Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior InfoSec GRC Analyst

$127.2k - $205.1k
Full-time

Camunda

Register Here!

Camunda is the enterprise platform for agentic orchestration , enabling organizations to coordinate AI agents, people, and systems across complex, end-to-end business processes. With built-in governance, auditability, and human oversight, Camunda gives enterprises the control they need to move AI from pilots to production — safely and at scale. Trusted by over 700 organizations worldwide , including 9 of top 10 US banks, Camunda helps enterprises boost operational efficiency, accelerate time-to-value, and deliver better customer experiences.

Fully remote and global, we are in the middle of something bigger: transforming into an AI-first organisation, built on our own platform . We use Agentic AI to automate, orchestrate intelligent processes, and elevate human contribution across every team.

Named GP Bullhound’s Top 100 Next Unicorn list, 2025 Great Place to Work certified. Visionary in 2025 Gartner® Magic Quadrant™ for Business Orchestration and Automation Technologies. ranked 3rd in Flexa's 2026 Most Flexible Companies , We’re growing fast and looking for top talent to join our team. If you want meaningful work, visible impact and put something genuinely rare on your CV, keep reading.

About the role:

At Camunda, hundreds of enterprises trust us to orchestrate their most critical business processes, and that trust is something we earn every single day. As our Senior InfoSec GRC Analyst, you will join a small, senior, and highly collaborative InfoSec team that lives our FAITH values (Focus, Ambition, Integrity, Talent and Humor) in everyday work. You will own the governance, risk, and compliance side of our security practice: keeping our ISMS healthy, driving our ISO 27001 and SOC 2 audit cycles, reviewing the security requirements our customers put in front of us, and replacing manual compliance work with automation wherever we can. It is a role with real ownership and plenty of cross functional contact, from Legal and Procurement to IT and our PreSales and PostSales teams, and your work will show up directly in how confidently customers adopt Camunda.

What You’ll Be Doing:

  • Own and continuously improve Camunda's Information Security Management System (ISMS), spotting gaps, closing them, and making measurable improvements rather than just keeping documents current.

  • Drive our security audit cycle for ISO 27001, SOC 2, and future frameworks with minimal supervision, working directly with external auditors and internal control owners to keep evidence, findings, and timelines on track.

  • Review the information security requirements in customer contracts, redline what we cannot realistically meet, and give our negotiators clear, practical recommendations they can act on.

  • Lead responses to complex customer security questionnaires and act as a trusted point of contact for InfoSec topics coming from PreSales, PostSales, and customer security teams.

  • Run and improve our GRC tooling, adding automation and continuous monitoring so compliance evidence is collected once and reused, not rebuilt every audit season.

  • Take ownership of emerging InfoSec compliance topics such as the Cyber Resilience Act and the AI Act: perform gap analysis, translate requirements into concrete work, and partner with Legal, IT, Procurement, and Engineering to get them implemented.

What You Bring:

  • Hands on experience implementing and maintaining ISO 27001 and/or SOC 2 certifications, including managing external audits from evidence gathering through to closing findings.

  • Substantial experience across information security, risk management, and compliance, with a clear focus on Governance, Risk, and Compliance (GRC), ideally gained in a SaaS or cloud software company.

  • Practical experience reviewing information security requirements in customer contracts and leading responses to security questionnaires, with the judgement to tell a real risk apart from a negotiable clause.

  • Experience working with GRC tools, compliance automation, and continuous monitoring, and a genuine preference for automating repetitive work instead of absorbing it.

  • Strong project management and collaboration skills, so you can move several workstreams forward at once across InfoSec, Legal and Compliance, IT, Procurement, and the field teams, and explain security topics clearly to technical and non technical colleagues alike.

  • Ability and/or willingness to use our product

Nice-to-haves:

  • Some software development or scripting ability, including comfort building small tools or automations with AI assisted coding.

  • Experience planning and running business continuity or disaster recovery testing.

  • Familiarity with newer regulatory frameworks such as the Cyber Resilience Act, the AI Act, or NIS2.

  • Experience working in a fully remote, async first organisation.

This role is an existing vacancy

#LI-SG1 #LI-Remote #C1

What We Have to Offer:

Compensation

We offer competitive, fair, and transparent compensation. Salary ranges are location-based, with Standard and Major markets (global tech hubs) reflecting local competition.

The Annual Total Target Cash (base salary + 100% variable target, where applicable) shown below spans from the minimum in a Standard market to the maximum in a Major market. Final offers depend on skills , experience , and location , and we typically hire in the first half of the range to allow room for growth:

  • United States: $127,200.00 to $205,100.00

  • United Kingdom: £79,900.00 to £131,400.00

  • Singapore: S$158,000.00 to S$237,000.00

If you’re based elsewhere, you’ll be hired via Remote.com (our global employer partner), and your Talent Acquisition Partner will provide a personalized Total Rewards Calculator after your first interview.

Equity: We also offer equity (where applicable) through our Virtual Stock Option Plan (VSOP) .

Benefits & Perks

We invest in your wellbeing, growth, and ability to connect, along with perks that support you no matter where you’re based. Our benefits are globally designed and locally delivered where applicable.

  • Remote & Flexible: Work from anywhere with the setup that suits you, home office budget, co-working space support, and flexible time off to recharge when you need it.

  • In Person Connection: We invest in meaningful face time through our Annual Kickoff (Vienna in 2025, Madrid in 2026!), team offsites, and Camundi Connection Budgets , including contributing to meetups while travelling,, and local gatherings with fellow Camundi.

  • Health & Wellbeing: Access locally tailored healthcare, Modern Health for global mental wellbeing, and our Live Well Lifestyle Spending Account (LSA), a flexible, global benefit that puts you in control of your whole life, not just work, from: staying active, to caring for family, exploring personal passions, meaningful experiences, and investing in your financial wellbeing. The Live Well program launches in 2026 and scales to €1,000 annually from 2027 .

  • Financial Security: Retirement and pension plans (often with company contributions), plus life and disability insurance where relevant.

  • Professional Growth: Up to $/€/£1,000 per year for self-driven learning: courses, certifications, books, you decide!

AI in our hiring process : Camunda may use AI tools to aid the screening of applications and during the interview process. You can learn more here

”Everyone is welcome at Camunda” it’s a celebrated component of our culture. We strive to create an inclusive environment that empowers our people. At Camunda, we honour diverse cultures and backgrounds and are proud to be an equal opportunity employer. All qualified applicants will receive consideration without regard to gender, race, ethnicity, religion, belief, sexual orientation, age, disability or any other protected characteristics under applicable law. We are looking forward to your application!

Come join us and be part of Camunda’s incredible journey: Make an impact at a pivotal moment in our story!

Please be aware that scammers may impersonate Camunda by reaching out about job opportunities. Camunda will only contact candidates from an email address ending in @ camunda.com . We will never ask candidates for bank account details, checks, payment, or other sensitive financial information as part of our hiring process. If you receive a suspicious message, please do not respond, click any links, or share personal information.

Note for recruiting and placement agencies: Camunda does not accept unsolicited agency resumes. Please do not forward resumes to our careers site, employees, or any other Camunda contact unless we have specifically engaged your firm for that search. Camunda will not pay fees related to unsolicited resumes.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior InfoSec GRC Analyst in Remote vacancy
  • United States Digital Space LLC is seeking a Senior InfoSec GRC Analyst for a fully remote, international role. You will own governance, risk, and compliance across the ISMS, drive ISO 27001 and SOC 2 audits, and review customer security requirements to enable safe production... 
    Senior
    Remote job

    United States Digital Space LLC

    New York, NY
    2 days ago
  • Ellenco Estágios e Treinamentos is seeking a Senior Information Security GRC Analyst to manage security audits and compliance efforts. The role requires over 10 years of experience in information security and a strong understanding of NIST standards. This position allows... 
    Senior
    Remote job

    Ellenco Estágios e Treinamentos

    New York, NY
    5 days ago
  • AlixPartners in Southfield, MI is looking for an IS GRC Senior Analyst - Risk & Compliance responsible for understanding security risks and compliance requirements. This position offers a hybrid work environment, combining in-office and remote work to support work-life... 
    Senior
    Work at office
    Remote work

    AlixPartners

    Southfield, MI
    5 days ago
  • $80.05k - $165k

     ...end-to-end issue management activities, including intake, validation, prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate evidence, and alignment with audit, risk, and regulatory... 
    Senior
    Full time
    Work at office

    Columbia Bank

    Hillsboro, OR
    5 hours ago
  •  ...including business leaders, technical personnel, audit personnel, senior management, and the board of directors Applies Cybersecurity...  ...operational compliance metrics General Governance, Risk, and Compliance (GRC) Support Leads process analysis, development, & improvement... 
    Senior
    Work experience placement
    Work at office
    Local area
    Remote work
    Relocation

    Blue Cross and Blue Shield of Louisiana

    Louisiana, MO
    1 day ago
  •  ...1 best company for remote workers Responsibilities Workato is seeking a detail-oriented, driven, and technically experienced Senior GRC Analyst to strengthen and advance its security governance, risk, and compliance (GRC) program - with a primary focus on FedRAMP authorization... 
    Senior
    Remote work
    Flexible hours

    Workato

    Palo Alto, CA
    1 day ago
  • DSA is hiring a Senior Information Security Analyst to support an EPA program in the DC Metro area with a hybrid schedule. The role requires onsite...  ...The ideal candidate will advise senior stakeholders on InfoSec initiatives, lead IV&V for ATO packages, and manage risk... 
    Senior
    Remote work

    DSA

    Fairfax, VA
    1 day ago
  • SunSoft Online seeks a GRC / Information Security Analyst for an Arizona state agency. The role is a 4-month contract-to-hire with hybrid work in Phoenix and participation in the State's remote-work program. Key duties include risk assessments, audit reviews, and producing... 
    Permanent employment
    Contract work
    Remote work

    SUNSOFT

    Phoenix, AZ
    5 days ago
  •  ...Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC...  .... What You Will Do As an Experienced or Senior GRC Analyst at Hotman Group you will work directly with clients to help them... 
    Senior
    Permanent employment
    Full time
    Contract work
    Temporary work
    Remote work

    Hotman Group

    Remote
    more than 2 months ago
  • Description The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader IT... 
    Senior
    Work at office
    Remote work

    CMG Financial

    United States
    a month ago
  • Senior GRC Analyst job at Quantexa. New York, NY. What we’re all about. We find, when we come together in the pursuit of excellence, great things happen. And that’s how we do things at Quantexa - together. Our business is data, but our culture is collective. We’re about... 
    Senior
    Contract work
    Temporary work
    Work experience placement
    Immediate start

    Quantexa

    New York, NY
    1 day ago
  •  ...We are seeking a highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team. In this role, you will own and grow RainFocus's governance, risk, and compliance program — maintaining our control framework, leading risk assessments, supporting... 
    Senior
    Full time

    Rainfocus

    Remote
    21 days ago
  • $150k - $200k

     ...Ventures, we are building the infrastructure for the next era of the global economy. Join us! Overview We're hiring a GRC Senior Analyst to help build the compliance foundation powering the future of global crypto payments. At Mesh, we're connecting hundreds of... 
    Senior
    Work at office
    Remote work
    2 days per week

    Mesh

    Remote
    20 days ago
  •  ...duration: through December 2026 with potential to extend About The Role As a member of the Information Security team, the IS GRC Senior Analyst - Risk & Compliance will be responsible for understanding the firm’s security risk and compliance requirements. You will... 
    Senior
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work
    Relocation package
    Monday to Friday

    AlixPartners

    Southfield, MI
    5 days ago
  •  ...C2 Labs is hiring a Senior FedRAMP Consultant (GRC Analyst III equivalent) to act as a lead technical writer for FedRAMP authorization packages and ongoing ConMon operations. If you can translate real-world cloud security implementations into crisp FedRAMP documentation... 
    Senior
    For contractors
    Remote work

    C2 Labs, Inc.

    Knoxville, TN
    6 days ago
  • $57k - $113k

    ## Senior GRC Programmer/AnalystApplyremote type: Officelocations: Columbus, OH: Chicago, IL: Detroit, MI: Tupelo, MS: Charlotte, NCtime...  ...Chicago, IL* Charlotte, NC**Summary:** The Sr GRC Programmer/Analyst modifies existing software/application programs, which are typically... 
    Senior
    Full time
    H1b
    Work at office
    Remote work
    Work from home
    Flexible hours

    Huntington

    Columbus, OH
    2 days ago
  •  ...Description: On-site in either King of Prussia, PA or Denver, PA   Our client is seeking a Senior Cybersecurity Governance, Risk & Compliance (GRC) Analyst to support cybersecurity governance, regulatory compliance, and risk management initiatives within a critical... 
    Senior
    Hourly pay
    Permanent employment
    Full time
    Local area
    Remote work

    Eliassen Group

    King of Prussia, PA
    14 days ago
  • $180k - $215k

     ...zones. Join us on our mission to transform lives by simplifying money, together. The Role: Monarch is seeking a Senior Security GRC Analyst to join our Security team. Reporting to the Manager of Corporate and Infrastructure Security, you'll own the day-to-day... 
    Senior
    Full time
    Contract work
    Work at office
    Immediate start
    Remote work
    Work from home
    Weekend work

    Monarch Money

    Remote
    1 day ago
  •  ...The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within...  ...~3+ years of experience in senior roles with cyber / infosec GRC projects or teams. ~ Proven experience with regulatory... 
    Full time
    Work experience placement
    Work at office

    Iccu

    Remote
    1 day ago
  • $105k - $135k

     ...Join Aya Healthcare, winner of multiple Top Workplace awards! We are seeking a Senior Governance, Risk & Compliance (GRC) Analyst to help operate and mature Aya’s enterprise GRC program, with a strong emphasis on compliance automation, scalability, and operational excellence... 
    Senior
    Full time
    Local area
    Remote work

    Aya Healthcare

    Remote
    1 day ago
  • $100.8k - $168k

     ...automation, and finance leaders to strengthen the control environment and ensure alignment with enterprise priorities. Reporting to the Senior Director of SOX Governance, you will play a key role in enabling compliance strategy, driving insights, and supporting a scalable... 
    Senior

    McKesson

    Irving, TX
    5 days ago
  • $75k - $95k

     ...Type: Full Time NextgenID is hiring a GRC Analyst to do the hands‑on work that keeps our compliance...  ...(for example, CCRA and customer InfoSec assessments) consistent with prior responses...  ...the right person, this is the path to a senior GRC or GRC Lead role. NextgenID focuses... 
    Full time
    For contractors
    Internship
    Local area
    Remote work
    Worldwide

    NextgenID

    Brooklyn, NY
    4 days ago
  • $134k - $202k

     ...our customers, growing our community, or shaping our story, you’ll help define what comes next.About the role:We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance... 
    Work at office
    Remote work
    Work from home
    Worldwide
    Monday to Friday
    Flexible hours

    Vercel

    San Francisco, CA
    4 days ago
  • $65 - $70 per hour

    job summary: The TPRM Continuous Monitoring Analyst is responsible for the ongoing oversight of critical third-party vendors, ensuring...  .... Collaborate with internal subject matter experts (e.g., InfoSec, Privacy, Legal, Compliance, Business Continuity) to validate... 
    Senior
    Hourly pay
    Contract work
    Temporary work
    Work experience placement
    Remote work
    Chicago, IL
    3 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We partner with the world's leading AI research labs to build smarter, safer AI systems - and we need practitioners who know how compliance and risk management actually work in the real... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Worldwide
    Flexible hours

    Alignerr

    Chicago, IL
    5 days ago
  •  ...Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports the Information Technology, Information Systems, and other technology teams aligned under the Chief Information Officer. This role executes governance, risk, and... 
    Work at office
    Remote work

    Trustmark

    United States
    4 days ago
  •  ...Governance, Risk & Compliance (GrC) Analyst We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI — and we need practitioners who know how GRC actually works in the real world. Your expertise in security policies, compliance... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    United States
    4 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, more reliable AI systems - and we need practitioners who know how GRC actually works in the real world. If you've... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Miami, FL
    5 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst Job Category : Information Technology Requisition Number : GOVER001449 Posted : July 1, 2026 Full-Time Hybrid Locations Showing 1 location Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk... 
    Full time
    Casual work
    Work at office
    Work from home
    Home office
    Night shift
    Weekend work

    Delta-Denta

    Saint Louis, MO
    2 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're looking for experienced GRC professionals to help evaluate and improve AI systems being trained on real-world security, compliance, and risk scenarios. Your practitioner knowledge... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    New York, NY
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior InfoSec GRC Analyst. Be the first to apply!