Jobs and Careers
SE

Senior GRC Analyst II, ISO 27001

Sensiba
IrelandRemotefull_timeVerifiedPosted 10 Apr 2026

About the role

Senior GRC Analyst II, ISO 27001

Department: Governance, Risk & Compliance

Employment Type: Full Time

Location: Ireland


Description

The Senior GRC Analyst II – ISO 27001 will serve as a technical leader and subject matter expert focused on ISO 27001 readiness and certification engagements, with deep specialization in ISO 27001 compliance platforms and GRC tooling (e.g., Drata, Vanta, Secureframe, OneTrust, ServiceNow GRC, etc.).

This role is responsible for leading complex ISO 27001 engagements from certification through certification maintenance, driving platform optimization for clients, and serving as a strategic auditor on ISMS design, control analysis, and automation. The Senior Analyst II combines strong technical knowledge of ISO 27001, ITGCs, and cloud environments with hands-on expertise configuring and managing compliance platforms to streamline evidence collection, continuous monitoring, and audit execution.

This individual will lead multiple ISO 27001 engagements simultaneously, mentor junior team members, enhance ISO 27001 methodologies and platform integrations, and strengthen client relationships through proactive, insight-driven auditing. The role plays a critical part in scaling Sensiba’s ISO 27001 practice by improving efficiency, automation, and client experience.

Only candidates in Ireland will be considered at this time.

Key Responsibilities

ISO 27001 Engagement Leadership
  • Lead ISO 27001 readiness engagements, Stage 1 / Stage 2 Certification audits, Surveillance audits, and Recertification audits in accordance with ISO/IEC 27001:2022.
  • Own engagement planning, scoping, timelines, client relationships, and execution across multiple concurrent ISO 27001 clients.
  • Audit clients on ISMS design, control selection, and implementation aligned to ISO 27001 Clauses and Annex A controls and organizational risk context.

Platform Administration & Automation
  • Serve as an internal and external subject matter expert on GRC and compliance automation platforms (e.g., Drata, Vanta, Secureframe, OneTrust, or similar tools) in the context of ISO 27001.
  • Configure and optimize client platform environments, including:
  • ISO 27001 control mapping to Annex A and organizational risk register
  • Evidence workflows and documentation management
  • Automated integrations (cloud providers, ticketing systems, HRIS, code repositories, etc.)
  • Continuous monitoring settings aligned to ISMS objectives
  • Review automated control outputs and exception reporting to ensure audit defensibility.
  • Identify opportunities to improve automation coverage and reduce manual evidence collection.
  • Partner with clients to mature their ISMS operations using platform analytics and reporting.
Technical Control Assessment
  • Review, document, and test IT general controls (logical access, change management, system operations) mapped to ISO 27001 Annex A domains.
  • Evaluate technical and organizational controls within SaaS, cloud-native, and hybrid environments.
  • Assess controls over infrastructure environments (AWS, Azure, GCP), identity management, and DevOps workflows in alignment with ISO 27001 requirements.
  • Validate evidence sufficiency and completeness within compliance platforms to support certification conclusions.
  • Support risk assessment and risk treatment processes central to ISMS implementation.
Client Advisory & Relationship Management
  • Serve as primary point of contact for ISO 27001 clients, including executive-level stakeholders.
  • Present audit findings, risk insights, and general advisory recommendations to client leadership.
  • Provide general advisory to high-growth SaaS and technology clients on building scalable, certification-ready ISMS programs.
  • Support sales and go-to-market efforts for ISO 27001 services, including scoping and technical input on proposals.
Practice Development & Mentorship
  • Mentor junior analysts on ISO 27001 methodology, platform navigation, and control testing best practices.
  • Contribute to the refinement of ISO 27001 templates, testing programs, risk assessment frameworks, and platform playbooks.
  • Identify efficiencies to standardize and scale ISO 27001 engagements across the practice.
  • Support training initiatives to elevate internal ISO 27001 platform expertise.



Skills, Knowledge & Expertise

  • 4+ years of experience in ISO 27001, IT audit, or GRC, preferably within public accounting or consulting.
  • Bachelor’s degree in Information Systems, Computer Scienc

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Sensiba

View company profile →