CyprusTech.Careers logoCyprusTech.Careers
Salary guide
Get started — it's freeSign in
This position is no longer accepting applications.Browse similar open roles below.
Browse open jobs
Jobs/Senior Governance, Risk and Compliance Analyst
Payabl
PayablCurated· 12 AUG

Senior Governance, Risk and Compliance Analyst

Limassol On-site FULL TIME

About the role

payabl. is looking for a Senior GRC Analyst to join its Information Security team in Limassol, Cyprus.

This is a hands-on role covering governance, risk, compliance, third-party oversight, privacy operations and audit readiness within a regulated financial-services environment.

You will take ownership of key GRC programmes rather than simply maintaining existing processes. This includes managing information-security policies, developing the third-party risk-management programme, operating the company’s GRC platform and improving how controls and evidence are monitored and collected.

You will also work closely with the Data Protection Officer on privacy activities across multiple jurisdictions and coordinate regulatory and audit requirements covering areas such as DORA, PCI DSS, ICT controls and central-bank requests.

The role reports to the Head of Information Security.

What you’ll be doing

  • Manage the complete lifecycle of information-security and governance policies.

  • Maintain a clear policy structure, ownership model and review schedule.

  • Build and operate the organisation’s third-party risk-management programme.

  • Maintain the vendor-risk register and assessment process.

  • Introduce risk and compliance checks into supplier onboarding.

  • Manage vendor-review cycles and DORA-related third-party oversight.

  • Take ownership of the organisation’s GRC platform.

  • Improve continuous control monitoring and automated evidence collection.

  • Reduce manual compliance work through automation.

  • Work with the Data Protection Officer to support privacy operations across multiple jurisdictions.

  • Coordinate regulatory, compliance and assurance activities.

  • Manage evidence requirements for external ICT audits.

  • Support PCI DSS compliance and assessment cycles.

  • Coordinate DORA-related evidence and regulatory requests.

  • Support internal audit activities and central-bank information requests.

  • Maintain clear documentation for auditors, regulators and internal stakeholders.

  • Help integrate AI-related risks and regulatory expectations into the organisation’s control framework.

  • Assess AI vendors through the third-party risk-management process.

  • Continuously improve GRC processes, tooling and automation.

What we’re looking for

  • At least five years of professional experience in GRC, information-security governance or operational risk.

  • Experience working within regulated financial services such as payments, electronic money, banking or fintech.

  • Hands-on experience in at least two of the following areas:

    • PCI DSS

    • DORA implementation

    • GDPR and privacy operations

    • Third-party risk management

    • Audit and assurance

  • Demonstrated experience building or significantly improving governance, risk or compliance programmes.

  • Strong understanding of regulatory and information-security controls.

  • Experience working directly with auditors, regulators or supervisory authorities.

  • Excellent written English suitable for regulatory submissions, audit responses and formal documentation.

  • Strong ownership and organisational skills.

  • The ability to manage multiple compliance activities and deadlines.

  • Practical experience using AI tools to improve productivity and the quality of your own work.

  • A proactive approach to identifying opportunities for process improvement and automation.

Skills that would be an advantage

  • Knowledge of DORA.

  • Knowledge of PSD2.

  • Familiarity with EBA ICT and outsourcing guidelines.

  • Knowledge of FCA operational-resilience requirements.

  • Experience with PCI DSS.

  • CIPP/E certification.

  • CISA certification.

  • CRISC certification.

  • ISO 27001 Lead Auditor or Lead Implementer certification.

  • Experience implementing or administering a GRC platform.

  • Experience with low-code automation.

  • Basic scripting skills.

  • Familiarity with AI governance and AI-related third-party risk.

Work location

This position is based in Limassol, Cyprus.

The role reports directly to the Head of Information Security.

Benefits

Benefits for Cyprus-based employees include:

  • 25 days of annual leave.

  • Cyprus public holidays.

  • 10 days of sick leave.

  • Provident Fund participation after successful completion of probation.

  • Annual learning and professional-development budget after probation.

  • €150 monthly Wolt allowance.

  • Access to participating gyms and sports facilities through a sports-benefits programme.

  • Complimentary office parking.

  • Free Greek-language lessons twice per week.

  • Local employee discounts and access to selected entertainment and sporting events.

  • Company-wide celebrations and international employee events.

  • Potential eligibility for a company car after one year, depending on performance and availability.

Benefits may vary according to employee location and contract type and should be confirmed directly with payabl. during the recruitment process.

Recruitment process

The expected selection process includes:

  1. Talent Acquisition and technical screening – An initial conversation covering your experience, career background and motivation, together with a short technical assessment.

  2. Hiring Manager interview – A meeting with the Head of Information Security focused on your GRC experience, achievements and suitability for the position.

  3. Final interview – A discussion with senior Technology leadership, which may include the CTO, CPO and Head of Information Security, covering collaboration, expectations, team fit and the wider technology environment.

The exact interview structure may vary depending on the applicant and business requirements.

About payabl.

payabl. is a financial-technology and payments company providing payment infrastructure and services to businesses across multiple markets.

Its technology, information-security and compliance teams operate within a highly regulated environment where security, operational resilience, risk management and regulatory compliance are central to the company’s platforms and services.

How to apply

Applicants should submit an up-to-date CV through payabl.’s official careers page.

Your application should clearly demonstrate:

  • Your total GRC or information-security governance experience.

  • Experience within payments, banking, e-money or another regulated financial-services environment.

  • GRC programmes you have built or significantly improved.

  • Your experience with DORA, PCI DSS, GDPR, third-party risk or audit and assurance.

  • Experience managing policy frameworks and review cycles.

  • Your involvement in vendor-risk assessments and third-party oversight.

  • Experience working with GRC platforms and compliance automation.

  • Examples of interaction with regulators, auditors or supervisory authorities.

  • Relevant certifications such as CIPP/E, CISA, CRISC or ISO 27001.

  • Any scripting, low-code automation or AI-governance experience.

Applications are processed directly by payabl. cyprustech.careers is presenting this vacancy for informational purposes and is not acting as the employer or recruitment agency for this position.