GRC Analyst
Job in
London, Greater London, W1B, England, UK
Listed on 2026-09-03
Listing for:
Pleo
Full Time
position Listed on 2026-09-03
Job specializations:
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Job Description & How to Apply Below
About Pleo Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we're changing that. We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike - with a vision to help all businesses ‘go beyond’.The word ‘Pleo’ actually means ‘more than you’d expect’, and living by that mantra has been the secret to our success over the last 10 years.
Now, we’re at a pivotal moment in our journey; every move we make has a direct impact on our 40,000+ customers, our business, and our collective success. We need people who take pride in uncovering customer needs, who turn complex problems into simple solutions, challenge the way things are done (respectfully), and always aim high. With great ambitions driving us forward, we can’t say we’ve got this whole thing figured out.
And frankly, that’s half the fun! What we can say is that we’re a driven, progressive, and, importantly, a kind bunch of 850+ people from over 100 nationalities, all committed to delivering the future of business spending, together.
About the role
We're looking for a Staff GRC Analyst to join our Information Security team this role, you'll help and be part of our governance operating model as we scale compliance. If you're excited about building compliance automation and are passionate about fast-paced scale ups, then this is the opportunity for you!
Who you’ll be working with and reporting toYou’ll report to our VP of Fraud & Security and work closely with teams in Risk and Compliance, Procurement, Legal, Finance, and Engineers. Our team is highly collaborative and dedicated to ensure compliance and security of the business. You’ll also have the chance to partner with teams across the organization to ensure success.
What you’ll be doing
As a Staff GRC Analyst, you will:
Automate our legacy systems relating to governance, risk, and compliance frameworks, including ISO 27001, PCI-DSS, DORA, UK Cyber Essentials and relevant financial services regulations.
Engineer GRC workflows with internal systems (e.g., ticketing, asset management, identity, cloud platforms) to support compliance by design.
Design and build scalable GRC architectures and automation for evidence collection, control testing, and compliance reporting.
Draft, review, and maintain Pleo's security policies, mapping them to relevant control standards and ensuring alignment across frameworks as the business evolves.
Automate incoming security requests from customers and prospects, including questionnaires, one-off questions, review calls, and documentation ensuring responses are accurate, thorough, and reflect our actual security posture.
Automate third-party vendor assessments, evaluating suppliers against Pleo's compliance and security standards and ensuring identified gaps are tracked and resolved.
Automate tracking and report on compliance metrics and KPIs, giving leadership the data-driven visibility they need to understand where the programme stands and where it needs to go.
Translate compliance requirements into technical specifications that engineering teams can implement, and make the same topics accessible to non-technical stakeholders.
Coordinate complex, multi-team work streams, keeping dependencies visible, priorities clear, and delivery on track even when things shift.
Contribute to the broader Cybersecurity team, staying connected with ongoing initiatives and supporting shared goals across the function.
What you bring
You’ll thrive in this role if you have:
Significant experience in Security GRC, understanding of auditing processes, with direct experience in both internal and external audit cycles.
Demonstrated experience using AI and/or coding automation to get controls built, implemented, and operating in practice.
A strong understanding of cloud architectures (AWS or equivalent) and how infrastructure decisions map to security controls and audit evidence.
Experience automating reporting for GRC programs, including dashboards and executive-level summaries.
Fintech, payments industry or IT audit background, with familiarity…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×