camunda
camunda1d ago
New
USD 127200-205100/yr

Senior InfoSec GRC Analyst

Remotefull-timesenior
Grc AnalystCybersecurity
1 views0 saves0 applied

Quick Summary

Key Responsibilities

Own and continuously improve Camunda's Information Security Management System (ISMS), spotting gaps, closing them, and making measurable improvements rather than just keeping documents current.

Requirements Summary

Own and continuously improve Camunda's Information Security Management System (ISMS), spotting gaps, closing them, and making measurable

Technical Tools
Grc AnalystCybersecurity

Register Here!

Camunda is the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex, end-to-end business processes. With built-in governance, auditability, and human oversight, Camunda gives enterprises the control they need to move AI from pilots to production — safely and at scale. Trusted by over 700 organizations worldwide, including 9 of top 10 US banks, Camunda helps enterprises boost operational efficiency, accelerate time-to-value, and deliver better customer experiences.

Fully remote and global, we are in the middle of something bigger: transforming into an AI-first organisation, built on our own platform. We use Agentic AI to automate, orchestrate intelligent processes, and elevate human contribution across every team.

Named GP Bullhound’s Top 100 Next Unicorn list, 2025 Great Place to Work certified. Visionary in 2025 Gartner® Magic Quadrant™ for Business Orchestration and Automation Technologies. ranked 3rd in Flexa's 2026 Most Flexible Companies, We’re growing fast and looking for top talent to join our team. If you want meaningful work, visible impact and put something genuinely rare on your CV, keep reading.

About the Role

~1 min read

At Camunda, hundreds of enterprises trust us to orchestrate their most critical business processes, and that trust is something we earn every single day. As our Senior InfoSec GRC Analyst, you will join a small, senior, and highly collaborative InfoSec team that lives our FAITH values (Focus, Ambition, Integrity, Talent and Humor) in everyday work. You will own the governance, risk, and compliance side of our security practice: keeping our ISMS healthy, driving our ISO 27001 and SOC 2 audit cycles, reviewing the security requirements our customers put in front of us, and replacing manual compliance work with automation wherever we can. It is a role with real ownership and plenty of cross functional contact, from Legal and Procurement to IT and our PreSales and PostSales teams, and your work will show up directly in how confidently customers adopt Camunda.

Responsibilities

~1 min read
  •  Own and continuously improve Camunda's Information Security Management System (ISMS), spotting gaps, closing them, and making measurable improvements rather than just keeping documents current.

  • Drive our security audit cycle for ISO 27001, SOC 2, and future frameworks with minimal supervision, working directly with external auditors and internal control owners to keep evidence, findings, and timelines on track.

  • Review the information security requirements in customer contracts, redline what we cannot realistically meet, and give our negotiators clear, practical recommendations they can act on.

  • Lead responses to complex customer security questionnaires and act as a trusted point of contact for InfoSec topics coming from PreSales, PostSales, and customer security teams.

  • Run and improve our GRC tooling, adding automation and continuous monitoring so compliance evidence is collected once and reused, not rebuilt every audit season.

  • Take ownership of emerging InfoSec compliance topics such as the Cyber Resilience Act and the AI Act: perform gap analysis, translate requirements into concrete work, and partner with Legal, IT, Procurement, and Engineering to get them implemented.

  • Hands on experience implementing and maintaining ISO 27001 and/or SOC 2 certifications, including managing external audits from evidence gathering through to closing findings.

  • Substantial experience across information security, risk management, and compliance, with a clear focus on Governance, Risk, and Compliance (GRC), ideally gained in a SaaS or cloud software company.

  • Practical experience reviewing information security requirements in customer contracts and leading responses to security questionnaires, with the judgement to tell a real risk apart from a negotiable clause.

  • Experience working with GRC tools, compliance automation, and continuous monitoring, and a genuine preference for automating repetitive work instead of absorbing it.

  • Strong project management and collaboration skills, so you can move several workstreams forward at once across InfoSec, Legal and Compliance, IT, Procurement, and the field teams, and explain security topics clearly to technical and non technical colleagues alike. 

  • Ability and/or willingness to use our product

  • Some software development or scripting ability, including comfort building small tools or automations with AI assisted coding.

  • Experience planning and running business continuity or disaster recovery testing.

  • Familiarity with newer regulatory frameworks such as the Cyber Resilience Act, the AI Act, or NIS2.

  • Experience working in a fully remote, async first organisation.

This role is an existing vacancy

#LI-SG1 #LI-Remote #C1

What We Offer

~3 min read

We offer competitive, fair, and transparent compensation. Salary ranges are location-based, with Standard and Major markets (global tech hubs) reflecting local competition.

We invest in your wellbeing, growth, and ability to connect, along with perks that support you no matter where you’re based. Our benefits are globally designed and locally delivered where applicable.

Remote & Flexible: Work from anywhere with the setup that suits you, home office budget, co-working space support, and flexible time off to recharge when you need it.
In Person Connection: We invest in meaningful face time through our Annual Kickoff (Vienna in 2025, Madrid in 2026!), team offsites, and Camundi Connection Budgets, including contributing to meetups while travelling,, and local gatherings with fellow Camundi.
Health & Wellbeing: Access locally tailored healthcare, Modern Health for global mental wellbeing, and our Live Well Lifestyle Spending Account (LSA), a flexible, global benefit that puts you in control of your whole life, not just work, from: staying active, to caring for family, exploring personal passions, meaningful experiences, and investing in your financial wellbeing. The Live Well program launches in 2026 and scales to €1,000 annually from 2027.
Financial Security: Retirement and pension plans (often with company contributions), plus life and disability insurance where relevant.
Professional Growth: Up to $/€/£1,000 per year for self-driven learning: courses, certifications, books, you decide!

Location & Eligibility

Where is the job
Worldwide
Fully remote, anywhere in the world
Who can apply
Open to applicants worldwide

Listing Details

Posted
August 5, 2026
First seen
August 5, 2026
Last seen
August 5, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
59%
Scored at
August 5, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

camundaSenior InfoSec GRC AnalystUSD 127200-205100