GRC / TrustOps Analyst
il y a 1 semaine
Shift is the leading AI platform for insurance. Shift combines generative, agentic, and predictive AI to transform underwriting, claims, and fraud and risk - driving operational efficiency, exceptional customer experiences and measurable business impact. Trusted by the world's leading insurers, Shift delivers AI when and where it matters most, at scale and with proven results.
Our culture is built on innovation, trust, and a drive to transform the insurance industry through our SaaS platform. We come from more than 50 different countries and cultures and together we are creating the future of insurance.
The security team is a critical component of Shift Technology as no organization is immune to cyber-crime. The team is responsible for protecting information throughout the security infrastructure, edge devices, networks, and data. We strive to stay up to date with the latest tactics hackers are employing in the field in order to prevent data breaches by monitoring and reacting to attacks but the first step is finding the most qualified professionals to lead the way.
DESCRIPTION
As a GRC/TrustOps Analyst, you will be a key member of Shift's security program, focused on executing and supporting our security governance framework. You will assist with security and privacy compliance activities, help conduct risk assessments, and operate our third-party security assurance program. This role is essential for the day-to-day operations that ensure Shift meets its regulatory obligations and proactively demonstrates security to maintain customer trust. As part of the Information Security department, this role reports to the CISO.
RESPONSIBILITIES
Customer Trust & External Assurance
- Manage the end-to-end intake, completion, and quality assurance of customer-facing security questionnaires (e.g., SIG, CAIQ, custom client forms).
- Maintain and expand standardized, reusable security response libraries and knowledge bases to improve response time and consistency.
- Curate, update, and proactively deliver audit-ready evidence packages for clients and prospects.
- Pull, validate, and aggregate data from internal systems to produce reports, decks, and support external security reporting.
- Maintain dashboards and manage recurring metric updates for the security program.
- Track and report on key risk indicators (KRIs) and key performance indicators (KPIs) for internal and external stakeholders.
Governance & Policy Management
- Promote a mind-set of security and compliance by assisting with knowledge sharing and acting as a resource for other teams.
- Support the development and execution of the security awareness plan and related activities.
Risk Management & Security Assurance
- Contribute to the maintenance of the ISMS and security assurance plan by executing assigned tasks and providing feedback.
- Execute security control evaluations and testing based on established procedures to validate their effectiveness.
- Support routine GRC Ops and Risk Management activities
Compliance & Audits
- Support internal and external audits (e.g., ISO 27001, SOC 2) by gathering evidence, coordinating with internal teams, and tracking requests.
- Perform analysis and compile documentation and evidence to demonstrate the compliance level of systems, services, and controls.
- Assist in tracking the remediation of audit findings to ensure they are addressed in a timely manner.
Third-Party Risk Management
- Execute the third-party information security assurance process, including sending assessments, reviewing responses, and documenting results.
- Contribute to the improvement of the Third-Party Risk Management (TPRM) process based on operational feedback.
SKILLS & BACKGROUND
Experience & Education
- 2+ years of proven experience in a GRC, IT Audit, Security Assurance, or a similar role in a SaaS or Financial Services company - apprenticeship experience is acceptable
- Bachelor's Degree in a relevant field or equivalent work experience.
- Professional certifications (e.g., CIPP/E, CIPP/US, CIPT, CISA, CISM, CRISC) are a plus, or the candidate should be actively working towards one.
- Direct experience with GRC management software, (e.g. Drata, Vanta).
Knowledge & Frameworks
- Strong familiarity with security and privacy frameworks is required (e.g., ISO 27001/ISO27701, SOC 2, NIST CSF, HIPAA, GDPR).
- Direct experience supporting formal audit and certification processes.
- Direct experience responding to customer security questionnaires and managing a security response library.
- Experience executing tasks within a Third-Party Risk Management (TPRM) program.
Core Competencies
- Strong communication skills, with the ability to clearly explain security and compliance concepts to others.
- Highly organized with great attention to detail, capable of managing multiple tasks and requests simultaneously.
- A collaborative team player who can work effectively with a variety of stakeholders.
- An analytical mindset with the ability to pull, analyze, and visualize data, track metrics (KPIs/KRIs), and identify areas for improvement.
Recruitment Process
- TA Interview
- Security team interview
- Technical / Team interview
To support our permanent, full time employees at every stage of their careers and lives, we provide a competitive total rewards and benefits package. Here are the global benefits we'd like to highlight:
- Flexible remote and hybrid working options
- Competitive Salary and a variable component tied to personal and company performance
- Company equity
- Multiple Learning and Development opportunities, including Focus Fridays, a half-day each month to focus on learning and personal growth
- Generous PTO and paid holidays
- Mental health benefits
- 2 MAD Days per year (Make A Difference Days for paid volunteering)
Additional benefits may be offered by country - ask your recruiter for more information. Intern and Apprentice position are eligible for some of these benefits - ask your recruiter for more details.
At Shift we strive to be a diverse and inclusive workforce.
We welcome applications from and hire people who will contribute to the diversity of our company,
without regard to race, color, religion, marital status, age, national or ethnic origin, physical or mental disability, medical condition, pregnancy, genetic information, gender identity or expression, sexual orientation, or other non-merit criteria.
Shift Technology is committed to providing reasonable accommodations for qualified individuals with disabilities in our application and employment process. Should you require accommodation, please email - and we will work with you to meet your accessibility needs.
Please be aware of scammers and only trust correspondence that comes from emails ending in "shift-". We will never do initial outreach to you via Whatsapp/Text/SMS, never ask for banking information or personal identification numbers (ex. Social Security Number) as part of our recruitment process.
Shift Technology does not accept unsolicited CVs from recruiters or employment agencies in response to the Shift Technology Careers page or a Shift Technology social media post. Any unsolicited CVs, including those submitted directly to hiring managers, are deemed to be the property of Shift Technology.
-
GRC / TrustOps Analyst
il y a 1 semaine
Paris, Île-de-France Shift Technology Temps pleinShift is the leading AI platform for insurance. Shift combines generative, agentic, and predictive AI to transform underwriting, claims, and fraud and risk - driving operational efficiency, exceptional customer experiences and measurable business impact. Trusted by the world's leading insurers, Shift delivers AI when and where it matters most, at scale...
-
GRC / TrustOps Analyst
il y a 1 semaine
Paris, Île-de-France Shift Technology Temps pleinShift is the leading AI platform for insurance. Shift combines generative, agentic, and predictive AI to transform underwriting, claims, and fraud and risk - driving operational efficiency, exceptional customer experiences and measurable business impact. Trusted by the world's leading insurers, Shift delivers AI when and where it matters most, at scale...
-
Business Analyst DORA
il y a 1 semaine
Paris, Île-de-France Collective Temps pleinBusiness Analyst for Supporting DORA ImplementationAbout the RoleWe are looking for an experienced Business Analyst to support the run of the application, its parametrisation through the Designer Tool, Requirements Definition, Release implementation and introduction of further modules.Key ResponsibilitiesSupport application operations and managementConfigure...
-
Business Analyst
il y a 2 jours
Paris, Île-de-France Cherry Pick Temps pleinFiche de poste ? Business Analyst technico-fonctionnelLa mission se fait dans le cadre du Programme Relation Client, et en particulier sur le projet FID (Formatage et Intégration de Données), qui a pour finalité la mise en ?uvre de la brique d?intermédiation centrale du SI cible, en remplacement d?un CRM Siebel qui doit être totalement décommissionné...
-
Business Analyst IT Coporate functions H/F
il y a 5 jours
Paris, Île-de-France FinDiT Consulting Temps pleinFinDiT Consulting est un cabinet de conseil spécialisé dans l'accompagnement des acteurs financiers dans la transformation digitale.Notre offre s'articule autour de deux axes majeurs :Le Conseil en accompagnement Digital, ou comment aider nos clients à converger vers des solutions digitales correspondant à leur métier (digitaliser un process de...
-
Manager(e) SAP Risque, Sécurité
il y a 2 semaines
Paris, Île-de-France Turnkey Consulting Temps pleinA propos de Turnkey:Au sein du groupe international Turnkey Consulting, spécialiste de la Sécurité Applicative, de la Gouvernance des Risques et de la Conformité (GRC), de la Gestion des Identités (IAM) et de la Cybersécurité des ERP, l'entité Française recherche son nouveau talent Sécurité & GRC, un profil manager (5-10 ans d'expérience) pour...
-
Business analyste informatique IT DORA
il y a 2 semaines
Paris, Île-de-France Free-Work Temps pleinObjectif de la mission :"The Group IT department is organized into IT ""Business Verticals"" where each business has its entry point to IT department, and transversal teams (Architecture, Software development factory, Operations). In this organisation we are looking for the IT Business Analyst to mainly support the appilcation Topease, already in use for...
-
ServiceNow Solution Architect
il y a 2 semaines
Paris, Île-de-France Blackfluo Temps pleinServiceNow Solution Architect Designing scalable, secure, and integrated ServiceNow solutions across enterprise workflowsPosition Overview We are seeking a ServiceNow Solution Architect to lead the design, governance, and implementation of enterprise workflows on the ServiceNow platform. The architect will drive strategic alignment of modules including ITSM,...
-
RSSI - Conformité DORA
il y a 1 semaine
Paris, Île-de-France BMB France Temps pleinBMB France est un cabinet de conseil certifié PASSI (Prestataire d'Audit de la Sécurité des Systèmes d'Information), spécialiste reconnu en cybersécurité depuis 1995. Pionniers et innovateurs, nous accompagnons nos clients à travers une large gamme de services adaptés aux enjeux actuels de sécurité numérique : audits organisationnels, physiques...
-
Analyste Politique Junior
il y a 2 semaines
Paris, France OCDE Temps plein**Description de l'entreprise**: L’Organisation de coopération et de développement économiques (OCDE) est une organisation internationale regroupant 38 pays Membres, qui œuvre pour la mise en place de politiques meilleures pour une vie meilleure. Notre mission consiste à promouvoir des politiques de nature à améliorer le bien-être économique et...
-
Analyste SOC
il y a 1 semaine
Paris 8e, France SERMA SAFETY & SECURITY Temps pleinSERMA Group est un acteur indépendant français dans le conseil et l’expertise spécialisée dans les systèmes électroniques embarqués et industriels, ainsi que la sécurité des systèmes d’information par le biais de sa filiale Serma Safety & Security. Serma Safety & Security a su développer son expertise en cybersécurité en accompagnant ses...
-
IT Business Analyst DORA
il y a 2 semaines
Paris, France FinDiT Consulting Temps pleinFinDiT Consulting est un cabinet de conseil spécialisé dans l'accompagnement des acteurs financiers dans la transformation digitale.Notre offre s’articule autour de deux axes majeurs :Le Conseil en accompagnement Digital, ou comment aider nos clients à converger vers des solutions digitales correspondant à leur métier (digitaliser un process de...
-
Cyber Risk Analyste
il y a 2 semaines
Paris, France Iliad - Free Temps plein**Description de l'entreprise** Chez Free, tu trouveras une **culture interne singulière** et très marquée. Il règne un fort état d’esprit collectif. Le recrutement est ouvert, sans a priori : on ne juge les gens ni sur leur âge, ni sur leur background. On aime aller vite, faire les choses nous-mêmes, et on mise sur l’autonomie pour être...
-
Business Analyst IT Coporate functions H/F
il y a 6 jours
Paris, France FINDIT CONSULTING Temps pleinFinDiT Consulting est un cabinet de conseil spécialisé dans l'accompagnement des acteurs financiers dans la transformation digitale. Notre offre s'articule autour de deux axes majeurs : Le Conseil en accompagnement Digital, ou comment aider nos clients à converger vers des solutions digitales correspondant à leur métier (digitaliser un process de...
-
Paramétreur Web Cleva
il y a 1 heure
Paris, France SOFTEAM Temps plein**Poste**: Paramétreur WEB CLEVA **Contribution sur les tâches suivantes**: Analyse de la totalité d’un périmètre y compris sur la partie technique JAVA (Ex: reprise du paramétrage des mots clés JAVA et déclencheurs RCP et les adapter pour un usage WEB) Chiffrage et participation aux chiffrages de certains chantiers ou évolutions. Concevoir des...
-
Analyste Soc/cert
il y a 1 semaine
Paris 8e, France SERMA SAFETY & SECURITY Temps plein**Analyste SOC/CERT - H/F (ALR)** **Poste et missions** SERMA Group est un acteur indépendant français dans le conseil et l’expertise spécialisée dans les systèmes électroniques embarqués et industriels, ainsi que la sécurité des systèmes d’information par le biais de sa filiale Serma Safety & Security. Serma Safety & Security a su...
-
Analyste Cybersecurite
il y a 1 semaine
Paris 1er, France Banque de France Temps plein**Présentation de la direction générale et du service** La Banque de France, qui assure des missions sensibles au service de la collectivité nationale dans un cadre européen, se doit d'être à l'état de l'art en matière de cybersécurité. Au sein du Contrôle général, qui regroupe les équipes d'inspection et d'audit interne de la Banque de...
-
Technical IT Compliance and Risk Analyst
il y a 1 semaine
Paris 17e, France PartnerRe Temps pleinCompany Description PartnerRe is a leading, privately owned, multi-line global reinsurer with a reputation of financial stability and strength, and a commitment to rebuilding businesses and communities after risk events around the world. Our mission is to continue to be a financially stable and predictable business partner, supporting our clients with...
-
Charge de ClientÈle a Distance
il y a 2 semaines
Paris 2e, France Bourse des crédits Temps plein**L'entreprise** Fintech en pleine croissance, lauréate de prix prestigieux, lancée par des experts du courtage en crédit, du web et de la data science, en juillet 2012. Son objectif est de révolutionner le marché du courtage en crédit et assurance. Il lui aura fallu 2 ans pour devenir un acteur majeur dans ce domaine en France. Nous avons...