Information Security Analyst (GRC Focus) in Berlin, Vermont at PPRO
Explore Related Opportunities
Job Description
- Support and Maintain the ISMS: Contribute to the continuous improvement of PPRO’s Information Security Management System aligned to ISO/IEC 27001:2022.
- Contribute to Compliance & Assurance: Play an active role in the continuous compliance and certification lifecycles for ISO/IEC 27001, PCI-DSS, and other regulatory requirements. You will help keep compliance running smoothly by assisting with continuous control monitoring and automated assurance workflows using tools like Vanta.
- Help Embed Native Security: Collaborate closely with your team and various cross-functional peers (e.g. Engineering, Product) to help embed security controls seamlessly into daily workflows.
- Active Risk Identification: Actively identify risks or security concerns, maintain the risk register and drive risk treatment. You will connect your day-to-day work with PPRO’s overall strategy, working alongside your manager and senior teammates to resolve complex risk treatments.
- Customer-Centric Due Diligence: Support vendor security reviews and customer due diligence. You will consistently consider the customer’s perspective in your tasks to help build trust both internally and externally.
- Deliver Security Awareness: Help design and deliver engaging, data-informed security education and awareness initiatives that encourage a security-first culture across PPRO.
- Contribute to Process Improvements:.Look for ways to improve our current processes by proactively suggesting ideas for automation. You will help experiment with new technologies, including AI, to make our risk insights better and make evidence collection easier.
Core Experience: Solid, hands-on experience supporting an ISMS aligned to ISO/IEC 27001:2022, along with practical exposure to audits, risk management, and control testing.
An Automation Mindset: You look at manual, repetitive compliance tasks and naturally think about how to streamline them. Familiarity with automation platforms, scripting, or tools like Vanta is a strong plus.
Balanced Independence: You are comfortable managing tasks of moderate complexity independently, prioritizing your time effectively, and anticipating issues. You also know when to flag challenges and seek guidance from senior teammates on complex decisions.
Adaptive Communication: You listen actively to understand context and can adapt your communication style to your audience. You are comfortable sharing constructive feedback with peers and translating security concepts into practical insights for developers and other business teams.
Curiosity and Adaptability: You are enthusiastic about expanding both your technical and soft skills. You willingly step out of your comfort zone, accept feedback as a growth opportunity, and adjust your ways of working to accommodate team needs and deadlines.
Business Awareness: You understand the fintech/payments market and competitors, allowing you to connect your day-to-day work to the company's overall business reality.