Grc Analyst

Synthesia Synthesia · Multimodal · EUROPE · Engineering

The GRC Analyst will own and evolve the governance, risk, and compliance program for an AI video platform company. This role requires a strong technical foundation to bridge the gap between how systems are built and operated and compliance requirements for audits, customers, and leadership. Responsibilities include managing GRC programs (ISO 27001, SOC 2, ISO 27701, ISO 42001), translating technical realities into audit narratives, and contributing to risk management. The role also involves preparing for future certifications like ISO 22301, HITRUST, and FedRAMP. A hands-on technical background, understanding of cloud environments (AWS), and experience supporting audits are essential. Familiarity with AI/LLM tools is a plus.

What you'd actually do

  1. Own and continuously improve our GRC program across ISO 27001, SOC 2, ISO 27701, and ISO 42001, including control mapping and evidence expectations.
  2. Partner with control owners to make compliance repeatable and low-friction - evidence as a habit, not a scramble.
  3. Drive audit readiness: artifacts, timelines, action tracking, and clear control demonstration.
  4. Improve policies, standards, and procedures so they reflect how we actually operate.
  5. Build strong working relationships with DevOps/Platform and engineering teams.

Skills

Required

  • GRC program management
  • Audit readiness
  • Risk management
  • Technical understanding of cloud environments (AWS)
  • Understanding of CI/CD, Kubernetes, monitoring
  • Communication with technical and business audiences
  • Problem-solving
  • Proactiveness
  • Independent workstream management
  • Experience supporting audit cycles

Nice to have

  • Experience with ISO 27001, SOC 2, ISO 42001, ISO 27701
  • Experience with ISO 22301, HITRUST, FedRAMP
  • Experience with GRC tooling (Vanta, Drata, OneTrust)
  • Lightweight automation for compliance
  • Experience in fast-growing SaaS
  • Experience with AI and LLM tools

What the JD emphasized

  • credible with technical teams
  • useful for the business
  • strong technical foundation
  • ISO 22301
  • HITRUST
  • FedRAMP
  • hands-on technical background
  • understand how cloud environments work
  • follow technical conversations well beyond what a traditional auditor can
  • understand how the sausage is made
  • experience supporting audit cycles
  • know what good evidence looks like
  • AI and LLM tools