Logo for FYUL

Senior GRC Analyst

Role overview

Qualifications

  • 5+ years of experience in cybersecurity GRC, IT audit, or security compliance
  • Strong communication and negotiation skills
  • Demonstrated automation capability
  • Self-directed working style with strong ownership

Responsibilities

  • Plan and execute internal and external audit activities across ISO 27001, SOC 2, and related frameworks
  • Design and implement automation for evidence collection and recurring compliance activities
  • Conduct security assessments of third-party vendors during onboarding and annual reviews
  • Maintain the risk register: perform risk assessments and track remediation plans

Key facts

Hard skills

Other skills

  • Security Policies
  • Communication
  • Negotiation

About the company

FYUL logo

FYUL

Unknown

Company details

Company sizeUnknown

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About the team & the role: 

The Information Security Governance & Assurance function at FYUL is deliberately small and execution-focused. The Cybersecurity Governance & Assurance Manager is responsible for strategy, stakeholder relationships, and cross-functional communication; this senior analyst role, reporting directly to the manager, is responsible for its execution: audits, evidence, vendor security, and the automation of GRC operations. This is an individual-contributor position where professional growth comes from depth of expertise and ownership of outcomes.

Printful & Printify hold active ISO 27001 and other certifications. The primary mandate of this role is to maintain and strengthen this certified posture, ensure the continuity of ongoing audit cycles, and extend the same governance standard to additional frameworks as the company's needs evolve.

Your responsibilities:

  • Audit management. Plan and execute internal and external audit activities across ISO 27001, SOC 2, and related frameworks: evidence collection, control readiness, direct communication with external auditors, and follow-through on findings until closure. Represent the function confidently in audit interactions, including the ability to decline inappropriate requests in a professional and well-substantiated manner.

  • GRC automation. Design and implement automation for evidence collection and recurring compliance activities; apply compliance-as-code practices where they deliver measurable value; leverage AI-based agents and workflows to reduce manual effort. Maintain working knowledge of the commercial GRC platform landscape and prefer established industry solutions over custom development.

  • Vendor security operations. Conduct security assessments of third-party vendors during onboarding and annual reviews, with continuous improvement of the process's efficiency.

  • Risk management. Maintain the risk register: perform risk assessments, track remediation plans, and ensure timely closure of identified risks.

  • Policies, documentation, and security awareness. Develop and maintain information security policies and procedures in collaboration with the manager, and contribute to security awareness materials and training delivery.

Your qualifications:

  • 5+ years of experience in cybersecurity GRC, IT audit, or security compliance, including direct hands-on participation in complete ISO 27001 and/or SOC 2 audit cycles, preferably on the industry side.

  • Strong communication and negotiation skills, with the professional confidence to hold a position under pressure from auditors, vendors, and internal stakeholders, and the judgment to know when refusal is the correct response.

  • Demonstrated automation capability: scripts, integrations, GRC platform implementations, or AI-assisted workflows. Software engineering background is not required; a track record of building practical automation is.

  • Self-directed working style with strong ownership: the ability to take ambiguous problems through to completed outcomes with minimal supervision.

  • Excellent written and spoken English.

Relevant certifications (e.g., ISO 27001 Lead Implementer/Lead Auditor, CISA, CISSP, CISM) are an advantage. Practical audit experience will be weighted more heavily than certification.

What we offer:

  • Monthly salary EUR 5,000+ gross, depending on work experience, education, and skills

  • A high-trust, compact team with minimal bureaucracy: initiatives move directly from proposal to implementation.

  • An opportunity to work remotely or in a modern and welcoming office in Riga.

  • Flexible working hours (start your day as late as 11 AM).

  • Private health insurance.

  • 2 extra paid days off to focus on your mental or physical well-being.

  • 1 extra paid day off to celebrate a Birthday or any other celebration of your choice.

  • Internal and external learning opportunities.

  • Access to mentorship, internal meetups, and hackathons, both on-site and online.

  • Free and healthy lunch if you work from the Rīga office.

  • Design and order your own merch using our platforms with an employee discount.

  • Exciting team-building events and parties you’ll never forget!


FYUL is the engine that powers on-demand commerce at global scale.

Formed in 2024 through the merger of Printful, Printify, and Snow Commerce, we bring together tech, talent, and infrastructure to help people turn ideas into beautiful products.

From solo creators to entertainment giants, FYUL powers merch that connects with millions, backed by advanced tech, premium production, and global reach.

We're a fast-growing global company working toward powering great brands, great experiences, and great people.

We are an equal-opportunity workplace. We’re committed to diversity and inclusion and make hiring decisions based solely on qualifications, merit, and work experience.

If you think you’d excel in this role, send us your resume in English, showing us why you are the right person for the job.

Interested, but don’t think this is the right fit for you? Feel free to share it with friends and check out other open positions at our career site. We’re always looking for creative and driven minds to join our ever-growing team!

AS Printful Latvia (Reģ. Nr. 40203050078)

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

GRC Analyst Related jobs

Other jobs at FYUL

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.