Do you have a strong understanding of information security GRC operations and technologies? Have you built lasting relationships with business owners and vendors? Appfire, the leading provider of Atlassian apps, is looking for a creative problem-solver and a self-starter with a finesse for project management to join our Information Security team. The Senior Security Analyst will handle diverse security-related tasks and issues for our rapidly growing company, including managing risk through a shared vision with Appfire’s business leaders.
You’ll work closely with our CISO to manage diverse governance, risk and compliance security-related tasks and issues for our rapidly growing company, with a focus on people, practices, systems, and metrics. You’ll be asked to keep up with the latest industry requirements and will assist in the identification of security risks and the associated execution of remediation and corrective action plans, ensuring we are following up with those steps previously agreed upon by the business. Additionally, you’ll conduct regular vendor reviews and ensure compliance with Appfire policy, as well as provide ISO 27001 and other audit support. If you’re a highly organized, detail-oriented expert communicator with eGRC technology experience, let’s chat!
You will be expected to engage in professional development to maintain continual growth in professional skills and knowledge essential to the position, and thrive in a highly collaborative workplace, and actively engage in helping create secure software applications.
Appfire is looking for a Senior Security Analyst. You will report to one of our Managers and be a member of the Information Security Department.
You can choose to work remotely from any location in Poland.
Your everyday tasks will include:
- Work on the coordination and facilitation of Appfire’s security governance goals and initiatives
- Support our sales channels regarding prospect and customer security questions, assessments, and audits, including speaking to technical controls and their alternatives and appropriate risk mitigation.
- Conduct assessments related to vendor risk management and follow up on associated findings.
- Provide support and act as key stakeholder and lead of regulatory and compliance initiatives (e.g. ISO 27001, SOC2, GDPR, etc.).
- Identify, document, and track information security policy related non-conformities and assist in developing and monitoring corrective action plans.
- Assist in identifying & tracking information security risks, assessing impact, and tracking the execution of mitigation plans.
- Assist in tracking information security risk acceptances and exceptions and monitoring the execution of remediation plans.
- Track and ensure adequate and timely resolution to all audit and risk assessment findings/issues relating to information security.
- Assist in the monitoring of business continuity (BC) and disaster recovery (DR) planning and testing.
- Develop control key performance indicators (KPI) to ensure compliance-related controls are operating to an acceptable tolerance level.
- Perform periodic compliance checks across the Appfire organization and develop and define associated metrics to allow clear visibility into Appfire governance, risk, and compliance status
- Work on the coordination and execution of integration plans for Appfire acquisitions.
- Moderate the annual review and update of information security related policies and processes.
- Participate in and manage annual security awareness campaigns.
- Evaluate and recommend GRC related technologies and solutions for future implementation.
- Handle sensitive and/or confidential material and information with suitable discretion
Skills and experience you'll need to succeed:
- Bachelor’s Degree in Computer Science, Information Security, Engineering, related curriculum, or equivalent experience.
- 5+ years of experience working in information security risk and/or compliance roles.
- Knowledge of common Information Security frameworks such as CIS, ISO 27001 & SOC 2
- Prior experience with cloud-based security tools, technologies, and controls a plus (e.g, Amazon AWS, Azure, Heroku, GCP)
- Ability to work effectively within a fast-paced, changing environment that is going through high growth.
- A self-starter with the demonstrated ability to take initiative, who can proactively identify issues/opportunities and recommend actions.
- Strategic analysis, creative problem solving, and business judgment are required
- Excellent interpersonal and communication skills
- CISA, CISSP or similar security/GRC focused certifications a plus.
Beyond the resume skills that match our culture and this role:
- You are dedicated to elevating client and co-worker experiences, knowing that exceptional work centers on serving others.
- You adapt swiftly to new business demands, understanding that change fuels collective and individual growth.
- You excel in communication, effectively connecting in remote/hybrid environments using tools like Slack, Zoom, and G Suite and through occasional in-person events.
- You have exceptional coaching, mentoring, and people development skills.
We offer:
Financial benefits
- Every Appfire employee is eligible for company equity.
- Home Office allowance – 200 PLN/month to cover your electricity and internet bills.
- MyBenefit Platform – 150 PLN/month to spend on shopping, culture and entertainment, Multisport, travel, and more.
- Lunch Card – 300 PLN/month to spend on groceries/restaurants (excluding alcohol and other excise duties items).
- You can apply for a 50% tax-deductible cost on creative works (AKUP/IP tax-deductible costs).
Skills development benefits
- Access to the Appfire University learning platform – a hub of knowledge, interactive resources, and engaging instructor-led courses designed to fuel your learning journey with unparalleled depth and accessibility.
- English language courses.
PTO, health & well-being
- 26 working days of paid annual leave, regardless of years of experience.
- Wellness Days – additional time off each month to recharge and take care of yourself.
- Private healthcare.
- Life Insurance.
Volunteering
- 3 fully paid days each year to participate in Appfire Town, Appfire’s Corporate Social Responsibility (CSR) Program.
Other
- Indefinite Employment contract from day one, no trial periods.