Hiring.Camp

Security Risk and Compliance Analyst

Auto Store

·

Jul 2, 2026

Location
Oslo, Norway · Nedre Vats, Norway · Stavanger, Norway
Type
Full-time
Department
Legal
Closing date
3 weeks ago
Source
Workday

Description

The Security Risk and Compliance Analyst is the operational engine of AutoStore's Technology Risk and Compliance function, turning frameworks and policies into working processes, maintaining the evidence base for assurance activities, and keeping the compliance position current and visible. Reporting to the CISO, the role works across IT, Legal, Finance, HR, and Product to ensure regulatory and certification obligations are met, controls are documented and evidenced, and employees understand and act on their security responsibilities.  

The Security Risk and Compliance Analyst  works closely with the Senior Risk and Compliance Professional (SRCP) on a day-to-day basis, operating within the frameworks and programme structure the SRCP owns, and escalating material issues to the CISO. AI is a growing part of this role, both as a practical tool for working more effectively, and as a subject area that requires operational support across governance, risk assessment, and awareness. 

Control Assurance and Audit 

  • Maintain control documentation, ownership records, and evidence in line with the framework owned by the SRCP, supporting the assurance and testing cycle, coordinating with control owners, and flagging gaps or discrepancies to the SRCP or CISO as appropriate. 

  • Coordinate IT General Controls (ITGC) and Internal Control over Financial Reporting (ICFR) requirements, maintaining documentation of scope, testing schedules, and results, and acting as the primary operational interface for cybersecurity audit activities, tracking findings to closure. 

  • Own the operational management of the risk exception and control deviation process, intake, documentation, approval tracking, expiry management, and escalation of material exceptions to the CISO. 

Third Party Assurance & Reporting 

  • Execute the supplier assurance programme, issuing questionnaires, tracking responses, maintaining the supplier risk register, and escalating gaps to the CISO, ensuring outcomes feed into third-party risk reporting. 

  • Maintain accurate records across all areas of responsibility, compliance register, control evidence, audit findings, exception log, and supplier outcomes, and contribute timely, structured data to the SRCP’s dashboards and reporting outputs. 

 

  • Proactively flag changes in compliance or assurance status to the SRCP and CISO, and maintain documentation to a standard that supports internal visibility and external audit or regulatory scrutiny. 

AI Governance and Support 

  • Support the SRCP in the operational delivery of AutoStore's AI governance programme, maintaining the AI tools register, coordinating risk assessments of AI tools submitted for approval, tracking assessment outcomes, and keeping records current as the AI landscape evolves. 

  • Monitor the AI obligations inventory maintained by the SRCP, flagging where new tool adoptions, regulatory updates, or business changes may affect AutoStore's compliance position under the EU AI Act or related frameworks. 

  • Apply AI-assisted tools across day-to-day GRC work, compliance tracking, evidence management, risk analysis, and reporting, and contribute practical experience of what works to the SRCP’s broader assessment of AI-assisted GRC capabilities. 

Security Education & Awareness 

  • Lead the design and delivery of AutoStore's security and privacy awareness programme, delivering targeted campaigns (phishing simulations, data handling, access management, AI use, social engineering) in collaboration with HR and Communications, and managing the awareness training platform. 

  • Develop and maintain metrics that measure genuine behavioural change, not just participation, tracking trends in phishing results, training completion, and incident patterns to continuously improve programme targeting and content. 

  • Ensure AI use is a substantive topic within the awareness programme, not a single annual module but an evolving thread that reflects how AI tools are being used across the business, the risks they introduce, and the behaviours AutoStore expects.  

Key Qualifications

Essential

  • Experience in a compliance, GRC, risk, or information security role with hands-on operational delivery responsibilities

  • Familiarity with control frameworks, including documenting, evidencing, and testing controls, and supporting audit activities

  • Strong organisational skills, with the ability to manage multiple concurrent workstreams and maintain accurate records

  • Clear written communication skills, able to translate compliance requirements into plain-language guidance for non-specialists

Desirable

  • ISO 27001 Lead Implementer/Auditor certification, or equivalent

  • Experience delivering security awareness programmes, including phishing simulations

  • Experience with GRC tooling or security awareness training platforms

  • Familiarity with AI governance considerations and the compliance and risk implications of AI tool adoption

We Offer: 

  • A Collaborative and Inclusive Culture where we celebrate and value everyone’s contributions, encouraging diverse perspectives in decision-making.

  • Work-Life Balance & Well-being: We offer 1 hour per week of paid exercise, health insurance, and a generous pension plan, prioritizing your mental and physical well-being.

  • A Creative and Safe Workplace by joining a company experiencing rapid growth, with the stability of being Norway’s first unicorn listed on the Oslo Stock Exchange.

  • International and Supportive Environment within a Norwegian multinational that values collaboration and innovation.

The location for this role is Oslo, Stavanger, or our headquarters in Nedre Vats.

Application deadline: July 26th.  Please note that we review applications continuously—if this opportunity excites you, we encourage you to apply as early as possible! All inquiries are treated confidentially.

If you are applying from outside of Norway please indicate that you will be relocating to be considered.

AutoStore does not accept agency resumes or assistance for this role. Please do not forward resumes to our job's alias or AutoStore employees. AutoStore is not responsible for any fees related to unsolicited resumes. This policy should be respected.

Skills

CybersecurityComplianceISO 27001

Similar Jobs

30

Sr. Research IT Security Risk and Compliance Analyst - Computing Services

Careers @ Carnegie Mellon · Pittsburgh, United States of America

Today

Technology Leadership Program, Risk and Security Analyst (TX)

Vanguard · Dallas, TX, United States of America

Yesterday

Technology Leadership Program, Risk and Security Engineer (TX)

Vanguard · Dallas, TX, United States of America

Yesterday

Technology Leadership Program, Risk and Security Analyst (TX)

Vanguard · Dallas, TX, United States of America

Yesterday

Technology Leadership Program, Risk and Security Engineer (TX)

Vanguard · Dallas, TX, United States of America

Yesterday

AWS Security Risk Specialist, AWS Security, Risk, and Compliance

Amazon

3 days ago

Delivery Consultant - Security, Risk, and Compliance, Professional Services

Amazon

1 week ago

Security Risk and Compliance Analyst II

Jocogov · Olathe, KS, US · Remote, Hybrid, Onsite

1 week ago

C1 - Temporary Promotion - Security Risk and Assurance Manager - Social Security Scotland

Scottish Government Recruitment · Glasgow, United Kingdom, GB · Hybrid

1 week ago

Delivery Consultant - Security, Risk, and Compliance, AWS Professional Services

Amazon

3 weeks ago

Director, Operations and Strategy, Risk and Security

Parsons Corporation · USA VA Chantilly (14291 Park Meadow Dr), United States of America +1 · Hybrid, Remote

3 weeks ago

Delivery Consultant - Security, Risk and Compliance, Professional Services, Professional Services

Amazon

3 weeks ago

Delivery Consultant - Security, Risk, and Compliance, Professional Services, Professional Services

Amazon

3 weeks ago

Delivery Consultant - Security, Risk, and Compliance, Professional Services, Professional Services

Amazon

3 weeks ago

Delivery Consultant - Security, Risk, and Compliance, Professional Services

Amazon

3 weeks ago

Delivery Consultant - Security, Risk and Compliance, Professional Services

Amazon

3 weeks ago

Risk and Security Specialist

Argent Federal Credit Union · Chester, VA

1 month ago

IT Risk and Security Compliance Specialist

Respond.io · Kuala Lumpur, MY

1 month ago

Principal, Global Event Security and Risk Management

Wikimedia Foundation · Remote · Remote

1 month ago

Information Security Centre of Competence / Industrial Cyber Security and Risk Manager (m/f)

Airbus · Blagnac - Wings Campus, France

1 month ago

Security Risk and Audit Specialist - RDT Information Security

Roche · Madrid Osiris, Spain · Hybrid

1 month ago

Information Security Risk and Compliance Analyst

Sunflower Bank · Denver, CO · Hybrid

1 month ago

Information Security Risk and Compliance Analyst

Sunflower Bank · Dallas, TX

1 month ago

Sr Platform Security and Risk Adv (App)

Work at Shell · Bangalore RMZ-ECO WORLD, India

1 month ago

Director IT Risk and Security Management

Depository Trust Company · Tampa, FL, United States, US

1 month ago

Principal Analyst, Security and Risk

Forrester · Singapore Office +1 · Remote

2 months ago

Senior Director, Physical Security, Risk, and Business Management

La2028 · Los Angeles, California, United States

3 months ago

Lead IT Risk and Security Engineer

Depository Trust Company · Jersey City, NJ, United States, US

4 months ago

Lead IT Risk and Security Engineer

Depository Trust Company · Jersey City, NJ, United States, US

4 months ago

IT Risk and Security Engineer

Depository Trust Company · Hyderabad, India

4 months ago