Analyst - Governance Risk & Compliance (ISO 27001, SOC 2)

Trimble , Kyiv, 2025-08-13 13:36:36

Описание

Your Title: Analyst - Governance Risk & Compliance

Job Location: Ukraine

Our Department:Corporate Cybersecurity

Trimble is transforming the way the world works by delivering products and services that connect the physical and digital worlds. Core technologies in positioning, modeling, connectivity and data analytics enable customers to improve productivity, quality, safety, and sustainability. From purpose built products to enterprise lifecycle solutions, Trimble software, hardware and services are transforming a broad range of industries such as agriculture, construction, geospatial and transportation and logistics. 

In order to improve integrity between physical and digital worlds, Governance, Risk and Compliance (GRC) facilitates the integrated collection of capabilities necessary to support connected performance. GRC doesn't burden the business, it supports and improves it by adding value through establishing efficiencies, centralizing policy and creating metrics to reduce risk to maintain Trimble brand equity. GRC resides within the corporate Trimble Cybersecurity team.

To be considered for this position, you must be familiar with security frameworks and security control auditing; (, ISO 27001, ISO 27701, SOC 2, NIST*, CSF), risk assessments and scoring, conducting gap analysis, internal audits, and external audit coordination. Proficiency in English is essential.

This Opportunity

You are a self-motivated, mildly technical but versatile individual contributor looking to fill a Cybersecurity Compliance Analyst role by joining a diverse and collaborative international cybersecurity team for a large dynamic publicly traded company. You will be responsible for helping to ensure Trimble’s product portfolio maintain compliance to an array of frameworks (ISO 27001, ISO 27701, SOC 1 & 2, NIST*). You will be a crucial member of our organization, working to achieve our customers expectations in the area of Compliance & Audit. 

The role requires an individual who works well independently and as part of a global team by adding value through processes optimization and managing a diverse portfolio of Trimble products seeking compliance to existing and new standards & frameworks.

Key Responsibilities

Perform ISO 27001, ISO 27701, SOC 2 & NIST 800-171 gap analysis and recommend process, procedural, documentation and tooling recommendations to remediate.

Improve Compliance and certification scope efficiency via review and enhancements of the Trimble Common Control Framework

Perform ISO 27001 & ISO27701 Internal Audits.

Perform SOC 2, NIST 800-171 Internal & External Audits

Contribute to annual policy revisions and maintenance of the IMS.

Constantly coordinate with key business stakeholders and the external auditor

Present metrics derived from the Integrated Management System, audit results, trends in risk, and corrective action plans to senior leadership.

Contribute to the creation of processes and procedures that increase efficiency of the overall compliance program across all standards and frameworks.

Collaborate with Cybersecurity team members, Trimble businesses across various geographies.

Contribute to risk management processes to ensure business risk posture is properly calculated and proactively managed.

Produce and analyze information that will accurately demonstrate the risk posture of each business and drive actions to reduce and manage technical risks.

Be able to understand and communicate technical risks to a broad set of stakeholders. 

Communication

The Trimble Cybersecurity team serves the entire organization. Trimble is divided into several Business focused Sectors and Divisions. This role will communicate with:

Cybersecurity, IT and GRC teams

Trimble leadership

Divisional & Sector Cybersecurity representatives

Software development staff

Other global functions (Human Resources, Legal as required

No communication with Trimble customers required

Skills / Competencies

Working knowledge of ISO 27001, ISO 27701, SOC 2 & NIST 800-171

Designing audit controls spanning ISO 27001, ISO 27701, SOC 2 & NIST 800-171

Ability to write policy and interpret complex business changes, as they arise

Comprehensive understanding of risk management standards and guidelines.

General IT knowledge (networking, cloud computing, software development)

General knowledge in Data Privacy (GDPR, CCPA and other regulations)

A passion for user-centric information that is clear and actionable, attention to detail focused on delivering accurate and creative metrics.

Ability to make effective, timely decisions with clear reasoning

Ability to quickly establish a broad understanding of an issue with limited available information and outline the steps required to bring it to a successful conclusion

Excellent organizational and presentation skills

Effective communication skills (verbal and written) and time management skills

Flexible approach to working in a changing environment and can work well under pressure with dynamically changing priorities

Ability to work as part of a collaborative global team, prepared to remain resilient to complete tasks to conclusion.

Qualifications / Experience

Preferable a relevant degree in Data Science, Computer Science or Engineering (Software or Electrical)

Current general security certifications (, SEC+, GSEC) encouraged but not required

ISO 27001 Certified Internal / Lead Auditor and or equivalent experience.

2 years experience working with ISO 27001, ISO 27701, SOC 2 and or NIST 800-171 

Proficiency in English (written and oral)

2 years experience in a risk management role, information security role or systems engineer/administrator role in a large, international software company

Hands-on experience with business and GRC tools such as: Jira Service Desk

Demonstrated experience in collecting information from disparate data sources and formulating into reports that can be presented to various audiences

Intermediate level experience with Windows and Linux/Unix operating systems

Intermediate level cloud knowledge within AWS, Azure and GCP

Intermediate level scripting knowledge and experience of Splunk and creating queries

Experience of using AI to reduce manual process and procedure

Excellent analytical, problem-solving and decision making skills.

Trimble's Inclusiveness Commitment

We believe in celebrating our differences. That is why our diversity is our strength. To us, that means actively participating in opportunities to be inclusive. Diversity, Equity, and Inclusion have guided our current success while also moving our desire to improve. We actively seek to add members to our community who represent our customers and the places we live and work. We have programs in place to make sure our people are seen, heard, and welcomed and most importantly that they know they belong, no matter who they are or where they are coming from.

Trimble’s Privacy Policy

Похожие вакансии

  • Data Governance Manager

    JTI 14 дней назад
    ... metrics and ensure compliance with data related policies, standards, roles and responsibilities, and adoption requirementsDefine roles and responsibilities related to Data Governance and ensure clear accountability ... reply within 2 weeks after the application deadline ...
    jobs.jti.com
  • Data Governance Manager

    JTI 14 дней назад
    ... metrics and ensure compliance with data related policies, standards, roles and responsibilities, and adoption requirementsDefine roles and responsibilities related to data governance and ensure clear accountability ... reply within 2 weeks after the application deadline ...
    jobs.jti.com
  • Data Governance Manager

    JTI 14 дней назад
    ... metrics and ensure compliance with data related policies, standards, roles and responsibilities, and adoption requirementsDefine roles and responsibilities related to data governance and ensure clear accountability ... reply within 2 weeks after the application deadline ...
    jobs.jti.com
  • National Compliance Specialist

    FAO , Kyiv, 3 дня назад
    ... integration of risk management, compliance, and quality assurance into programme activities and operations.2. Compliance and Fiduciary Oversight • Provide guidance ... financial reporting, risk management and compliance.9. Perform other related duties ...
    ua.talent.com
  • National Compliance Specialist

    FAO , Kiev, 4 дня назад
    ... integration of risk management, compliance, and quality assurance into programme activities and operations.2. Compliance and Fiduciary Oversight • Provide guidance ... financial reporting, risk management and compliance.9. Perform other related duties ...
    ua.talent.com
  • Information Security Risk Manager

    JTI 14 дней назад
    ... promptly to appropriate parties.Governance and Compliance:Ensure compliance with industry standards (e.g., ISO 27001, NIST,) and regulatory requirements (e.g., GDPR).Maintain and improve the D&IT and cybersecurity risk management framework.Conduct audits ...
    jobs.jti.com
  • GRC Engineer

    Andersen Ukraine 14 дней назад
    ... , standards, and procedures to ensure compliance with regulatory requirements (e.g., ISO 27001, SOC 2, GDPR, NIST). Conducting risk assessments and audits, identifying security ...
    people.andersenlab.com
  • Compliance Manager

    Sigma Software , , месяц назад
    Overview Required skills ISO 27001 strong ISO 9001 strong EU GDPR strong English strong We are looking for a professional who will provide the highest level of compliance management expertise to Sigma Software ...
    ua.talent.com
  • ICT Coordinator, NPSA-9, DS-Kyiv, Nationals only

    PNUD Argentina , Kyiv, 24 дня назад
    ... groups. Collaborate with the Component 2 team to ensure the quality ... & Technology User Experience and Business Analyst Capacity to translate efficiently users’ ... of relevant work experience  Minimum 2 years (with Master’s degree) or ...
    ua.talent.com
  • Quality and Processes Specialist

    Miratech , , 2 дня назад
    ... risk identification, documentation, and mitigation efforts ... , or compliance roles, preferably in IT outsourcing or tech environments. Solid knowledge of ISO 9001 and ISO IEC 27001. Familiarity with ISO 22301 and 31000, BPMN 2.0.Experience with ITSM ...
    ua.talent.com
  • AML Lead

    FYST , Kyiv, 15 дней назад
    ... Communication: Prepare detailed compliance and risk management reports for internal and ... enhance overall regulatory compliance and risk awareness across the organization. WHAT ... experience in AML, compliance, or risk management roles within the financial ...
    ua.talent.com
  • KYC Operations Analyst - Maker

    05056 Joint Stock Company Citibank , Kiev, день назад
    ... Analyst - Maker responsible for Anti-Money Laundering (AML) monitoring, governance, oversight and regulatory reporting activities in coordination with the Compliance ... , Risk Controls and Monitors, Risk Identification and Assessment, Risk Remediation.-----------------------------------------...
    ua.talent.com
  • KYC Operations Analyst (fixed term)

    05056 Joint Stock Company Citibank , Kiev, день назад
    ... Analyst responsible for Anti-Money Laundering (AML) monitoring, governance, oversight and regulatory reporting activities in coordination with the Compliance ... Escalation, Risk Controls and Monitors, Risk Identification and Assessment, Risk Remediation.--------------------------------------...
    ua.talent.com
  • Analyst - Sustainable Infrastructure and Energy

    The European Bank for Reconstruction and Development , Kyiv, 23 дня назад
    ... Bank. 2. Portfolio Monitoring, Value Creation and ... the Analyst is assigned as part of the project team, including compliance with project agreements and Bank ... risk factors and monitoring and assessing covenant compliance; • As requested by the operation ...
    ua.talent.com
  • Fintech Сompliance Engineer

    Andersen Ukraine 14 дней назад
    ... experience in identifying and interpreting compliance requirements from various regulatory frameworks (e.g., GDPR, PCI DSS, SOX, ISO 27001). Experience working with projects involving ...
    people.andersenlab.com
  • Financial Analyst

    RISK , Kyiv, 25 дней назад
    ... looking for a skilled Financial Analyst to join our team and ... in financial analytics.QualificationsMandatory Skills:2+ years of hands-on experience ...
    ua.talent.com
  • Employee Relations Manager

    JTI 14 дней назад
    ... in the organization while ensuring compliance with local laws and company- ... ”.Represents P&C in factory compliance initiatives (ex: Audits ISO FSMS SH&E)Responsible for ... Employee Relations, with at least 2 years in a managerial role. ...
    jobs.jti.com
  • SMM Manager (iGaming)

    RISK , Lviv, 3 дня назад
    ... IGaming, betting, or high-risk niches)Hands-on expertise with ... of content moderation and risk management in regulated platformsSkills in ... opportunity to take a RISK and come out on top. ... solutions into reality.At RISK, we believe that our people ...
    ua.talent.com
  • SMM Manager (iGaming)

    RISK , Kyiv, 23 дня назад
    ... IGaming, betting, or high-risk niches)Hands-on expertise with ... of content moderation and risk management in regulated platformsSkills in ... opportunity to take a RISK and come out on top. ... solutions into reality.At RISK, we believe that our people ...
    ua.talent.com
  • ICITAP Export Control and Trade Compliance Advisor

    Amentum , Kyiv, месяц назад
    ... with public-private outreach efforts, compliance seminars, and government consultations. REQUIRED ... contributions to STC legislation or compliance frameworks. Experience conducting Red Team or risk-based assessments in aviation, nuclear, ...
    ua.talent.com
  • Compliance Engineer (Muscat, Oman)

    Andersen Ukraine 14 дней назад
    ... project is to support the governance, strategic planning, and operational alignment ... the Super App ecosystem. Aligning governance structures with regulatory requirements and compliance needs. Conducting stakeholder workshops and ...
    people.andersenlab.com
  • FX Risk Manager / Dealer

    Propmetry Limited , , 6 дней назад
    ... company development department.Strict, Prudent Risk ManagementYou can have guts, but ... practices. That’s why we treat risk management with the utmost seriousness … ... controls and suggesting improvements.Analysing risk incidents and performing Root Cause ...
    ua.talent.com
  • Information Security Compliance Specialist

    Miratech , , месяц назад
    ... and external security audits, ensuring compliance with security frameworks (ISO 27001, GDPR, etc.) and providing detailed ... requirements.Work with security processes, risk assessments, and incident investigations, implementing ...
    ua.talent.com
  • AML & Compliance Specialist

    FYST , , 7 дней назад
    ...  years of experience in AML, Compliance, or Risk Management roles within the financial ...
    ua.talent.com
  • EHS Manager

    JTI 14 дней назад
    ... , branches, and equipment to ensure compliance with standards.d. Train branches on risk assessment process, develop capabilities of branch personnels risk assessment capabilities, and support branches during risk assessment exercises.e. Develop emergency ...
    jobs.jti.com
  • EHS Engineer

    JTI 14 дней назад
    ... all sites to ensure compliance with ISO 45001 14001 requirements are met). ... manufacturing industries, with 2 years of experience in ISO 45001, ISO14001 internal auditor & other ... related legal requirements (Risk assessments, operating instructions, list of ...
    jobs.jti.com
  • Influencer Marketing Manager

    RISK , Kyiv, 2 дня назад
    ... approaches to audience specifics;Ensure compliance with platform rules and advertising ... an opportunity to take a RISK and come out on top. ... extraordinary solutions into reality.At RISK, we believe that our people ...
    ua.talent.com
  • Middle CRM Manager

    RISK , Lviv, 3 дня назад
    ... an opportunity to take a RISK and come out on top. ... extraordinary solutions into reality.At RISK, we believe that our people ...
    ua.talent.com
  • CRM Manager

    RISK , Kyiv, 3 дня назад
    ... an opportunity to take a RISK and come out on top. ... extraordinary solutions into reality.At RISK, we believe that our people ...
    ua.talent.com
  • Analytics Team Lead

    RISK , Kyiv, 9 дней назад
    ... insights for product, marketing, finance, risk, and compliance teams.Collaborate with cross-functional ... will be a strong advantage.2+ years of hands-on experience ...
    ua.talent.com
  • Middle CRM Manager

    RISK , Kyiv, 15 дней назад
    ... an opportunity to take a RISK and come out on top. ... extraordinary solutions into reality.At RISK, we believe that our people ...
    ua.talent.com
  • Reporting Manager (IFRS)

    RISK , Kyiv, месяц назад
    ... improve reporting procedures and ensure compliance with IFRS.Responsibilities: Prepare monthly ... an opportunity to take a RISK and come out on top. ... extraordinary solutions into reality.At RISK, we believe that our people ...
    ua.talent.com
  • Growth Product Manager

    RISK , Kyiv, месяц назад
    ... product performanceQualificationsSkills and Experience Needed:2+ years of experience Product mindset — ... an opportunity to take a RISK and come out on top. ... extraordinary solutions into reality.At RISK, we believe that our people ...
    ua.talent.com
  • Assistant 2 - Consumer Industrial Products Group - Audit & Assurance Department

    13 часов назад
    ... audit, consulting, corporate finance, enterprise risk, and tax and legal services. ... internal controls, and assess the risk of material misstatement of the ... of the financial statements in compliance with local and international accounting ...
    careers.deloitte.ru
  • Communications and Outreach Analyst, NPSA-8, DS - Kyiv, Nationals Only

    PNUD Argentina , Kyiv, 5 дней назад
    ... vulnerable people, and strengthening of governance in the formulation and implementation ... infrastructure for basic services Output 2: Debris management and recycling Output ... Organization. The Communication and Outreach Analyst will work under supervision of ...
    ua.talent.com
  • IT Business Solutions Analyst

    JTI 14 дней назад
    ... of centralized systems. Additionally, the analyst upholds compliance with JTI’s governance, project management methodologies, and security ... standards.Promote cost efficiency and risk reduction.InnovationExplore new technologies and ...
    jobs.jti.com
  • Business Analyst

    TechMagic Львів, Україна 12 часов назад
    ... product ecosystem. Approximately 2-3 years in development; however, ... team: 1 Solutions Architect, 2 Business Analyst, 1 Project Manager, 7 Salesforce ... with Recruiter (30 minutes)2-nd stage — interview with our Business Analyst and Recruiter (1 hour)3- ...
    www.techmagic.co
  • Middle Application Security Engineer

    SoftServe , , 21 день назад
    ... recognized standards (ISO 27000, CIS Benchmarks, NIST, SOC 2, HIPAA, PCI DSS, etc.) and tailored to both short- and long-term business goals.Our comprehensive solutions offer exceptional visibility into identified security risks, ensure compliance with ...
    ua.talent.com
  • Chief Legal Officer for NDA iGaming Provider

    TalentIn , Kyiv, месяц назад
    ... Structuring & Corporate Governance Manage setup and maintenance of legal entities globally Ensure compliance with corporate laws, tax regulations, and governance standards Support international structuring ... impact Risk Management & Dispute Resolution Assess and ...
    ua.talent.com

Карточка вакансии:

  • Должность Analyst - Governance Risk & Compliance (ISO 27001, SOC 2)
  • Размещено: 2025-08-13 13:36:36
  • Город , Kyiv,
  • Зарплата:
  • Компания: Trimble