Staff GRC Analyst
Role Summary
Join Pleo as a Staff GRC Analyst and enhance compliance automation while collaborating with diverse teams to ensure security and governance.
About the Organisation
Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we're changing that. We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike - with a vision to help all businesses ‘go beyond’.
The word ‘Pleo’ actually means ‘more than you’d expect’, and living by that mantra has been the secret to our success over the last 10 years.
Now, we’re at a pivotal moment in our journey; every move we make has a direct impact on our 40,000+ customers, our business, and our collective success. We need people who take pride in uncovering customer needs, who turn complex problems into simple solutions, challenge the way things are done (respectfully), and always aim high. With great ambitions driving us forward, we can’t say we’ve got this whole thing figured out. And frankly, that’s half the fun! What we can say is that we’re a driven, progressive, and, importantly, a kind bunch of 850+ people from over 100 nationalities, all committed to delivering the future of business spending, together.
We're looking for a Staff GRC Analyst to join our Information Security team at Pleo. In this role, you'll help and be part of our governance operating model as we scale compliance. If you're excited about building compliance automation and are passionate about fast-paced scale ups, then this is the opportunity for you!
This role is a good fit for you if:
This role is not a good fit for you if:
Find Jobs in United Kingdom on Arbeitnow
- You're equally excited about getting into the details of regulations requirements as you are about writing code.
- You demonstrate high-agency and like to take initiative in developing solutions that will save the team time.
- You are not able to work closely with colleagues who do not have an engineering background.
- You require a well groomed backlog and task assignment in order to perform at your best.
- English first. Since it's our company language, please submit your application in English. You’ll be using it a lot if you join us.
- A fair look for everyone. Our talent team reads every single application to ensure the process is fair. To keep things running smoothly, we only accept applications through our system—our support team can’t pass on calls or emails.
- Diversity drives us. We can only reach our goals if our team reflects the world around us. That starts with you hitting apply, even if you don't tick every single box. We encourage people from all backgrounds and experiences to join us.
- Interview at your best. We want you to feel comfortable throughout the process. If you have any accessibility requirements or need a specific format, email ----- We’ll design a process that works for you.
- Your data is safe. When you apply, we process your personal data as a data processor. For more information on how Pleo processes personal data, read our Privacy Policy here.
- Applying for multiple roles? Nothing is stopping you, and we assess every role independently. However, we do look for alignment, so make sure you can explain why your interest and experience are right for each specific role.
- Reapplying. If you’re applying for the same role again, please wait six months from your last decision before hitting submit.
Minimum Requirements
You’ll thrive in this role if you have:
- Significant experience in Security GRC, understanding of auditing processes, with direct experience in both internal and external audit cycles.
- Demonstrated experience using AI and/or coding automation to get controls built, implemented, and operating in practice.
- A strong understanding of cloud architectures (AWS or equivalent) and how infrastructure decisions map to security controls and audit evidence.
- Experience automating reporting for GRC programs, including dashboards and executive-level summaries.
- Fintech, payments industry or IT audit background, with familiarity with regulatory expectations and payment platform architectures.
- Certifications such as CISM, CISSP, CISA, or PCI-related credentials. A degree in Cybersecurity, Engineering, Computer Science, Mathematics, or equivalent experience is a plus.
Working Conditions
Transparency is important to us so we also wanted to share some insights about what we’re looking for in applications to ensure you can set yourself up for success!
Last time we hired a GRC Analyst, we received a total of 350 applications but only 18 were selected for an intro call. Some of the key reasons why previous candidates didn’t make it past the application screening stage include:
- Your own Pleo card (no more out-of-pocket spending!)
- Lunch is on us for your work days - enjoy catered meals or receive a lunch allowance based on your local office
- Comprehensive private healthcare - depending on your location, coverage options include Vitality, Alan or Médis
- We offer 25-28 days of holiday (depending on your location) + public holidays
- For our Team, we offer both hybrid and fully remote working options
- Option to purchase 5 additional days of holiday through a salary sacrifice
- We use MyndUp to give our employees access to free mental health and well-being support with great success so far
- Paid parental leave - we want to make sure that we're supportive of families and help you feel that you don't have to compromise your family due to work
- CV writing and content: we receive a lot of CVs, and many of them are AI-generated. We love seeing people leverage AI—it’s a big focus for us internally too—but without human intervention, these CVs can sometimes become generic and fail to show a candidate in the best light. What we're really looking for is the specific details of real impact that only you know from your previous experience. A top tip from us is to use the “Achieved X, as measured by Y, by doing Z” formula (credit: Laszlo Bock, ~2014) to give a really clear picture of what you’ve worked on. A final note: including links to your previous companies' websites is a huge help and allows us to truly understand your background!
Eligibility Criteria
No specific eligibility criteria are mentioned; requires further review on international applicant eligibility.
⚠️ Disclaimer: PathwayAI Africa does not guarantee employment, scholarships, visas, or admission. Always verify all opportunities through official sources before submitting personal information.
Check if You Qualify
Upload your CV to compare it against this specific opportunity. You can still apply even if improvements are recommended.
