key responsibilities & impact
  • Develop, maintain and continuously improve information security policies, standards and procedures aligned with ISO 27001 and applicable regulatory requirements
  • Manage the full policy lifecycle, including approval workflows, periodic reviews, ownership and version control
  • Maintain the information security risk register, including risk identification, assessment, treatment tracking and formal risk acceptance
  • Prepare risk reporting for management and governance committees and track remediation actions through closure
  • Support compliance activities under DORA, including the Register of Information, PSD2/EBA ICT guidelines, GDPR and PCI DSS across licensed entities
  • Contribute to operational resilience activities for the UK entity in line with FCA requirements
  • Manage the third-party risk management lifecycle, including due diligence, security questionnaires, risk rating, onboarding gates and periodic reassessments
  • Maintain the vendor register and contractual security requirements with the Legal team
  • Coordinate internal and external audits, including Big Four ICT audits, regulator requests and PCI QSA cycles, and manage the audit calendar
  • Own evidence collection and maintain an evidence library for audits, certifications and client questionnaires
  • Administer and develop the GRC platform, including control monitoring, automated evidence collection, framework mapping and reporting
  • Apply AI tools to GRC activities such as policy drafting, gap analysis, evidence assembly and questionnaire responses, and automate recurring processes
  • Contribute to the AI governance programme, including AI vendor assessment, support of the AI system register and alignment with emerging requirements such as the EU AI Act
  • Report to the Head of Information Security

Requirements

What you’ll need
  • 3+ years of similar experience in GRC, information security governance, IT audit or IT risk management
  • Working knowledge of ISO/IEC 27001
  • Exposure to DORA, GDPR or PCI DSS
  • Experience in regulated financial services (payments, e-money, banking, fintech) or advisory work for such companies
  • Hands-on experience with audits, including coordinating audits, preparing evidence and remediating findings
  • Familiarity with GRC platforms or a strong interest in compliance automation
  • Strong written English
  • Ability to manage multiple workstreams against fixed deadlines
  • Certifications such as CISA, CRISC, CISM, CIPP/E or ISO 27001 Lead Auditor / Lead Implementer are nice to have
  • Direct experience with DORA implementation, EBA outsourcing guidelines or FCA operational resilience is nice to have
  • Experience implementing or administering a GRC platform such as Vanta, ServiceNow GRC, OneTrust or similar is nice to have
  • Familiarity with ISO 42001, the EU AI Act or AI risk management is nice to have
  • Light scripting or workflow automation skills using low-code tools are nice to have

Benefits

Comp & perks
  • Annual Learning Budget for professional development (eligible after probation)
  • Company celebrations bringing colleagues from all offices together
  • Opportunities to participate in international company events and initiatives
  • Global collaboration with colleagues from all regions