GRC Analyst
Listed on 2026-08-01
-
Security
Cybersecurity, Information Security & Data Protection
Who are we?
MyPass Global is a multi-award-winning workforce compliance software company. Our cutting-edge technology helps companies in high-stakes industries reduce risk, save up to 70% on back-office costs, and create safer work environments through our digital workforce solutions. As we rapidly expand with offices worldwide, we are seeking the next generation of innovative MyPassers to join us in shaping the future of our industry.
Read more about us here
Role OutcomeThe GRC Analyst supports the integrity and currency of MyPass's third-party provider, risk, policy, and CAPA registers, ensuring all entries are reviewed, updated, or progressed to closure on schedule with appropriate evidence. The role supports the Senior Corporate Services Manager's ISMS ownership and audit obligations, and provides broader coordination support across compliance platforms, training campaigns, system access, Google Workspace guidance, and process documentation.
ResponsibilitiesPolicy Register Management
- Monitor the policy lifecycle to ensure review deadlines are met
- Coordinate the policy review and approval process across all business areas
- Publish approved policies in Confluence and Drata
- Maintain the controlled document register, published versions, and master files
- Maintain controlled templates within the master files and Google Gallery
- Coordinate the timely review of risks within Drata
- Support the Senior Corporate Services Manager with risk assessment scheduling, expediting evidence with stakeholders, and preparing documentation for risk closure
- Monitor and report on risk review completion status
- Monitor and report on Drata control readiness, identifying failing or at-risk technical, operational, and people controls
- Create and manage Jira tickets for control issues requiring remediation, coordinating with control owners through to resolution
- Coordinate personnel compliance within Drata, including monitoring onboarding and offboarding status against required time frames
- Maintain the Drata evidence register, ensuring evidence is current, complete, and mapped to the correct controls
- Maintain the third-party provider register covering software vendors, IT service providers, and other third-party providers
- Coordinate vendor due diligence and periodic performance reviews with relevant stakeholders
- Ensure vendor contract records, renewals, and review evidence are current and accurately maintained
- Own the CAPA register within QT9, covering corrective actions arising from ISO audits, risk treatments, and incidents
- Expedite the collection of evidence from stakeholders to support timely CAPA closure
- Prepare and present evidence for review by the Senior Corporate Services Manager prior to closure, flagging any gaps or inconsistencies identified
- Maintain CAPA reporting and manage CAPA workflows end to end
- Support the internal audit programme, providing CAPA status and evidence to the Lead Auditor and internal auditors as required
- Coordinate the rollout of new KnowBe4 training campaigns
- Monitor the validity of training modules to ensure content remains current
- Prepare and distribute KnowBe4 completion and compliance reports
- Coordinate and undertake system access reviews on a rolling schedule across managed platforms
- Support timely remediation of identified access issues with relevant stakeholders
- Provide guidance to users on Google Workspace functionality, including templates and shared drives
- Undertake analysis of user needs for shared drives to inform structure and access decisions
- Provide project support as required across Corporate Services initiatives, including coordination, documentation, and status reporting
- Document GRC standard operating procedures in Confluence, keeping content current as processes evolve
- Support external audit processes, including ISO 27001 certification and surveillance audits
- Maintain documentation, configurations, and evidence in accordance with ISMS requirements
- Demonstrated experience in GRC, risk, or compliance roles within an organisation managing information security or regulatory compliance obligations
- Proven ability to manage and coordinate multiple compliance registers simultaneously, including policy, risk, and corrective action registers
- Demonstrated experience working within a GRC platform such as Drata or equivalent, including control monitoring, evidence management, and compliance reporting
- Demonstrated experience supporting internal or external audit programmes, including evidence preparation and coordination
- Experience managing or coordinating corrective action or CAPA workflows through to closure
- Proven ability to coordinate across multiple business areas to meet compliance…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).