KeyStep

Senior GRC Analyst (m,f,x)

HelloFresh
Berlin, Germany
about 3 hours ago
full-time

Skills & Technologies

PCI DSSRisk ManagementComplianceRegulatoryImplementationMakeMentoringData ProtectionAIDocumentationInternal ControlsData PrivacyInformation Security

Job Description

The role

We’re looking for a new teammate who will support the implementation and ongoing maintenance of information security compliance and certification programs, working with cross-functional internal teams and external auditing agencies. The person will also support data protection, data privacy, and third-party vendor risk management functions.

The position will be part of the Governance, Risk & Compliance (GRC) team at HelloFresh that is responsible for creating, maintaining and improving HelloFresh’s security risk management program and remediation activities; information security and data privacy related processes, policies, and guidelines; supporting compliance and certification related activities; and driving security awareness and education.

Above all, we are looking for people who will make HelloFresh better. We believe there are many different ways of developing skills and we love diverse experiences! So even if you don’t “tick all the boxes” but think you’d thrive in this role, we would really like to learn more about you.

What you’ll do

Lead end-to-end compliance readiness for NIS2 and support alignment across other key frameworks (e.g., PCI DSS, CSRD, ISO/SOC and EU AI Act).

Plan and execute internal control assessments and coordinate external compliance audits on a defined cadence.

Translate regulatory requirements into practical controls; drive cross-functional implementation across international teams.

Own remediation management: track findings, evidence, owners, deadlines, and report status to stakeholders.

Improve GRC maturity through continuous monitoring, clear documentation, and mentoring junior team members.

Lead internal assessments and coordinate external compliance audits at planned intervals

Evaluate and validate the design and operational effectiveness of security policies, standards, and internal controls to help reduce compliance risk in the company

Develop comprehensive and accurate reports and presentations on the compli

Company & Role Analysis

JobSeeker+
Likely perks
Private MedicalPension25+ Days HolidayStock OptionsLearning BudgetFlexible Hours
Culture & working style

Neutral 2–4 sentence summary of what working at this company is like, drawn from public reviews and press coverage. Tone, collaboration style, pace, benefits highlights.

Market salary range

£45,000 – £60,000 (Glassdoor, Levels.fyi, 2025)

Unlock the full analysis for this job
Sign in to unlock →

Similar roles

See more
HelloFresh
Warszawa, Masovian Voivodeship, Poland
Full-time
10 days ago

Work with HelloFresh in Warsaw and its HelloTech organisation, HelloFresh’s global technology backbone with more than 1000 people, building…

View Job
Ntt Data
London, UK
£72,857 – £72,857
Full-time
26 days ago

The Information Security Analyst will be responsible for maintaining and enhancing the organizations information security measures. This rol…

View Job
Apply NowApply with CV Improver