Senior, Cybersecurity Assurance Analyst

Axonius · Remote Portugal · Engineering

Posted 2026-07-28

Apply for this role →

This is a full-time and fully remote position from Portugal only

Axonius is seeking a Cybersecurity Assurance Senior Analyst based to lead security audit, assurance, and Governance, Risk, and Compliance (GRC) efforts. Reporting to the Director of Cybersecurity Assurance/GRC, this role manages cybersecurity governance, risk management, and compliance across the organization and with third-party vendors. The position focuses on conducting comprehensive security assessments, managing vendor risk, and driving the continuous improvement of the GRC program to support the company's technology platform.

Responsibilities

Conduct comprehensive internal and external security compliance assessments, identify cybersecurity vulnerabilities, and maintain the organizational risk register.

Manage internal and external audits by preparing compliance documentation, maintaining the audit repository, and tracking remediation findings.

Coordinate quarterly meetings with risk and control owners to review mitigation plans, evaluate control effectiveness, and report on quarter-over-quarter performance metrics.

Administer GRC and procurement platforms, and support customer pre-sales and renewals by completing cybersecurity assurance documentation within RFPIO.

Minimum Qualifications

5+ years of combined experience in Cybersecurity Risk, Vendor Risk, Enterprise Risk, IT System Administration, or IT Auditing.

Professional proficiency in English, including reading, writing, and speaking, to document processes and collaborate with US-based teams.

Core implementation and assessment experience with compliance standards and frameworks such as SOC 2, ISO 27001, ISO 22301, ISO 42001, or HIPAA.

Experience applying third-party risk management (TPRM) frameworks to execute vendor security assessments.

Preferred Qualifications

Technical experience in independently coordinating, executing, and documenting business continuity or disaster recovery testing scenarios.

Experience automating GRC processes using platforms such as Fusion RM, Zip, Anecdotes, or Vanta.

Professional certifications or working knowledge related to NIST, ISO 31000, or ISO 42001 frameworks.

Experience utilizing ticketing platforms to track and manage cybersecurity vulnerabilities.

Technical familiarity with security controls and technologies used for securing SaaS environments.

Proficiency in navigating and utilizing Google Products (Docs, Sheets, Forms, Slides) for data collection and reporting.

#LI-REMOTE#LI-AZ1

Apply for this role →

← Back to all jobs