Senior Governance, Risk and Compliance Analyst

Limassol, Limassol, Cyprus on site Until 10/7/2026 5+ years exp H-1B sponsor history First posted August 8, 2026 Last posted August 8, 2026
Job description

The role is about:
We are looking for a Senior GRC Analyst to join our team in Cyprus. This is a hands-on, ownership-driven role that sits at the intersection of governance, risk, compliance, and operational delivery. You will be responsible for managing our policy estate end-to-end, building and running our third-party risk programme (including DORA-related vendor oversight), and taking full ownership of our GRC platform to ensure it delivers continuous control monitoring and automated evidence collection. The role also spans privacy operations across five jurisdictions in partnership with our DPO, and covers the full audit and evidence calendar including PCI DSS, DORA, ICT, and central bank requests. This is not a maintenance role — we are looking for someone who builds, improves, and automates.

  • Location: Limassol, Cyprus 
  • Reporting to: Head of Information Security

What will you do:

  • Own the policy estate end to end: taxonomy, lifecycle, review cadence 
  • Build and run third-party risk management: vendor register, DORA, onboarding gates, assessment cycles
  • Take ownership of our GRC platform and make it earn its keep — continuous control monitoring and automated evidence collection
  • Scale privacy operations with our DPO across five jurisdictions
  • Run the audit and evidence calendar: external ICT audits, PCI DSS, DORA and central bank requests, PCI cycles, internal audit
  • Automate your own workload
  • Contribute to AI governance: AI vendors through the third-party gate, regulatory expectations folded into the control set

What we need:

  • 5+ years in GRC, information security governance or operational risk within regulated financial services — payments, e-money, banking or fintech
  • Hands-on delivery across at least two of: PCI DSS, DORA implementation, GDPR privacy operations, third-party risk, audit & assurance
  • A track record of building programmes, not just operating them.
  • Confident, regulator-grade written English — your work goes to supervisory authorities and auditors as written
  • Genuine working fluency with AI tools applied to your own output

Nice to have

  • DORA, PSD2, EBA ICT/outsourcing guidelines, FCA operational resilience or PCI DSS exposure
  • CIPP/E, CISA, CRISC, ISO 27001 Lead Auditor/Implementer
  • Experience implementing a GRC platform
  • Light scripting or low-code automation

Hiring Process:

  • Step 1 – Thinking in Action (40 minutes) Your first conversation will be with our Talent Acquisition team. We'll explore your background, career journey, motivations, and overall fit for the role. As part of this discussion, you'll also complete a short technical screening that will be reviewed by our engineering team. This stage helps us understand both your experience and how you approach technical challenges.
  • Step 2 – Hiring Manager interview (60-minutes) you will meet the Head of Security, to explore your skills, achievements, and alignment with the role.
  • Step 3 – Final Interview (45 minutes) The final stage is a group interview with senior members of our Technology squad, which may include the CTO, CPO and Head of Security. Together, we'll discuss team fit, collaboration style, expectations from both sides, and any remaining questions about the role, team, or technology domain. This is also an opportunity for you to learn more about our culture and ways of working.

The perks of being a payabl.er: 

  • Future-Proof Your Finances: Once you’ve passed probation, we’ll kickstart your Provident Fund to secure your future. 
  • Grow with Us: Annual Learning Budget for professional development (eligible after probation)—because your growth is our growth. 
  • Wolt Your Way Through Lunch: €150 monthly Wolt allowance to keep you fueled and happy.
  • Stay Active Your Way: Enjoy a SportsBenefits membership giving you access to a wide variety of gyms and sports facilities to support your active lifestyle.
  • Drive in Style:  After one year with us, you may be eligible for a company car—performance and availability permitting. 
  • Park with Ease: Complimentary parking space just steps from the office, so your commute is as smooth as your workday.
  • Max Out Your Downtime: 25 days of vacation + public holidays + 10 days of sick leave.
  • Shop & Save: Exclusive local discount card + tickets for exciting events like Beonix, basketball games, and more. 
  • Speak Like a Local: Join free Greek language classes, twice a week, open to all team members. 
  • Celebrate Together: We bring colleagues from all offices together for unforgettable company celebrations.
  • Global Collaboration & Events: Opportunities to participate in international company events and initiatives, connecting with colleagues from all regions and contributing to a truly global community

The benefits listed above are for our Cyprus office location only, a list of benefits and contract type will be assessed subject to your location and discussed in the first interview with your Talent Acquisition Partner.

Let's embark on a journey to redefine the landscape of payments together. We're not just offering a role; we're inviting you to be a part of something bigger. Join our team, and let's innovate, disrupt, and lead the future of payments. Together, we can make an impact that resonates. Welcome to the team! 

Please review our Privacy Policy to understand how we process your personal data during the recruitment process: https://payabl.com/privacy-policy

About this role

Summary

Manage GRC programs, policies, third-party risk, audits, and automate workflows.

Job title

Senior Governance, Risk and Compliance Analyst

Experience level

5+ years

Minimum experience

5+ years exp

Industry

finance

Location requirements

Limassol, Cyprus; remote work not specified

Salary

Not specified

Visa sponsorship

H-1B sponsor history

Management role

No

Skills & keywords

Required skills

GRCinformation securityregulatory complianceaudit & assuranceautomated evidence collection

Preferred skills

DORAPSD2ISO 27001CISAlight scripting

Specializations

governancerisk managementcomplianceprivacy operationsaudit
Locations

Structured locations inferred from the posting.

Limassol, Cyprus

On-site City