This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Rogo is hiring a GRC Analyst to support our customer trust, security assurance, and compliance programs as we scale globally. This role plays a critical part in how Rogo communicates its security and privacy posture to customers, partners, and internal stakeholders. You will work closely with security, engineering, legal, and go-to-market teams to ensure Rogo’s controls, risk posture, and security practices are clearly understood and accurately represented. This is a hands-on role requiring strong written communication, technical curiosity, and continuous improvement across frameworks relevant to the UK, EU, US, and beyond.
Job Responsibility:
Support Rogo’s customer trust and security assurance processes, including responding to customer security inquiries and risk assessments
Serve as a key point of contact for customer security reviews, partnering with internal teams to provide accurate, consistent, and timely responses
Maintain and improve Rogo’s security documentation and response materials, ensuring alignment with current systems and controls
Collaborate with security and engineering teams to understand and articulate technical controls in a customer-facing context
Support compliance initiatives across frameworks such as SOC 2, ISO 27001, ISO 42001, EU AI Act, UK Cyber Essentials, and GDPR, including evidence collection and audit readiness
Identify common themes and gaps surfaced through customer inquiries and contribute to continuous improvement of security and compliance practices
Help streamline and scale trust-related workflows as customer volume and enterprise requirements grow
Requirements:
Experience supporting customer-facing security, compliance, or trust functions at a SaaS or cloud-native company
Comfortable translating technical security concepts into clear, concise written responses
Understand common enterprise security expectations across areas such as cloud infrastructure, access control, data protection, and incident response
Detail-oriented and capable of managing multiple parallel requests without sacrificing quality
Communicate clearly with both technical and non-technical stakeholders
Exercise strong judgment when handling sensitive or ambiguous security questions
Enjoy operating at the intersection of security, compliance, and customer engagement
Nice to have:
Experience working with security questionnaires, audits, or third-party risk assessments
Exposure to cloud security concepts (AWS/GCP, Kubernetes, IAM)
Experience improving or scaling trust, GRC, or compliance processes in growing organizations
Prior experience supporting enterprise customers
Comfort engaging with financial services customers on security, risk, and compliance topics