Full-Time

GRC Analyst

Updated on 9/4/2026

Rhymetec

Rhymetec

11-50 employees

Cybersecurity services for cloud, compliance, privacy

Compensation Overview

£35k - £40k/mo

London, UK

Remote

Remote within the London area, with travel of up to two weeks per calendar year.

Bachelor's

Category
Cybersecurity (1)
Required Skills
Datadog
Microsoft Azure
Incident Response
Vulnerability Analysis
SOC 2
AWS
DevOps
Google Cloud Platform

Get referred to Rhymetec

See people who can refer or advise you

Requirements
  • Knowledge of compliance and regulatory frameworks, including PCI, ISO/IEC, SOC 2, DORA, and GDPR.
  • Strong logical security skills with experience in cloud security.
  • Understanding of cloud environments including Amazon Web Services, Google Cloud Platform, and Microsoft Azure, and of integrating security controls through DevOps and Infrastructure as a Service techniques.
  • Experience in customer service and the ability to develop professional relationships with customers.
  • A bachelor's degree or equivalent experience related to the technology or cybersecurity field.
  • Bilingual proficiency in German and/or French.
  • At least four years of work experience in technology or cybersecurity.
  • Ability to adapt to innovative and changing work demands.
  • Willingness to travel up to two weeks per calendar year.
Responsibilities
  • Prepare agendas and supporting materials for client business meetings.
  • Conduct regular meetings with clients.
  • Configure performance monitoring alarms in Amazon Web Services, Microsoft Azure, Google Cloud Platform, Datadog, and other cloud infrastructures.
  • Configure security alarms and intrusion detection systems in Amazon Web Services, Google Cloud Platform, and Microsoft Azure.
  • Set up supporting security applications.
  • Set up mobile device management applications such as Jamf, JumpCloud, Microsoft Endpoint Manager, and Hexnode.
  • Configure and maintain compliance monitoring platforms.
  • Conduct internal audits and risk assessments and generate reports.
  • Conduct incident response tabletop exercises with clients.
  • Conduct business continuity and disaster recovery tabletop exercises with clients.
  • Support clients in mapping frameworks and controls such as SOC 2 Type 2, ISO 27001, GDPR, and DORA into actionable client items.
  • Conduct employee access reviews, software-as-a-service vendor security assessments, and gap assessments.
  • Triage bug and vulnerability reports from security researchers.
  • Complete security questionnaires on behalf of clients.
  • Draft supporting documents for clients' information security management systems and information security policies.
  • Gather and maintain compliance evidence for various frameworks.
  • Lead engagements with auditors on behalf of clients.
  • Communicate tasks to clients' employees and educate clients on security best practices.

Rhymetec provides cybersecurity services focused on cloud security, data privacy, and compliance for SaaS businesses. It combines consulting and managed services, offering vCISO engagements, penetration testing, security assessments, cloud configuration reviews, phishing simulations with training, and compliance readiness for frameworks like SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS. The company tailors its work to each client’s infrastructure and growth stage and can deploy and manage security programs directly within the client’s environment, often partnering with firms like Drata, Picnic Corporation, and A-LIGN. Its goal is to help customers achieve and maintain security and compliance efficiently so they can focus on their core business operations.

Company Size

11-50

Company Stage

N/A

Total Funding

N/A

Headquarters

New York City, New York

Founded

2015

Get referred to Rhymetec

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Rhymetec launched AIUC-1 Readiness Services on July 24, 2026.
  • Its website updated August 7, 2026, highlighting AI, GRC, and pentesting expansion.
  • Brooklyn Nets partnership and 1,200-customer base strengthen brand visibility and trust.

What critics are saying

  • Vanta, Drata, A-LIGN, and Schellman commoditize compliance work by 2027.
  • AIUC-1 certification stays emerging, so Rhymetec's new offering risks weak demand.
  • Heavy SaaS startup exposure makes revenue vulnerable when customers freeze security spend.

What makes Rhymetec unique

  • Rhymetec bundles vCISO, pentesting, and compliance for SaaS teams.
  • Its 2026 AIUC-1 readiness launch adds niche AI assurance services.
  • Modular enterprise services reduce full-time security hires and audit burden.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

PTO and Sick Time

11 paid Holidays

401K retirement option

Company paid Life Insurance

Annual Subscription to TalkSpace (online counseling & therapy service)

Summer Fridays!

Company News

Rhymetec
Jul 24th, 2026
Rhymetec expands AI security offerings with AIUC-1 Readiness Services.

Rhymetec expands AI security offerings with AIUC-1 Readiness Services. Posted on Jul 24, 2026 By Rhymetec As organizations move AI from experimentation to production, customers, regulators, and enterprise buyers are demanding greater assurance that AI systems are secure, governed, and operating as intended. To help organizations meet these expectations, Rhymetec is expanding its AI security and governance portfolio with the launch of AIUC-1 Readiness Services. AIUC-1 is one of the first certification frameworks designed specifically for AI systems and AI agents. It provides a structured approach to evaluating AI across security, safety, reliability, accountability, data privacy, and governance, helping organizations demonstrate that their AI systems meet the expectations of enterprise customers and stakeholders. Since its launch in 2025, AIUC-1 has continued to develop as an emerging standard for AI assurance. In 2026, Schellman became the first authorized auditor for the framework, establishing a pathway for independent evaluation and certification for organizations pursuing AIUC-1. With this new offering, Rhymetec provides end-to-end guidance throughout the AIUC-1 certification journey, helping organizations prepare for assessment while strengthening the security and governance practices that support long-term AI adoption. Supporting the next generation of AI assurance. Enterprise AI introduces new opportunities alongside new risks. As organizations deploy AI-powered products, copilots, and autonomous agents, they must address evolving concerns around model security, prompt injection, hallucinations, data protection, governance, and ongoing oversight. AIUC-1 brings these technical and operational requirements together into a single certification framework. Rather than replacing established standards like ISO/IEC 42001, ISO 27001, SOC 2, or the NIST AI Risk Management Framework, AIUC-1 complements them by focusing specifically on the unique risks introduced by AI systems. Rhymetec's AIUC-1 services help organizations: * Assess readiness for AIUC-1 and identify gaps. * Develop AI governance policies and supporting documentation. * Implement security and operational controls aligned to AIUC-1 requirements. * Prepare evidence and documentation for assessment activities. * Coordinate assessment readiness activities. * Support ongoing compliance requirements and annual recertification. "Our customers are moving quickly with AI, but trust has become just as important as innovation. Organizations need practical guidance that helps them secure AI systems while demonstrating responsible governance to customers, partners, and regulators. AIUC-1 represents an important step toward creating greater confidence in enterprise AI, and we're excited to help organizations prepare for the framework." - Kyle Jones, Chief AI Officer, Rhymetec Addressing the next generation of AI Risk. AIUC-1 was developed in response to the rapid evolution of AI systems from tools that generate content to systems capable of making decisions and taking actions on behalf of users. As these technologies become more integrated into business operations, organizations are seeking clearer ways to validate that AI systems are secure, reliable, and governed appropriately. The framework establishes a structured approach to evaluating AI systems across key areas such as security, safety, reliability, accountability, and data privacy. By combining technical evaluation with operational governance, AIUC-1 helps organizations demonstrate that responsible AI practices extend beyond policy into the way AI systems are designed, tested, and maintained. Building on Rhymetec's AI security expertise. The launch of AIUC-1 Readiness Services expands Rhymetec's growing portfolio of AI security offerings, which includes AI governance consulting, ISO/IEC 42001 readiness, AI risk assessments, and AI penetration testing. By combining governance expertise with offensive security testing and compliance advisory services, Rhymetec helps organizations build AI programs that are not only innovative, but secure, resilient, and prepared for increasing customer and regulatory scrutiny. As enterprise adoption accelerates, organizations are looking for trusted partners who can help them operationalize responsible AI without slowing innovation. AIUC-1 provides an emerging framework for demonstrating that commitment, and Rhymetec is helping customers navigate every stage of their readiness journey. Organizations interested in preparing for AIUC-1 can learn more about Rhymetec's AI security services or contact its team to discuss their AI governance and readiness goals.