Skip to main content
Patrianna

Vendor Risk and GRC Analyst

RemoteMalta, Georgia, Poland +3 more only
Published
Role
Security
Employment
Full-time
Salary not disclosed
Check eligibility

Open to MT, GE, PL, RO, GI, BG only. Set where you work from to check your eligibility.

No BS summary

GRC/vendor risk analyst for a remote full-time role hiring in Malta, Georgia, Poland, Romania, Gibraltar, or Bulgaria. Needs hands-on third-party/supplier risk experience, vendor due diligence, security questionnaires, contractual risk review, ISO 27001, ISO 31000, and GDPR processor obligations.

Core skills

Third-party risk managementGRCVendor due diligence

Required skills

SIG/CAIQISO/IEC 27001:2022ISO 31000GDPR

Optional skills

DORAOneTrustProcessUnityWhisticCISO AssistantISO 27001 Lead ImplementerISO 27001 Lead AuditorCTPRP

What you'll do

  • Own the full vendor risk lifecycle: due diligence, security questionnaires, risk rating, contractual safeguards, and ongoing monitoring.
  • Maintain the supplier register and drive reassessment cadence based on criticality.
  • Track fourth-party dependencies and concentration risk across critical suppliers.
  • Align supplier oversight with DORA ICT third-party requirements and ISO 27001 supplier controls.
  • Support policy maintenance, control mapping, and evidence collection to keep the Statement of Applicability current and audit-ready across covered entities and clients.
  • Execute risk assessments using an ISO 31000-aligned methodology.
  • Contribute to Risk & Control Self-Assessment workshops and remediation tracking.
  • Support RoPA maintenance, DPIAs, and data subject requests, focused on processor and controller arrangements with vendors and group entities.
  • Prepare third-party risk materials for governance committees.
  • Keep registers accurate, visible, and current.

What they require

  • Proven track record in GRC, IT audit, vendor risk, or information security, with hands-on third-party/supplier risk responsibility.
  • Practical experience running vendor due diligence, security questionnaires, and contractual risk review.
  • Working knowledge of ISO/IEC 27001:2022 supplier controls, ISO 31000, and GDPR processor obligations.
  • Ability to understand the why behind a control, spot gaps, and propose improvements without being prompted.
  • Pragmatic compliance mindset and ability to balance rigor with momentum.
  • Precise, confident writing across questionnaires, risk memos, and supplier-facing responses that need minimal oversight.
  • Preferred: Familiarity with DORA third-party requirements.
  • Preferred: Experience in iGaming, fintech, or other regulated sectors.
  • Preferred: Certifications such as ISO 27001 Lead Implementer/Auditor, CTPRP, CIPP/E, CISA, or CRISC.

Benefits

  • Take real ownership of a critical GRC domain.
  • Work alongside infrastructure, security, procurement, and product teams.
  • See the direct impact of your work on how the business grows and operates.
  • Autonomy to shape how third-party risk is managed at a fast-moving company.
  • Support of a GRC & Assurance Manager who values initiative and independent thinking.
  • Opportunity to build something meaningful, not just maintain it.

Patrianna is a fast-scaling product development company headquartered in Gibraltar, with a dynamic, global team. It operates at the intersection of technology and entertainment, building social gaming solutions for millions of players worldwide.

🇬🇮 GibraltarGamingStartup

Details

Apply routeDom
Salary not disclosed