{"id":203533,"url":"https://alion.io/job/oanda-senior-grc-analyst","title":"Senior GRC Analyst","company":{"id":97363,"name":"OANDA","domain":"oanda.com","url":"https://alion.io/company/oanda-2","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Kraków, Poland"],"countries":["PL"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":61000,"max_usd":108000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":17},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"GDPR","optional":false},{"name":"ISO 27001","optional":false},{"name":"NIST CSF","optional":false},{"name":"PCI DSS","optional":false},{"name":"SOC 2","optional":false}],"status":"live","first_seen_at":"2026-07-29T00:00:00Z","employer_posted_date":"2026-07-29","last_verified_at":"2026-09-29T21:49:29Z","board_verified":true,"closed_at":null,"days_open":63,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":63},"description":"Fancy helping to shape the future of FinTech?\nWe have always been innovators. In 1996 we were the first company to share exchange rate information, free of charge on the internet. Today, we are a world leading online trading group.\nJoin us to:\nHelp build the future of online trading \nBe part of a culture driven by integrity and global impact\nBecome part of an award-winning company - check out our full list of awards here\nWe are only as good as our people. Luckily, our people are the best. Join us!\nHow do we work?\nWe implement governance and assurance of the Information Security Program, including the measurement of its adoption, performance, and maturity. We provide oversight of security stakeholders along with their related processes and documentation, ensuring that the Information Security Program is aligned with regulatory requirements, identified security frameworks (NIST CSF, ISO27001:2022), and relevant data protection requirements. In our daily operations, we oversee FTMO Group’s Cyber Risk Management, ensuring that Cyber Risk processes and metrics are seamlessly integrated into the Enterprise Risk Management Framework. We ensure strict compliance with FTMO Group’s internal controls, regulatory requirements, and information security policies and procedures. To achieve this, we work closely with internal audit, compliance teams, external audit firms, and regulatory agencies to provide supportive documentation as applicable.\nThis role is available on a B2B contract basis.\nIn this role, you will:\nTake ownership of the Information Security Program's governance, ensuring alignment with key frameworks like NIST CSF and ISO27001:2022.\n\nQuantify and track cyber risks, seamlessly integrating them into our broader Enterprise Risk Management framework.\n\nStay ahead of the curve by mapping our security program against critical regulatory requirements, including GDPR, DORA, and global Banking Authority guidelines in countries where FTMO Group operates.\n\nChampion our security culture by creating and delivering engaging training materials to defend against threats like malware, phishing, and physical security risks.\n\nAct as the key point of contact for internal and external auditors, responding to regulatory questionnaires and leading the remediation of any security gaps.\n\nStreamline and automate our GRC processes by implementing and supporting modern GRC tools.\n\nWhat skillset do you need to be successful in this role?\n5 to 10 years of hands-on experience specifically in the information security industry.\n\nStrong working knowledge of major security frameworks and standards, such as SOC2, ISO27001, NIST, and PCI-DSS.\n\nDeep understanding of data protection and sectorial regulations, specifically GDPR and DORA.\n\nProven experience performing risk assessments, writing security policies, and managing compliance.\n\nExcellent communication skills to lead security meetings, present clear action plans to senior management, and persuade stakeholders.\n\nNice to have:\nIndustry credentials like CISSP, CRISC, CISA, CISM, or ISO27001 Lead Auditor/Implementer, as well as a relevant university degree.\n\nPrior experience in the financial industry, especially with regulations surrounding leveraged trading products, is a strong plus.\n\n___\nAt OANDA, to help us efficiently process applications, we use AI-driven tools to help source and rank candidates based on professional experience and skills. While these tools provide recommendations, our recruitment process remains human-centric: all final shortlisting and hiring decisions are made by OANDA team. You have the right to request a human review of your application.\nOANDA Global Corporation is a diverse and global team with offices around the world. We value the unique skills and experiences each individual brings to OANDA. We are committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide an inclusive and accessible environment for everyone. Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment and selection process, please let us know. We will work with you to provide as seamless a recruitment experience as possible.\nLearn more about our culture here.\nReview OANDA Privacy Policy and learn more about how we treat your personal data and protect your privacy.","description_format":"text","description_chars":4468,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Blockchain & Crypto","Currency Exchange & FX Payments","Forex & CFD Brokers","Financial Data & Market Intelligence"],"lifecycle":[{"event":"open","at":"2026-09-05T01:27:54Z"}],"liveness":{"score":24,"band":"cold","label":"Long shot","p_open":1,"p_active":0.668,"p_room":0.36,"age_days":62,"expected_fill_days":40,"reasons":["conf:0","velocity","win:tail","crowd:"],"computed_at":"2026-09-29T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/oanda-senior-grc-analyst","json_url":"https://alion.io/job/oanda-senior-grc-analyst.json","meta":{"generated_at":"2026-09-30T04:15:13Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2897,"day_limit":5000,"remaining_today":2103,"minute_limit":60,"resets_at":"2026-10-01T00:00:00Z"}}}