Logo for Patrianna Limited

Vendor Risk and GRC Analyst

Role overview

Qualifications

  • Proven track record in GRC, IT audit, vendor risk, or information security
  • Practical experience running vendor due diligence, security questionnaires, and contractual risk review
  • Working knowledge of ISO/IEC 27001:2022 supplier controls, ISO 31000, and GDPR processor obligations

Responsibilities

  • Own the full vendor risk lifecycle including due diligence and ongoing monitoring
  • Track fourth-party dependencies and concentration risk across critical suppliers
  • Support policy maintenance and evidence collection for audit readiness
  • Execute risk assessments using ISO 31000-aligned methodology

About the company

Patrianna Limited logo

Patrianna Limited

Patrianna is a super fast-growing product development company headquartered in Gibraltar with colleagues around the world. We are looking for exceptional, smart talent striving to be number one. Motivated and capable of scaling up business functions at pace through domain expertise and a desire to continuously improve.

Company details

Company typeSME
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About Patrianna

Patrianna is a fast-scaling product development company headquartered in Gibraltar, with a dynamic, global team powering our growth. We operate at the intersection of technology and entertainment, building innovative solutions that shape the future of social gaming and deliver outstanding experiences to millions of players worldwide.

We're driven by speed, ambition, and bold ideas. At our core, we're product creators and problem-solvers who thrive in a high-performance environment. We're looking for exceptional talent—smart, adaptable, and motivated individuals eager to make an impact, scale business functions at pace, and continuously improve.

Whether you're a domain expert or an agile thinker who thrives in change, at Patrianna you'll have the freedom to innovate, take ownership, and help us lead the next wave of gaming innovation. Join us—and be part of something extraordinary.

The Role

Own the vendor and third-party risk lifecycle for a fast-scaling tech company, while supporting the wider GRC programme across ISMS, privacy, and compliance.

What you will be doing

  • Third-Party Risk (Champion) — Own the full vendor risk lifecycle: due diligence, security questionnaires, risk rating, contractual safeguards (DPAs, security schedules), and ongoing monitoring. Maintain the supplier register and drive reassessment cadence based on criticality.

  • Supplier Assurance — Track fourth-party dependencies and concentration risk across critical suppliers, aligning oversight with DORA ICT third-party requirements and ISO 27001 supplier controls.

  • ISMS & Audit Readiness — Support policy maintenance, control mapping, and evidence collection to keep the Statement of Applicability (SoA) current and audit-ready across the entities and clients you cover.

  • Risk Management & RCSA — Execute risk assessments using an ISO 31000-aligned methodology and contribute to Risk & Control Self-Assessment workshops and remediation tracking.

  • Privacy Operations — Support RoPA maintenance, DPIAs, and data subject requests — with a focus on processor and controller arrangements with vendors and group entities.

  • Governance Reporting — Prepare third-party risk materials for governance committees and keep registers accurate, visible, and current.

What we are looking for

  • Solid GRC grounding — A proven track record in GRC, IT audit, vendor risk, or information security, with hands-on third-party/supplier risk responsibility.

  • Third-party risk proficiency — Practical experience running vendor due diligence, security questionnaires (SIG, CAIQ, or equivalent), and contractual risk review.

  • Framework knowledge — Working knowledge of ISO/IEC 27001:2022 supplier controls, ISO 31000, and GDPR processor obligations; familiarity with DORA third-party requirements is a plus.

  • Independent thinker — You go beyond the checklist — you understand the why behind a control, spot gaps, and propose improvements without being prompted.

  • Pragmatic compliance mindset — You see GRC as a business enabler, not a blocker, and know how to balance rigor with momentum.

  • Clear communicator — Precise, confident writing across questionnaires, risk memos, and supplier-facing responses that need minimal oversight.

Why you will love it

At Patrianna, GRC isn't a back-office function — it's central to how we scale responsibly. You'll take real ownership of a critical domain, work alongside infrastructure, security, procurement, and product teams, and see the direct impact of your work on how the business grows and operates.

You'll have the autonomy to shape how third-party risk is managed at a company moving fast, with the support of a GRC & Assurance Manager who values initiative and independent thinking. If you want a role where you can build something meaningful — not just maintain it — this is it.

Nice to haves: Experience in iGaming, fintech, or other regulated sectors; exposure to TPRM/GRC platforms (OneTrust, ProcessUnity, Whistic, CISO Assistant); certifications such as ISO 27001 Lead Implementer/Auditor, CTPRP, CIPP/E, CISA, or CRISC; and familiarity with SOC 2 Type II or PCI-DSS supplier scoping.

Equal Opportunities Statement

We hire based on skills, drive, and ideas—nothing else. Your background, gender, age, race, ethnicity, disability, sexual orientation, religion, neurodiversity, or educational path will never be a barrier to joining us. We also welcome candidates from non-traditional career journeys and value diverse perspectives that challenge conventional thinking.

Diversity fuels our innovation, collaboration, and growth, and we're committed to creating an environment where everyone can contribute their best work and thrive.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Patrianna Limited

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.