Mirrai Careers
Resume BuilderCareer Test
JobsInsightsPricing
Get Started Free
Jobs/Vendor Risk and GRC Analyst

Vendor Risk and GRC Analyst

Patrianna

Bulgaria Remote Full-time Posted 2w ago
Apply on company site
About Patrianna Patrianna is a fast-scaling product development company headquartered in Gibraltar, with a dynamic, global team powering our growth. We operate at the intersection of technology and entertainment, building innovative solutions that shape the future of social gaming and deliver outstanding experiences to millions of players worldwide. We're driven by speed, ambition, and bold ideas. At our core, we're product creators and problem-solvers who thrive in a high-performance environment. We're looking for exceptional talent—smart, adaptable, and motivated individuals eager to make an impact, scale business functions at pace, and continuously improve. Whether you're a domain expert or an agile thinker who thrives in change, at Patrianna you'll have the freedom to innovate, take ownership, and help us lead the next wave of gaming innovation. Join us—and be part of something extraordinary. THE ROLE Own the vendor and third-party risk lifecycle for a fast-scaling tech company, while supporting the wider GRC programme across ISMS, privacy, and compliance. WHAT YOU WILL BE DOING * Third-Party Risk (Champion) — Own the full vendor risk lifecycle: due diligence, security questionnaires, risk rating, contractual safeguards (DPAs, security schedules), and ongoing monitoring. Maintain the supplier register and drive reassessment cadence based on criticality. * Supplier Assurance — Track fourth-party dependencies and concentration risk across critical suppliers, aligning oversight with DORA ICT third-party requirements and ISO 27001 supplier controls. * ISMS & Audit Readiness — Support policy maintenance, control mapping, and evidence collection to keep the Statement of Applicability (SoA) current and audit-ready across the entities and clients you cover. * Risk Management & RCSA — Execute risk assessments using an ISO 31000-aligned methodology and contribute to Risk & Control Self-Assessment workshops and remediation tracking. * Privacy Operations — Support RoPA maintenance, DPIAs, and data subject requests — with a focus on processor and controller arrangements with vendors and group entities. * Governance Reporting — Prepare third-party risk materials for governance committees and keep registers accurate, visible, and current. WHAT WE ARE LOOKING FOR * Solid GRC grounding — A proven track record in GRC, IT audit, vendor risk, or information security, with hands-on third-party/supplier risk responsibility. * Third-party risk proficiency — Practical experience running vendor due diligence, security questionnaires (SIG, CAIQ, or equivalent), and contractual risk review. * Framework knowledge — Working knowledge of ISO/IEC 27001:2022 supplier controls, ISO 31000, and GDPR processor obligations; familiarity with DORA third-party requirements is a plus. * Independent thinker — You go beyond the checklist — you understand the why behind a control, spot gaps, and propose improvements without being prompted. * Pragmatic compliance mindset — You see GRC as a business enabler, not a blocker, and know how to balance rigor with momentum. * Clear communicator — Precise, confident writing across questionnaires, risk memos, and supplier-facing responses that need minimal oversight. WHY YOU WILL LOVE IT At Patrianna, GRC isn't a back-office function — it's central to how we scale responsibly. You'll take real ownership of a critical domain, work alongside infrastructure, security, procurement, and product teams, and see the direct impact of your work on how the business grows and operates. You'll have the autonomy to shape how third-party risk is managed at a company moving fast, with the support of a GRC & Assurance Manager who values initiative and independent thinking. If you want a role where you can build something meaningful — not just maintain it — this is it. Nice to haves: Experience in iGaming, fintech, or other regulated sectors; exposure to TPRM/GRC platforms (OneTrust, ProcessUnity, Whistic, CISO Assistant); certifications such as ISO 27001 Lead Implementer/Auditor, CTPRP, CIPP/E, CISA, or CRISC; and familiarity with SOC 2 Type II or PCI-DSS supplier scoping. Equal Opportunities Statement We hire based on skills, drive, and ideas—nothing else. Your background, gender, age, race, ethnicity, disability, sexual orientation, religion, neurodiversity, or educational path will never be a barrier to joining us. We also welcome candidates from non-traditional career journeys and value diverse perspectives that challenge conventional thinking. Diversity fuels our innovation, collaboration, and growth, and we're committed to creating an environment where everyone can contribute their best work and thrive.

See how well you match this job

Upload your resume and we’ll score your fit for this role and 6 similar roles — then tailor your CV to it with AI. Free, no credit card.

Check your match

Similar jobs

  • Fraud Data Analyst

    patrianna

    Remote
  • Chargeback Analyst

    patrianna

    Remote
  • GRC Analyst

    mypassglobal

    Cebu
  • Third Party Risk Analyst, Security GRC

    Anthropic

    Remote
  • Security GRC Analyst

    lendable

    Remote
  • Senior, Cybersecurity Assurance Analyst

    axonius

    Remote
Apply on company site

Want more roles like this? Browse fresh jobs or tailor your resume with AI.

Mirrai Careers

AI-powered career platform: build resumes, match jobs, and plan your career.

Product

  • All Tools
  • Resume Builder
  • Career Test
  • Pricing
  • For employers

Browse jobs

  • Job Search
  • Jobs by role
  • Companies hiring
  • Remote jobs (US)
  • Jobs in the US
  • Jobs in the UK

Legal

  • Privacy Policy
  • Terms of Service
  • Fair Use Policy

Company

MIRRAI CHAT LTD (Company No. 16403306)

71-75 Shelton Street, Covent Garden

London, WC2H 9JQ, UNITED KINGDOM

contact@mirrai.chat

© 2026 Mirrai Careers. All rights reserved.