← Back to your search

FundApps

Security GRC Analyst

Security

Employment

Not stated

Level

Not stated

Category

Security
Not doable from Austria

Country assessment

Not doable from Austria because the employer's own board marks it as not remote.

Our assessment is guidance. Confirm arrangements with the employer.

Job description

We are looking for a curious and hands-on Information Security Analyst to help keep FundApps secure, resilient and trustworthy as we continue to grow. This role has a broad scope, as you will work across security operations, access reviews, vulnerability management, supplier assurance, security awareness, audits, incident response, risk management and the day-to-day running of our Information Security Management System.

As an Information Security Analyst, you will help operate and improve the controls that support our ISO 27001 and SOC 2 programmes, while also getting involved in the real security work that happens across a growing SaaS business. You will not be expected to know everything on Day 1, but you will be expected to learn quickly, ask good questions, follow through on details and help make security easier for everyone at FundApps.

Support the operation of FundApps’ ISO 27001 and SOC 2 controls, contributing to every stage from initial evidence collection and control checks through to remediation tracking and comprehensive audit preparation. Assessing our vendors to ensure we accurately identify, evaluate, and mitigate any security risks brought in by outside partners. Partnering with Legal and Revenue to address security questionnaires and RFPs, ensuring our clients and prospects receive accurate, transparent, and timely answers about our security posture.

Organising monthly review meetings. Directing the end-to-end planning of penetration testing campaigns. Supporting security awareness activities, including onboarding, refresher training, phishing reporting and practical guidance for colleagues. Helping improve security documentation and processes so that our controls are easy to follow, repeatable and genuinely useful.

Recurring access reviews across key business systems, checking that permissions are correct and following up when something looks off. Helping maintain FundApps’ Information Security Management System, including security objectives, risk registers, management review inputs and follow-up actions. Working with Engineering, IT, Legal, Finance and People to make security a helpful, trusted partner in the way FundApps builds, buys and operates technology.

This role has a lot of freedom to solve problems in ways that achieve our outcomes and align with our values. You will be expected to take ownership of your work from Day 1, while being supported by experienced members of the Information Security team. To thrive at FundApps, you will need to be comfortable with uncertainty and embrace change as it comes. We value people who take charge of their destiny and help make things better for everyone around them Background: You don't need deep experience with any particular security tool.

We care far more about how you think and work than what you've used before. What matters is that you're genuinely curious: when something doesn't look right, you dig into it rather than accepting the first explanation. You ask questions until you actually understand a situation, rather than settling for a surface-level answer because it's quicker or easier.

You’re comfortable saying "I don't know, let me find out" and you’re comfortable learning new ways of doing things. Hands-on and thorough: You don't settle for the easy or convenient answer. If an access review throws up something odd, or a vulnerability report doesn't quite add up, you'll get into the detail, ask the awkward questions and follow the thread until you genuinely understand what's going on.

Work-with-purpose: You can articulate the value of your own work in the bigger picture. You understand that a third party review isn't just a task, it’s a way to surface risks and it's part of keeping FundApps and its clients safe. You're comfortable with ambiguity and evolving requirements. Have-courage: You're comfortable asking for and giving feedback, and you're not afraid to say "I don't understand this, can you explain it" in front of others.

You participate in debates, brainstorms and team conversations, and you build strong relationships with colleagues across the wider company. Be-transparent: As a company, we value and aspire to transparency at all levels; you'll provide work updates to communicate regularly about progress and blockers and reach out for help when needed. Raise-the-bar: You seek out opportunities to improve our workflows, processes and practices; 1% improvements over time improve things for everyone.

You're the type of person who asks "why do we do it this way?" rather than just following a checklist. Do-more-with-less: You identify and help implement improvements to processes and standards within the team, seek to optimise our workflows, and share ideas for how to automate manual tasks. As a company, we try to minimise meetings (we have meeting-free Wednesdays) and default to asynchronous written communication over long, multiple-person meetings.