Senior Governance, Risk and Compliance Specialist
FullTimeJob Overview
CUBE are a global RegTech business defining and implementing the gold standard of regulatory intelligence for the financial services industry. We deliver our services through intuitive SaaS solutions, powered by AI, to simplify the complex and everchanging world of compliance for our clients.Â
Â
Why us?
đ CUBE is a globally recognized brand at the forefront of Regulatory Technology. Our industry-leading SaaS solutions are trusted by the worldâs top financial institutions globally.
đ In 2024, we achieved over 50% growth, both organically and through two strategic acquisitions. Weâre a fast-paced, high-performing team that thrives on pushing boundariesâcontinuously evolving our products, services, and operations. At CUBE, we donât just keep up we stay ahead.
đą We believe our future is built by bold, ambitious individuals who are driven to make a real difference. Our âmake it happenâ culture empowers you to take ownership of your career and accelerate your personal and professional development from day one.
đ With over 700 CUBERs across 19 countries spanning EMEA, the Americas, and APAC, we operate as one team with a shared mission to transform regulatory compliance. Diversity, collaboration, and purpose are the heartbeat of our success.
đĄ We were among the first to harness the power of AI in regulatory intelligence, and we continue to lead with our cutting-edge technology. At CUBE, You will work alongside some of the brightest minds in AI research and engineering in developing impactful solutions that are reshaping the world of regulatory compliance.
Purpose
Provide senior analyst support across technology governance, risk, and compliance by keeping GRC data, workflows, actions, and reporting current and reliable. This role helps the organisation maintain audit readiness, strengthen accountability for risk actions, and provide clear visibility of compliance status, control health, and remediation progress.
Key Responsibilities
â˘ââMaintain GRC portals, including risk registers, control records, evidence libraries, issue logs, policy links, assessment workflows, dashboards, and reporting views.
â˘ââEnsure GRC portal data is complete, accurate, consistently classified, and aligned to agreed standards for risk, control, issue, and evidence management.
â˘ââCoordinate portal updates, access reviews, workflow changes, template improvements, and reporting enhancements with technology, security, and business stakeholders.
â˘ââPerform regular data quality checks across GRC records and follow up with owners to correct missing, outdated, or inconsistent information.
â˘ââOwn and manage the risk action calendar, covering risk assessments, control reviews, evidence refresh cycles, policy reviews, audit milestones, remediation deadlines, governance forums, and leadership reporting.
â˘ââTrack action owners, due dates, dependencies, and completion status for risk and compliance activity.
â˘ââProactively follow up on upcoming, overdue, or blocked actions, escalating material risks, delays, and dependencies through the appropriate governance channels.
â˘ââUse the calendar to support forward planning, workload visibility, and timely completion of recurring GRC obligations.
â˘ââSupport technology risk assessments, control reviews, compliance checks, and issue management activity across security, technology, and business teams.
â˘ââMaintain and update risk registers, control mappings, compliance evidence, remediation plans, and exception records.
â˘ââSupport the interpretation of policy, regulatory, contractual, and audit requirements into practical actions for control and risk owners.
â˘ââMonitor remediation progress and help ensure risk treatment plans are realistic, tracked, evidenced, and closed appropriately.
â˘ââPrepare risk and compliance status reports, dashboards, metrics, and packs for governance forums and leadership review.
â˘ââCoordinate evidence collection for internal audits, external audits, customer assurance requests, and compliance reviews.
â˘ââValidate that evidence is current, complete, clearly labelled, and mapped to the relevant controls or obligations.
â˘ââSupport audit walkthroughs, control owner preparation, finding tracking, and post-audit remediation follow-up.
â˘ââMaintain reusable evidence and control documentation to reduce repeated requests and improve audit readiness.
â˘ââPartner with security, technology, legal, procurement, internal audit, and business teams to drive clear ownership of GRC actions.
â˘ââProvide guidance to control and risk owners on GRC processes, portal usage, evidence expectations, and action tracking.
â˘ââIdentify opportunities to improve GRC workflows, portal usability, reporting, data quality, and stakeholder accountability.
â˘ââContribute to the maintenance of GRC procedures, guidance materials, and operating rhythms.
â˘ââProvide support with the compliance inbox.
Skills & Competencies
â˘ââStrong experience in governance, risk, and compliance operations within a technology, cybersecurity, audit, or regulated environment.
â˘ââPractical experience maintaining GRC tools or portals, including risks, controls, issues, evidence, workflows, dashboards, and reporting.
â˘ââStrong planning and coordination skills, with the ability to manage calendars, action trackers, recurring obligations, and cross-functional follow-ups.
â˘ââGood working knowledge of technology risk management, control frameworks, audit evidence, compliance reporting, and remediation tracking.
â˘ââAbility to interpret risk and compliance requirements and translate them into clear actions for stakeholders.
â˘ââStrong attention to detail and commitment to accurate, well-governed records.
â˘ââConfident communication skills, including the ability to follow up, challenge constructively, and escalate when required.
â˘ââComfortable working with senior stakeholders, control owners, auditors, and technical teams.
â˘ââStrong written documentation skills and the ability to produce clear status reports, dashboards, and governance packs.
â˘ââFamiliarity with frameworks and obligations such as ISO 27001, NIST, SOC 2, SOX, PCI DSS, GDPR, COBIT, or DORA.
â˘ââExperience with GRC platforms such as Vanta, ServiceNow GRC, Archer, OneTrust, LogicGate, AuditBoard, Jira-based risk workflows, or equivalent tooling.
â˘ââExperience supporting third-party risk, policy management, control testing, or regulatory compliance programmes.
â˘ââRelevant certification such as CISA, CRISC, CISM, CISSP, ISO 27001, or equivalent professional experience.
Interested?
If you are passionate about leveraging technology to transform regulatory compliance and meet the qualifications outlined above, we invite you to apply. Please submit your resume detailing your relevant experience and interest in CUBE.â
CUBE is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
Make Your Resume Now