8h ago
Information Security Governance, Risk and Compliance Analyst
Edinburgh
✨ $85k-$110k / yearest.
full-timemidtechnology
💼 About This Role
You'll help mature core compliance frameworks and shape AI security and governance at Trustpilot. You'll apply pragmatic risk assessment to AI systems and automate GRC workflows to strengthen security posture. This role balances security risks with fast-paced innovation.
🎯 What You'll Do
- Drive SOC 2, **ISO27001**, ISO42001, and PCI DSS compliance efforts.
- Evaluate security risks of **AI and machine learning** systems.
- Streamline vendor and third-party security assessments.
- Develop internal standards for **artificial intelligence** governance.
📋 Requirements
- Experience managing SOC 2, ISO27001, and PCI DSS frameworks.
- Proficiency in risk management including vendor due diligence.
- Ability to develop and implement security policies and procedures.
- Understanding of cloud environment risks.
✨ Nice to Have
- Familiarity with AI governance frameworks like EU AI Act or NIST AI RMF.
- Interest in using AI to automate GRC workflows.
🎁 Benefits & Perks
- 🍃 Learning & development via Trustpilot Academy and Blinkist.
- 🏖️ Pension, life insurance, and health cash plan.
- 🧘 Headspace mindfulness app access.
- 🚲 Season ticket loan and cycle-to-work scheme.
- 🎉 Company events and ERG activities.
0 0 0