We are seeking a highly skilled, expert-level Cybersecurity GRC Analyst to provide external services until 31 October 2026. In this role, you will assist the end-to-end preparation and execution of upcoming audits, map technical controls to organizational policies, and provide collaborative support to our security architecture team. The ideal candidate possesses a strong background in traditional security frameworks and regulatory mandates, combined with the technical literacy needed to partner effectively with Security Operations, Engineering and Architecture functions to optimize compliance enforcement.
â Compliance & Frameworks: Assist the control and evidence collection management for key compliance frameworks, notably ISO/IEC 27001, SOC 2, NIS2, BSIG, and DORA.
â Audit: Assist the end-to-end preparation and execution of upcoming external security audits (including ISO/IEC 27001, ISO/IEC 27701, SOC 2).
â Architecture Support & Control Mapping: Partner with technical teams to evaluate cloud and system architectures. Translate governance policies into verifiable technical requirements and assess existing system configurations against corporate security baselines.
â AI Regulatory Control Execution: Partner with legal to translate the EU AI Act and global AI mandates into explicit technical requirements. Assess and validate that internal AI deployments, LLM-driven engineering pipelines, and product integrations conform to these technical compliance standards.
â GRC Engineering: Work with GRC Engineers to design and build automated compliance workflows, custom scripts, and data collection mechanisms to enable continuous control monitoring.
â GRC Platform Utilization.
â Experience: 3+ years in delivering cybersecurity GRC consultancy and 2+ in Engineering, Security Operations, Security Architect or related field
â Regulatory & Standard Expertise: Deep knowledge of ISO/IEC 27001 and SOC 2 frameworks. Comprehensive knowledge of current EU cybersecurity regulations (NIS2, CRA, DORA, EU AI Act) and ISO/IEC 42001. Familiarity with Common Criteria certification concepts and assurance requirements, including EAL4+ or comparable certification expectations, is an advantage.
â Audit Experience: Experience managing end-to-end audit lifecycles.
â Architectural Collaboration: Strong technical literacy to partner effectively with Security Architects, Engineering and Security Operations in evaluating cloud environments, identity architectures and software supply chain components to verify policy alignment
â Project Delivery Focus: Proven ability to onboard autonomously and deliver immediate project value within a defined 6-month timeline. Clear communication skills.
â AI Efficiency: Demonstrated ability to effectively leverage and integrate AI tools into daily workflows
â Open Source Knowledge: Familiarity with open-source software is an advantage
â Cybersecurity Certifications are an advantage.
Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.