Daily rate: up to 300 euros per day
Codertal is looking for an experienced Cyber Governance, Risk & Compliance Analyst to join our client’s Cyber Security team within a major European airline.
This is a remote, long‑term B2B contract, working closely with senior stakeholders across cyber, risk, and technology.
About the Role
As a Cyber GRC Analyst, you will help strengthen the organisation’s cyber security posture by performing risk assessments, evaluating security controls, and ensuring compliance with NIS2, GDPR, NIST CSF, and internal security standards.
You will support key governance areas such as third‑party risk management, project/change assurance, cyber resilience, policy lifecycle management, and structured control testing.
Your work will directly contribute to protecting critical systems, supporting audits, and maintaining regulatory alignment across the enterprise.
Key Responsibilities
- Conduct third‑party risk assessments for suppliers and partners
- Perform cyber risk assessments across systems, processes, and projects
- Support cyber resilience governance, including BCM, DR, and cyber recovery
- Monitor compliance against internal standards and regulatory frameworks
- Carry out security control testing and evidence‑based reporting
- Support internal and external audits and regulatory inspections
- Manage the policy and standards lifecycle
- Collaborate with technology owners on remediation and risk treatment
- Track and report cyber posture metrics
- Contribute to the continuous improvement of GRC processes and frameworks
Additional Responsibilities
- Support regulatory submissions
- Participate in audits and assurance activities
- Facilitate risk discussions with SMEs
- Support vulnerability and threat exposure reviews
- Contribute to cyber governance forums and resilience exercises
- Drive cyber culture and documentation quality initiatives
Required Experience
- 5+ years in cyber security, risk management, or technology assurance
- Hands‑on experience with control testing, risk assessments, or compliance
- Strong understanding of risk management principles
- Proven experience with third‑party risk management
- Familiarity with NIST, ISO 27001, CIS, and GDPR
- Experience with audits, project/change assurance, or structured testing
Key Skills
- Strong analytical and problem‑solving abilities
- Ability to evaluate control effectiveness and identify gaps
- Excellent written communication for assessment reports
- Strong documentation and evidence‑gathering skills
- Ability to manage multiple assessments simultaneously
- Comfortable challenging assumptions and asking probing questions
- Proactive mindset with full accountability for delivery
Nice to Have
- Experience in regulated industries such as aviation, finance, or critical infrastructure
- Knowledge of secure‑by‑design, cloud controls, and modern architectures
- Certifications such as ISO 27001 LI/LA, CRISC, CISSP, or CISA
- Experience with BCM/DR and compliance assurance frameworks
- Familiarity with SureCloud, Archer, or ServiceNow GRC
- Working knowledge of Power BI
Daily rate: up to 300 euros per day
Codertal is looking for an experienced Cyber Governance, Risk & Compliance Analyst to join our client’s Cyber Security team within a major European airline.
This is a remote, long‑term B2B contract, working closely with senior stakeholders across cyber, risk, and technology.
About the Role
As a Cyber GRC Analyst, you will help strengthen the organisation’s cyber security posture by performing risk assessments, evaluating security controls, and ensuring compliance with NIS2, GDPR, NIST CSF, and internal security standards.
You will support key governance areas such as third‑party risk management, project/change assurance, cyber resilience, policy lifecycle management, and structured control testing.
Your work will directly contribute to protecting critical systems, supporting audits, and maintaining regulatory alignment across the enterprise.
Key Responsibilities
- Conduct third‑party risk assessments for suppliers and partners
- Perform cyber risk assessments across systems, processes, and projects
- Support cyber resilience governance, including BCM, DR, and cyber recovery
- Monitor compliance against internal standards and regulatory frameworks
- Carry out security control testing and evidence‑based reporting
- Support internal and external audits and regulatory inspections
- Manage the policy and standards lifecycle
- Collaborate with technology owners on remediation and risk treatment
- Track and report cyber posture metrics
- Contribute to the continuous improvement of GRC processes and frameworks
Additional Responsibilities
- Support regulatory submissions
- Participate in audits and assurance activities
- Facilitate risk discussions with SMEs
- Support vulnerability and threat exposure reviews
- Contribute to cyber governance forums and resilience exercises
- Drive cyber culture and documentation quality initiatives
Required Experience
- 5+ years in cyber security, risk management, or technology assurance
- Hands‑on experience with control testing, risk assessments, or compliance
- Strong understanding of risk management principles
- Proven experience with third‑party risk management
- Familiarity with NIST, ISO 27001, CIS, and GDPR
- Experience with audits, project/change assurance, or structured testing
Key Skills
- Strong analytical and problem‑solving abilities
- Ability to evaluate control effectiveness and identify gaps
- Excellent written communication for assessment reports
- Strong documentation and evidence‑gathering skills
- Ability to manage multiple assessments simultaneously
- Comfortable challenging assumptions and asking probing questions
- Proactive mindset with full accountability for delivery
Nice to Have
- Experience in regulated industries such as aviation, finance, or critical infrastructure
- Knowledge of secure‑by‑design, cloud controls, and modern architectures
- Certifications such as ISO 27001 LI/LA, CRISC, CISSP, or CISA
- Experience with BCM/DR and compliance assurance frameworks
- Familiarity with SureCloud, Archer, or ServiceNow GRC
- Working knowledge of Power BI