Jobs and Careers
CL

Governance, Risk and Compliance Analyst

CloudBees
UKRemotefull_timeVerifiedPosted 17 Mar 2025

About the role

Job Type Full-time Description

About CloudBees


CloudBees enables enterprises to deliver scalable, compliant, and secure software, empowering developers to do their best work. 


Seamlessly integrating into any hybrid and heterogeneous environment, CloudBees is more than a tool—it's a strategic partner in your cloud transformation journey, ensuring security, compliance, and operational efficiency while enhancing the developer experience across your entire software development lifecycle. It allows developers to bring and execute their code anywhere, providing greater flexibility and freedom through fast, self-serve, and secure workflows.

CloudBees supports organizations at every step of their DevSecOps journey, whether using Jenkins on-premise or transitioning software delivery to the cloud. We’re helping customers build the future, today.


About the job


As a GRC Analyst at CloudBees, you will support the global Governance, Risk, and Compliance (GRC) function by assisting in the development and management of security policies, ensuring compliance with regulations, and integrating risk management into business operations. You will work with various stakeholders to help strengthen the organization’s security posture, contributing to audits, assessments, and security framework implementation. Additionally, you'll play a role in promoting security awareness throughout the company and supporting continuous improvement efforts within the GRC program.

If you are a proactive self-starter that is looking to join a fast-growing team, we would love to hear from you.


WHAT YOU'LL DO

  • Conduct risk assessments and support more complex audits under senior guidance.
  • Act as the initial point of contact for GRC issues, handling inquiries and guiding them through the process.
  • Support internal and external audit activities, tracking corrective actions and control deficiencies.
  • Maintain compliance certifications (e.g., ISO 27001, SOC 2) and contribute to certification efforts.
  • Assess third-party security risks through due diligence and vendor evaluations.
  • Contribute to privacy-related compliance efforts, particularly in data protection regulations.
  • Take responsibility for compliance initiatives, ensuring adherence to relevant frameworks and reducing risk exposure.
  • Liaise with business teams on compliance requirements and regulatory impacts.
  • Design and deliver cyber awareness training, as required.
  • Track KPIs related to risk assessments and audits, while identifying trends or issues that require attention. 
  • Track security tasks and milestones in roadmaps, ensuring timely progress.
  • Constructively challenge stakeholders when roadblocks arise, proposing practical solutions.

WHO YOU ARE

  • Minimum 1-3 years of relevant work experience, such as Cyber Risk Analyst, Security Engineer, Developer, IT Auditor, Project Manager, Cyber Security Analyst or Business Analyst.
  • Bachelor’s degree in business, information technology, engineering or relevant field of study
  • Strong Excel and data analysis skills
  • Must possess strong written and oral communication skills, and a practical, common-sense approach to getting things done
  • Experience of identifying technical risks within software development environments.
  • Proactively collaborates with individuals across various teams and keeps stakeholders informed with regular updates, minimizing surprises and ensuring alignment.
  • Ability to manage time and multiple priorities to execute high quality deliverables.
  • Ability to think strategically and execute tactically in a high-energy, fast-paced environment
  • High degree of organization and ability to manage multiple, competing priorities simultaneously
  • Ability to work independently and autonomously.
  • Awareness of relevant privacy regulations and security frameworks such as GDPR, SOC2 and ISO27001.
  • Desirable, CRISC or CISA qualification or any other relevant cyber security qualification.
  • Desirable, awareness of security practices within cloud environments (AWS or GCP) 
  • Desirable, understanding of SDLC and coding practices

WHAT YOU'LL GET

  • Highly competitive benefits and vacation package. 
  • Ability to work for one of the fastest growing companies with some of the most talented people in the industry. 
  • Team outings.
  • Fun, Hardworking, and Casual Environment.
  • Endless Growth Opportunities.

We’re invested in you!


We offer generous paid time off to allow our employees time to rest, recharge and to be present with family and friends throughout the year. At CloudBees, we tru

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CloudBees

View company profile →