{"id":1464783,"url":"https://alion.io/job/appfire-grc-security-analyst-information-security-2","title":"GRC Security Analyst - Information Security","company":{"id":9138,"name":"Appfire","domain":"appfire.com","url":"https://alion.io/company/appfire","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":null},"role":"Security","role_family":"Security","seniority":"junior","employment_type":null,"work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":["BG","PL","ES"],"hiring_countries_total":3,"salary":null,"salary_estimate":{"min_usd":23000,"max_usd":64000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":309},"experience_years_min":2,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"GCP","optional":false},{"name":"GDPR","optional":false},{"name":"Heroku","optional":false},{"name":"ISO 27001","optional":false},{"name":"Jira","optional":false},{"name":"SOC 2","optional":false}],"status":"live","first_seen_at":"2026-09-28T16:54:53Z","employer_posted_date":"2026-09-28","last_verified_at":"2026-10-01T16:54:24Z","board_verified":true,"closed_at":null,"days_open":3,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":3},"description":"At Appfire, we believe that great work happens when people get to choose how they work. After 20 years of creating software that empowers teams to break silos and collaborate seamlessly, we've learned that one size does not fit all. We’re a team of 800+ employees, working remotely across 28 countries. Our flagship products include: JXL, Comala Document Management, 7Pace Time Tracker, Jira Misc Workflow Extensions, and BigPicture.\nHere you can read some of our customer stories: https://appfire.com/resources/resource-library/customer-stories\nAbout the role\nWe are Appfire, the largest global provider of award-winning Atlassian apps! Our portfolio of trusted product brands includes more than 200+ purpose-built apps loved by thousands of teams and millions of users worldwide.\nAmplified by our partnership and strategic investment from private equity powerhouse Silversmith Capital Partners, a recent surge of marquee brand acquisitions, and an additional $100M investment from TA Associates, Appfire is uniquely poised to accelerate our leadership position within the billion-dollar Atlassian app market.\nCome be a part of our Appfire family for this amazing journey! Learn more at appfire.com.\nJob Purpose & Overview\nDo you have a strong understanding of information security GRC operations? Have you built lasting relationships with business owners and vendors? Appfire, the leading provider of Atlassian apps, is looking for a creative problem-solver and a self-starter to join our Information Security team. The GRC Security Analyst will handle diverse security-related tasks and issues for our rapidly growing company, including managing risk through a shared vision with Appfire’s business leaders.\nYou’ll work within the GRC department managing diverse governance, risk and compliance security-related tasks and issues for our rapidly growing company, with a focus on people, practices, systems, and metrics. You’ll be asked to keep up with the latest industry requirements and will assist in the identification of security risks and the associated execution of remediation and corrective action plans, ensuring we are following up with those steps previously agreed upon by the business. Additionally, you’ll participate in regular vendor reviews and ensure compliance with Appfire policy, as well as provide ISO 27001 and other audit support. \nIf you’re a highly organized, detail-oriented expert communicator, let’s chat! \nYou will be expected to engage in professional development to maintain continual growth in professional skills and knowledge essential to the position and thrive in a highly collaborative workplace. \nLists (Requirements & Responsibilities)\nWork on the coordination and facilitation of Appfire’s security governance goals and initiatives\nSupport our sales channels regarding prospect and customer security questions, assessments, and audits, including speaking to technical controls and their alternatives and appropriate risk mitigation.\nConduct assessments related to vendor risk management and following up on associated findings.\nProvide support for regulatory and compliance initiatives (e.g. ISO 27001, SOC2, GDPR, etc.). \nIdentify, document, and track information security policy related non-conformities and assist in developing and monitoring corrective action plans.\nAssist in identifying & tracking information security risks, assessing impact, and tracking the execution of mitigation plans.\nAssist in tracking information security risk acceptances and exceptions and monitoring the execution of remediation plans.\nTrack and ensure adequate and timely resolution to all audit and risk assessment findings/issues relating to information security.\nAssist in the monitoring of business continuity (BC) and disaster recovery (DR) testing.\nPerform periodic compliance checks across the Appfire organization.\nProvide support for the coordination and execution of integration plans for Appfire acquisitions.\nSupport the annual review and update of information security related policies and processes.\nParticipate in and support annual security awareness campaigns.\nHandle sensitive and/or confidential material and information with suitable discretion.\nAbout You:\nBachelor’s Degree in Computer Science, Information Security, Engineering, related curriculum, or equivalent experience.\n2+ years of experience working in information security risk and/or compliance roles.\nKnowledge of common Information Security frameworks such as CIS, ISO 27001 & SOC 2.\nPrior experience with cloud-based security tools, technologies, and controls a plus (e.g, Amazon AWS, Azure, Heroku, GCP)\nAbility to work effectively within a fast paced, changing environment that is going through high growth.\nA self-starter with the demonstrated ability to take initiative, who can proactively identify issues/opportunities and recommend actions.\nCreative problem solving required\nExcellent interpersonal and communication skills\nCISA, CISSP or similar security/GRC focused certifications a plus.\nBenefits & Perks\nEquity\nEvery Appfire team member is eligible for company equity, fostering a true sense of ownership and connection to our growth.\nTime Off & Wellbeing\n26 paid vacation days annually, regardless of tenure\n12 Wellness Days - one fully paid day off each month to recharge, available on an ad-hoc basis and not carried over month to month\n24 hours of paid volunteer time to support meaningful causes outside of work\n3 fully paid volunteering days each year through Appfire Town, our Corporate Social Responsibility (CSR) program supporting local communities\nLearning & Development\nGrow with Appfire University - our custom, on-demand learning platform designed to support continuous learning and professional development.\nHealth & Lifestyle\nPrivate health insurance through UNIQA, fully covered by Appfire Bulgaria\nMultisport Card with access to hundreds of gyms, studios, and swimming pools across Bulgaria, fully paid by Appfie\nFood vouchers via a prepaid Pluxee lunch card with a monthly allowance\nTransportation - Employees in Sofia receive a fully paid Sofia City Transport Card, providing access to all forms of public transportation within the city.\nFamily Support - Employees receive a one-time net Baby Bonus upon the birth of a child.\nFlexibility - This role is fully remote within Bulgaria\nMarket recognition\nAppfire has been consistently recognized for company growth, culture, corporate social responsibility, and product excellence and has been included among the Deloitte Technology Fast 500, Inc. Best Workplaces, BuiltIn Best Places to Work, and Inc. 5000. Learn more about our accomplishments, which would not be possible without our team members, partners, and customers: https://appfire.com/awards.\nEqual Employer Opportunity (EEO) \nAppfire is an equal opportunity employer and does not discriminate based on race, color, religion, sex (including pregnancy), sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, veteran status, or any other protected characteristic as defined by applicable law. Our commitment extends to all employment practices, including recruitment, hiring, training, promotion, compensation, benefits, and termination.","description_format":"text","description_chars":7254,"description_truncated":false,"requirements":{"experience_years_min":2,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Continuous learning","Equity","Health insurance","Paid volunteering days","Professional development"],"hiring_locations":[{"name":"Bulgaria","iso":"BG","kind":"country"},{"name":"Poland","iso":"PL","kind":"country"},{"name":"Spain","iso":"ES","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Information Security","Workflow & Process Automation (RPA, BPM)","Project & Work Management Software","Developer Tools"],"lifecycle":[{"event":"open","at":"2026-09-29T14:25:05Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":2,"expected_fill_days":22,"reasons":["conf:8","velocity","win:early","comp:junior"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/appfire-grc-security-analyst-information-security-2","json_url":"https://alion.io/job/appfire-grc-security-analyst-information-security-2.json","meta":{"generated_at":"2026-10-02T03:26:16Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4746,"day_limit":5000,"remaining_today":254,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}