Hiring.Camp

GRC Analyst

We are hiring!

·

Yesterday

Location
Warsaw, Poland
Workplace
Hybrid
Type
Full-time
Experience
2+ years
Source
Workday

Description

Fancy helping to shape the future of FinTech?
We have always been innovators. In 1996 we were the first company to share exchange rate information, free of charge on the internet. Today, we are a world leading online trading group.


Join us to:

  • Help build the future of online trading 
  • Be part of a culture driven by integrity and global impact
  • Become part of an award-winning company - check out our full list of awards here

We are only as good as our people. Luckily, our people are the best. Join us! 


How do we work?

Hi Everyone!

We build, maintain, and drive the evolution of our Information Security Program - ensuring strong governance, risk management, and regulatory compliance across the organization. From aligning with global frameworks like NIST CSF and ISO27001:2022 to seamlessly integrating Cyber Risk into Enterprise Risk Management, we keep our operations secure, resilient, and audit-ready. Working closely with internal teams, external auditors, and regulatory bodies, we protect our ecosystem while enabling continuous growth.

We work in a hybrid model - we'd love to meet you in the office 2 times a week with respect to your own commitments. 

In this role, you will:

  • Collect and analyze cybersecurity requirements to ensure alignment with GDPR, DORA, ISO27001, and financial regulations.

  • Monitor key controls, KRIs, and KPIs, tracking ongoing cyber risks and supporting remediation plans across teams.

  • Conduct third-party security due diligence, including vendor assessments, security questionnaires, and contract reviews to mitigate supply chain risks.

  • Participate in scheduled control testing, policy reviews, and documentation updates for the security program.

  • Assist in creating engaging training materials to defend employees against malware, phishing, and physical security threats.

  • Help gather supporting evidence for internal/external audits and assist in responding to regulatory questionnaires.

What skillset do you need to be successful in this role?

  • Min. 2 years of experience specifically within Information Security, Risk Management, or GRC, but impact matters more than years.

  • Good working knowledge of major security frameworks (ISO27001, NIST, SOC2, PCI-DSS).

  • Understanding of key regulations, particularly GDPR, DORA, and financial sector standards.

  • Hands-on experience with policy reviews, risk tracking, or control testing.

  • Good analytical and communication skills, with a proactive and solution-oriented mindset.

Nice to have:

  • Knowledge of GRC tools (preferably Vanta).

  • Relevant industry certifications e.g., Security+, ISO27001 Auditor/Implementer, CRISC.

  • Previous involvement in risk management (evaluation, management of risk treatment plans etc.).

  • Prior experience in the Financial Services or Trading industry.

Your perspective matters. We encourage you to apply even if you are hesitant about meeting every single qualification. We are excited to see what you can bring to the team!

___

At OANDA, to help us efficiently process applications, we use AI-driven tools to help source and rank candidates based on professional experience and skills. While these tools provide recommendations, our recruitment process remains human-centric: all final shortlisting and hiring decisions are made by OANDA team. You have the right to request a human review of your application.

OANDA Global Corporation is a diverse and global team with offices around the world. We value the unique skills and experiences each individual brings to OANDA. We are committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide an inclusive and accessible environment for everyone. Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment and selection process, please let us know. We will work with you to provide as seamless a recruitment experience as possible.

Learn more about our culture here.

Review OANDA Privacy Policy and learn more about how we treat your personal data and protect your privacy. 

Skills

CybersecurityRisk ManagementComplianceGDPR

Similar Jobs

30

GRC Analyst

American Tower Global · Boston, MA, United States, US · Hybrid

2 weeks ago

GRC Analyst

Indianapolis & Marion County

2 weeks ago

GRC Analyst

Paxos · Remote - India · Remote

2 weeks ago

GRC Analyst

Mypassglobal · Cebu · Hybrid

1 month ago

GRC Analyst

Zip · San Francisco · Hybrid

1 month ago

GRC Analyst

Northmark · Dallas - Victory Commons, United States of America

1 month ago

GRC Analyst

Fluidstack · New York, NY · Onsite

1 month ago

GRC Analyst

Vercel · Remote - United States +1 · Remote

1 month ago

GRC Analyst

Hempel · India - Pune · Remote

4 months ago

GRC Analyst

Hempel is · India - Pune · Remote

4 months ago

GRC Analyst

Rogo · New York City · Onsite

4 months ago

Senior Staff GRC Analyst - Strategic Account Partner

Diligentcorporation · Vancouver, British Columbia, Canada

Today

Cybersecurity Analyst 1 - GRC

Arizona State University · UNIVERSITY SERVICES, United States of America · Hybrid

2 days ago

Federal Exchange GRC Analyst

Integritymarketing · SSC - Dallas, TX, United States of America

6 days ago

Information Security GRC Analyst III - CISSP preferred

CareSource mission is known as · Dayton, OH, United States of America · Remote

6 days ago

Analyste GRC / GRC Analyst

Explorance · Montreal, Quebec, Canada

6 days ago

GRC & Privacy Analyst

Thriveglobal · Remote (United States) · Remote

6 days ago

Senior Analyst-GRC

Berry Appleman & Leiden · Richardson, TX

6 days ago

Security GRC & AI Analyst

PoloWorks · Cheltenham

1 week ago

User Access Management - SAP GRC Access Control Analyst

Jj · IN004 Bangalore, India +1 · Hybrid

1 week ago

Principal Security GRC Analyst

Rescale · Remote (United States) · Remote

1 week ago

Senior GRC / Third-Party Risk / Data Protection Analyst

Peraton · , US · Remote

1 week ago

Senior Analyst, Enterprise Risk Management (GRC Tool Implementation & Third-Party Risk Focus)

TMX group of companies includes · Toronto - 100 Adelaide St W, Canada · Hybrid, Onsite

1 week ago

Senior GRC Analyst

Preply · Barcelona · Hybrid

1 week ago

Senior GRC Analyst

Preply · London · Hybrid

1 week ago

Senior GRC Analyst

Bcbsla · Remote-LA, United States of America · Remote

1 week ago

GRC, Vulnerability Management Analyst

Acrisure · 1170 Peachtree St Ste 1200 - ATLANTA, GA, United States of America +1

1 week ago

Sr Cybersecurity Analyst - GRC

Dexcom · Manila, Philippines +1

1 week ago

Senior Governance, Risk, and Compliance (GRC) Analyst (Remote)

RainFocus · Orem, UT · Remote

1 week ago

Mid SAP GRC Security Analyst

Encora · Peru

1 week ago