Skip to main content
payabl.

Senior Governance, Risk and Compliance Engineer

RemoteCyprus, Poland, Portugal only
Published
Role
Security
Experience
Senior
Employment
Full-time
Salary not disclosed
Check eligibility

Open to CY, PL, PT only. Set where you work from to check your eligibility.

No BS summary

Senior GRC / information security governance specialist with 3+ years in GRC, IT audit or IT risk. Needs ISO 27001 knowledge, exposure to DORA/GDPR/PCI DSS, audit experience, regulated financial services background, and strong written English. Location: Limassol, Cyprus or remote from Poland or Portugal.

Core skills

ISO/IEC 27001GRC

Required skills

DORA/GDPR/PCI DSS

Optional skills

CISACRISCCISMCIPP/EISO 27001 Lead AuditorISO 27001 Lead ImplementerDORAEBA outsourcing guidelines

Required languages

English Strong written

What you'll do

  • Develop, maintain and continuously improve information security policies, standards and procedures aligned with ISO 27001 and regulatory requirements
  • Operate the policy lifecycle: approval workflows, periodic reviews, ownership and version control across the document estate
  • Maintain the information security risk register: risk identification, assessment, treatment tracking and formal acceptance
  • Prepare risk reporting for management and governance committees, and track remediation to closure
  • Support compliance activities under DORA, PSD2/EBA ICT guidelines, GDPR and PCI DSS across licensed entities
  • Contribute to operational resilience work for the UK entity under FCA requirements
  • Run the third-party risk management lifecycle: due diligence, security questionnaires, risk rating, onboarding gates and periodic reassessment
  • Maintain the vendor register and contractual security requirements together with Legal
  • Coordinate internal and external audits, including Big-4 ICT audits, regulator requests and PCI QSA cycles
  • Manage the audit calendar
  • Own evidence collection and maintain an evidence library for reuse across audits, certifications and client questionnaires
  • Administer and develop the GRC platform: control monitoring, automated evidence collection, framework mapping and reporting
  • Apply AI tooling to day-to-day GRC work, including policy drafting, gap analysis, evidence assembly and questionnaire responses
  • Help automate recurring processes
  • Contribute to the AI governance Programme by assessing AI vendors, supporting the AI system register and aligning with emerging requirements such as the EU AI Act

What they require

  • 3+ years of experience of similar experience in GRC, information security governance, IT audit or IT risk management
  • Working knowledge of ISO/IEC 27001; exposure to DORA, GDPR or PCI DSS
  • Experience in regulated financial services, including payments, e-money, banking, fintech, or advisory work for such companies
  • Hands-on experience with audits — coordinating them, preparing evidence, remediating findings
  • Familiarity with GRC platforms or a strong interest in compliance automation
  • Strong written English — your output goes to auditors, regulators and senior stakeholders
  • Ability to manage multiple workstreams against fixed deadlines
  • Preferred: Certifications such as CISA, CRISC, CISM, CIPP/E or ISO 27001 Lead Auditor / Lead Implementer
  • Preferred: Direct experience with DORA implementation, EBA outsourcing guidelines or FCA operational resilience
  • Preferred: Experience implementing or administering a GRC platform, e.g. Vanta, ServiceNow GRC, OneTrust or similar
  • Preferred: Familiarity with ISO 42001, the EU AI Act or AI risk management
  • Preferred: Light scripting or workflow automation skills using low-code tools

Benefits

  • Provident Fund after probation
  • Annual Learning Budget for professional development after probation
  • €150 monthly Wolt allowance
  • SportsBenefits membership with access to gyms and sports facilities
  • Potential eligibility for a company car after one year, performance and availability permitting
  • Complimentary parking space near the office
  • 25 days of vacation + public holidays + 10 days of sick leave
  • Exclusive local discount card
  • Tickets for events such as Beonix and basketball games
  • Free Greek language classes twice a week
  • Company celebrations bringing colleagues from all offices together
  • Opportunities to participate in international company events and initiatives

payabl. empowers businesses to grow through payments innovation and banking services. Our ambition is to expand our strong portfolio of global financial services and make them all accessible through our unified platform, payabl.one. As a licensed financial company with principal membership with card schemes, we specialize in global payments and multi-currency banking solutions.

Fintech
Salary not disclosed