Senior GRC Analyst

FYUL•Capon Bridge, WV
•€5,000•Hybrid

About The Position

The Information Security Governance & Assurance function at FYUL is deliberately small and execution-focused. The Cybersecurity Governance & Assurance Manager is responsible for strategy, stakeholder relationships, and cross-functional communication; this senior analyst role, reporting directly to the manager, is responsible for its execution: audits, evidence, vendor security, and the automation of GRC operations. This is an individual-contributor position where professional growth comes from depth of expertise and ownership of outcomes. Printful & Printify hold active ISO 27001 and other certifications. The primary mandate of this role is to maintain and strengthen this certified posture, ensure the continuity of ongoing audit cycles, and extend the same governance standard to additional frameworks as the company's needs evolve.

Requirements

  • 5+ years of experience in cybersecurity GRC, IT audit, or security compliance, including direct hands-on participation in complete ISO 27001 and/or SOC 2 audit cycles, preferably on the industry side.
  • Strong communication and negotiation skills, with the professional confidence to hold a position under pressure from auditors, vendors, and internal stakeholders, and the judgment to know when refusal is the correct response.
  • Demonstrated automation capability: scripts, integrations, GRC platform implementations, or AI-assisted workflows. Software engineering background is not required; a track record of building practical automation is.
  • Self-directed working style with strong ownership: the ability to take ambiguous problems through to completed outcomes with minimal supervision.
  • Excellent written and spoken English.

Nice To Haves

  • Relevant certifications (e.g., ISO 27001 Lead Implementer/Lead Auditor, CISA, CISSP, CISM) are an advantage. Practical audit experience will be weighted more heavily than certification.

Responsibilities

  • Plan and execute internal and external audit activities across ISO 27001, SOC 2, and related frameworks: evidence collection, control readiness, direct communication with external auditors, and follow-through on findings until closure. Represent the function confidently in audit interactions, including the ability to decline inappropriate requests in a professional and well-substantiated manner.
  • Design and implement automation for evidence collection and recurring compliance activities; apply compliance-as-code practices where they deliver measurable value; leverage AI-based agents and workflows to reduce manual effort. Maintain working knowledge of the commercial GRC platform landscape and prefer established industry solutions over custom development.
  • Conduct security assessments of third-party vendors during onboarding and annual reviews, with continuous improvement of the process's efficiency.
  • Maintain the risk register: perform risk assessments, track remediation plans, and ensure timely closure of identified risks.
  • Develop and maintain information security policies and procedures in collaboration with the manager, and contribute to security awareness materials and training delivery.

Benefits

  • Monthly salary EUR 5,000+ gross, depending on work experience, education, and skills
  • A high-trust, compact team with minimal bureaucracy: initiatives move directly from proposal to implementation.
  • An opportunity to work remotely or in a modern and welcoming office in Riga.
  • Flexible working hours (start your day as late as 11 AM).
  • Private health insurance.
  • 2 extra paid days off to focus on your mental or physical well-being.
  • 1 extra paid day off to celebrate a Birthday or any other celebration of your choice.
  • Internal and external learning opportunities.
  • Access to mentorship, internal meetups, and hackathons, both on-site and online.
  • Free and healthy lunch if you work from the Rīga office.
  • Design and order your own merch using our platforms with an employee discount.
  • Exciting team-building events and parties you’ll never forget!
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service