Vendor Risk and GRC Analyst
Tech Stack / Keywords
Firma i stanowisko
Patrianna is a fast-scaling product development company headquartered in Gibraltar. The company operates at the intersection of technology and entertainment, building innovative solutions shaping the future of social gaming and delivering experiences to millions of players worldwide.
Wymagania
- Proven track record in GRC, IT audit, vendor risk, or information security with hands-on third-party/supplier risk responsibility.
- Practical experience running vendor due diligence, security questionnaires (SIG, CAIQ, or equivalent), and contractual risk review.
- Working knowledge of ISO/IEC 27001:2022 supplier controls, ISO 31000, and GDPR processor obligations; familiarity with DORA third-party requirements is a plus.
- Independent thinker who understands the why behind controls, identifies gaps, and proposes improvements.
- Pragmatic compliance mindset balancing rigor with momentum.
- Precise and confident writing skills for questionnaires, risk memos, and supplier-facing responses.
Nice to have:
- Experience in iGaming, fintech, or other regulated sectors.
- Exposure to TPRM/GRC platforms such as OneTrust, ProcessUnity, Whistic, CISO Assistant.
- Certifications like ISO 27001 Lead Implementer/Auditor, CTPRP, CIPP/E, CISA, or CRISC.
- Familiarity with SOC 2 Type II or PCI-DSS supplier scoping.
Obowiązki
Third-Party Risk (Champion):
- Own the full vendor risk lifecycle including due diligence, security questionnaires, risk rating, contractual safeguards (DPAs, security schedules), and ongoing monitoring.
- Maintain the supplier register and drive reassessment cadence based on criticality.
Supplier Assurance:
- Track fourth-party dependencies and concentration risk across critical suppliers.
- Align oversight with DORA ICT third-party requirements and ISO 27001 supplier controls.
ISMS & Audit Readiness:
- Support policy maintenance, control mapping, and evidence collection to keep the Statement of Applicability (SoA) current and audit-ready.
Risk Management & RCSA:
- Execute risk assessments using an ISO 31000-aligned methodology.
- Contribute to Risk & Control Self-Assessment workshops and remediation tracking.
Privacy Operations:
- Support RoPA maintenance, DPIAs, and data subject requests with a focus on processor and controller arrangements with vendors and group entities.
Governance Reporting:
- Prepare third-party risk materials for governance committees.
- Keep registers accurate, visible, and current.
Benefity
- Autonomy to shape third-party risk management.
- Opportunity to work alongside infrastructure, security, procurement, and product teams.
- Support from a GRC & Assurance Manager encouraging initiative and independent thinking.
Inne informacje
We hire based on skills, drive, and ideas—nothing else. There are no barriers related to background, gender, age, race, ethnicity, disability, sexual orientation, religion, neurodiversity, or educational path. Candidates from non-traditional career journeys are welcome, valuing diverse perspectives that challenge conventional thinking.
Patrianna
17 aktywnych ofert