3,012 Open roles
109 Companies
81 Posted today
Jobs / LeoVegas / Information Security GRC Analyst
Posted 2026-09-05

Information Security GRC Analyst

Description

The Information Security GRC Analyst at LeoVegas is a key individual in a small team focusing his/her activities in the areas of GRC and SAT working alongside Internal IT, Privacy, Tech Compliance, Legal, Platform and other teams. This individual is responsible for ensuring good governance and compliance with regulatory requirements, as well as the adoption of good security industry practices across LeoVegas Group. Amongst other qualities, the role calls for a good communicator and risk advisor aimed at deriving value through the identification and reduction of risks following best practice.

Responsibilities
  • Assist with the development, maintenance and testing of business continuity and disaster recovery plans.
  • Participate in security maturity assessments and other risk assessments.
  • Participate in regulatory audits and assist other teams as may be required.
  • Assist with the Risk Management function to maintain the Group's Security Risk Register.
  • Assist with Security Incidents such as data breaches in terms of response, mitigation, and stakeholder communication.
  • Detect gaps in security processes and security product portfolios, determine risks, and provide recommendations on how to remediate.
  • Contribute to the development of appropriate security KPIs, objectives and strategies, towards improving the Group’s overall security posture and maturity.
  • Be responsible for employee training and education programmes related to Information Security.
  • Develop and maintain the Group's Information Security policies, standards, and guidelines.
  • Participate in vendor onboarding due diligence exercises and security reviews.
Requirements
  • A degree in Computing, Cybersecurity or Information Systems (Masters preferred) (required)
  • Ideally possess 1 or more of the following: CISSP, CISA, CRISC security certification (preferred)
  • Minimum of 3 years experience working in a cyber security position (required)
  • Familiarity with security auditing processes (required)
  • Sound knowledge of ISO27001 and PCI-DSS standards (required)
  • Knowledge of modern Cloud platforms (required)
  • Knowledge on dealing with Incident Response (required)
  • Soft skills training (required)
Benefits
  • Hybrid work policy
  • 4 weeks of Workation (T&C apply)
  • Well-being allowance to support your active lifestyle
  • Private health insurance
  • Discounts across a range of retailers, gyms, bars & restaurants
  • Employee assistance program that can provide help and guidance during challenging moments
About LeoVegas

LeoVegas Group is a Swedish mobile-first iGaming company founded in 2011, headquartered in Stockholm with its main operational hub in Sliema, Malta. A pioneer of mobile casino, it operates online casino and sportsbook products across regulated markets through brands including LeoVegas, BetUK, Expekt, Pink Casino and GoGo Casino. In 2022 the group was acquired by MGM Resorts International and now serves as MGM's international online-gaming arm, having previously been listed on Nasdaq Stockholm.

Read more about LeoVegas →

Apply on LeoVegas →