Senior GRC Security Analyst
At Appfire, we believe that great work happens when people get to choose how they work. After 20 years of creating software that empowers teams to break silos and collaborate seamlessly, we've learned that one size does not fit all. That’s why at Appfire, you choose.
Choose to work where you thrive: Whether from home, in one of our offices, or while exploring the world, you decide where you’re most productive. From hardware and software to access to two decades of collective wisdom on working effectively in a remote-first company, we’ve got you covered.
Choose to balance your life without compromise: Plan your workday around your needs and what matters most to you. Enjoy flexible time off without the hassle of complicated approvals. From day one, we trust you to deliver quality work without sacrificing your personal life, hobbies, loved ones, and well-being.
Choose to grow on your terms: Take charge of your professional growth with access to online learning platforms, facilitated training, leadership programs, and internal hackathons. Collaborate with a global team to gain fresh perspectives. When you're ready for a new challenge, our internal mobility program is here to support your journey.
No one knows you better than you do. So join us and customize your experience. Choose how you want to work. Choose Appfire.
About the role
Do you have a strong understanding of information security GRC operations and technologies? Have you built lasting relationships with business owners and vendors? Appfire, the leading provider of Atlassian apps, is looking for a creative problem-solver and a self-starter with a finesse for project management to join our Information Security team. The Senior Security Analyst will handle diverse security-related tasks and issues for our rapidly growing company, including managing risk through a shared vision with Appfire’s business leaders.
You’ll work closely with our CISO to manage diverse governance, risk and compliance security-related tasks and issues for our rapidly growing company, with a focus on people, practices, systems, and metrics. You’ll be asked to keep up with the latest industry requirements and will assist in the identification of security risks and the associated execution of remediation and corrective action plans, ensuring we are following up with those steps previously agreed upon by the business. Additionally, you’ll conduct regular vendor reviews and ensure compliance with Appfire policy, as well as provide ISO 27001 and other audit support. If you’re a highly organized, detail-oriented expert communicator with eGRC technology experience, let’s chat!
You will be expected to engage in professional development to maintain continual growth in professional skills and knowledge essential to the position, and thrive in a highly collaborative workplace, and actively engage in helping create secure software applications.
Appfire is looking for a Senior Security Analyst. You will report to one of our Managers and be a member of the Information Security Department.
You can choose to work remotely from any location in Poland.
Your everyday tasks will include:
- Work on the coordination and facilitation of Appfire’s security governance goals and initiatives
- Support our sales channels regarding prospect and customer security questions, assessments, and audits, including speaking to technical controls and their alternatives and appropriate risk mitigation.
- Conduct assessments related to vendor risk management and follow up on associated findings.
- Provide support and act as key stakeholder and lead of regulatory and compliance initiatives (e.g. ISO 27001, SOC2, GDPR, etc.).
- Identify, document, and track information security policy related non-conformities and assist in developing and monitoring corrective action plans.
- Assist in identifying & tracking information security risks, assessing impact, and tracking the execution of mitigation plans.
- Assist in tracking information security risk acceptances and exceptions and monitoring the execution of remediation plans.
- Track and ensure adequate and timely resolution to all audit and risk assessment findings/issues relating to information security.
- Assist in the monitoring of business continuity (BC) and disaster recovery (DR) planning and testing.
- Develop control key performance indicators (KPI) to ensure compliance-related controls are operating to an acceptable tolerance level.
- Perform periodic compliance checks across the Appfire organization and develop and define associated metrics to allow clear visibility into Appfire governance, risk, and compliance status
- Work on the coordination and execution of integration plans for Appfire acquisitions.
- Moderate the annual review and update of information security related policies and processes.
- Participate in and manage annual security awareness campaigns.
- Evaluate and recommend GRC related technologies and solutions for future implementation.
- Handle sensitive and/or confidential material and information with suitable discretion
Skills and experience you'll need to succeed:
- Bachelor’s Degree in Computer Science, Information Security, Engineering, related curriculum, or equivalent experience.
- 5+ years of experience working in information security risk and/or compliance roles.
- Knowledge of common Information Security frameworks such as CIS, ISO 27001 & SOC 2
- Prior experience with cloud-based security tools, technologies, and controls a plus (e.g, Amazon AWS, Azure, Heroku, GCP)
- Ability to work effectively within a fast-paced, changing environment that is going through high growth.
- A self-starter with the demonstrated ability to take initiative, who can proactively identify issues/opportunities and recommend actions.
- Strategic analysis, creative problem solving, and business judgment are required
- Excellent interpersonal and communication skills
- CISA, CISSP or similar security/GRC focused certifications a plus.
Beyond the resume skills that match our culture and this role:
- You are dedicated to elevating client and co-worker experiences, knowing that exceptional work centers on serving others.
- You adapt swiftly to new business demands, understanding that change fuels collective and individual growth.
- You excel in communication, effectively connecting in remote/hybrid environments using tools like Slack, Zoom, and G Suite and through occasional in-person events.
- You have exceptional coaching, mentoring, and people development skills.
We offer:
-
Salary Ranges: Perm (UoP) 14 700 - 25 000 PLN gross/month.
Financial benefits
-
Every Appfire employee is eligible for company equity.
-
Home Office allowance – 200 PLN/month to cover your electricity and internet bills.
-
MyBenefit Platform – 150 PLN/month to spend on shopping, culture and entertainment, Multisport, travel, and more.
-
Lunch Card – 300 PLN/month to spend on groceries/restaurants (excluding alcohol and other excise duties items).
-
You can apply for a 50% tax-deductible cost on creative works (AKUP/IP tax-deductible costs).
Skills development benefits
-
Access to the Appfire University learning platform – a hub of knowledge, interactive resources, and engaging instructor-led courses designed to fuel your learning journey with unparalleled depth and accessibility.
-
English language courses.
PTO, health & well-being
-
26 working days of paid annual leave, regardless of years of experience.
-
Wellness Days – additional time off each month to recharge and take care of yourself.
-
Private healthcare.
-
Life Insurance.
Volunteering
-
3 fully paid days each year to participate in Appfire Town, Appfire’s Corporate Social Responsibility (CSR) Program.
Other
-
Indefinite Employment contract from day one, no trial periods.
#LI-Remote
About Appfire
A people-first approach to business
Since its inception, Appfire has been a remote-first company. With 800+ employees (who we call fireflies) across 27 countries, we foster an environment where everyone is respected. We invest in team members by ensuring they grow professionally and personally.
Watch Appfire's Co-founder and CEO Randall Ward talk about his people-first leadership philosophy: https://youtu.be/GXuChQzzowI
Making an impact
At Appfire, corporate social responsibility is driven by team members, family, friends, customers, and partners through Appfire Town. This program brings people together to generate a strong social impact in our local and global communities.
Our CEO believes being philanthropic is integral to operating our business and is not merely the result of our success. In 2015, Appfire joined the Pledge 1% network of organizations committed to philanthropy. Appfire has since grown our Pledge 1% program to include all four pledge types — product, profit, equity, and employee time. We were among the first to do this, and we’re proud that Pledge 1% is part of our evolution.
Our business
Appfire has been profitable since its inception, with best-in-class free cash flow margins relative to the broader SaaS universe. The company's mission to equip and connect every team so they can plan and deliver their best work has proven successful, producing consistent year-over-year (YoY) growth – with Appfire growing from $10M ARR in 2019 to $200M ARR in 2023.
What’s our secret sauce?
- We follow teams. We do our research and build software that solves real-life collaboration challenges while being easy to implement and a joy to use. We’re proud to support over 20,000 customers and growing, including 55% of the Fortune 500. From the entertainment delivered by Netflix to the devices crafted by Samsung, and Dell Technologies and the financial transactions handled by Visa, Edward Jones, and US Bank, Appfire’s technology is indispensable. Our products also play a pivotal role in streamlining operations and fostering innovation at companies like Tesla and significant institutions such as NASA, Boeing, and many more.
- We enhance. We don’t compete. Our software is designed to give developers, knowledge workers, and teams the ability to extend and get greater value from the platforms they’ve invested in and enjoy. So far, our solutions extend and enhance the capabilities offered by Atlassian, Microsoft, monday.com, and Salesforce.
- We build bridges and invest in our partners. Appfire's success is underscored by the fact that the company has no direct sales team and instead leverages its channel program as its primary path to market. Today, Appfire has a dedicated Channel team supporting 700+ channel partners.
- We make security and privacy a priority, but we also keep it simple for our customers. We’ve achieved International Organization for Standardization (ISO) 27001 and ISO 27017 and System and Organization Controls (SOC) SOC 2, Type I and SOC 2, Type II certifications. In 2022, we launched our award-winning Appfire Trust Center, offering our customers, partners, and prospects the latest security, privacy, and compliance information, including pre-completed questionnaires (CAIQ, SIG, and VSA) with an accelerated NDA process and just one EULA to cover it all.
Market recognition
Appfire has been consistently recognized for company growth, culture, corporate social responsibility, and product excellence and has been included among the Deloitte Technology Fast 500, Inc. Best Workplaces, BuiltIn Best Places to Work, and Inc. 5000. Learn more about our accomplishments, which would not be possible without our team members, partners, and customers: https://appfire.com/awards.
Read about Appfire's continuous growth and mission to equip and connect every team so they can plan and deliver their best work.
Equal Employer Opportunity (EEO)
Appfire is an equal opportunity employer and does not discriminate based on race, color, religion, sex (including pregnancy), sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, veteran status, or any other protected characteristic as defined by applicable law. Our commitment extends to all employment practices, including recruitment, hiring, training, promotion, compensation, benefits, and termination.
Apply for this job
*
indicates a required field