GRC Analyst (f,x,m)
- Hybrid
- All finance & legal jobs
- FullTime
- Risk
About the role
We’re on the lookout for an ambitious Government, Risk and Compliance Analyst to join our Risk Team at our office in Berlin. Join us in building the largest AI enabled fintech for healthcare!
What to expect in the role as GRC Analyst:
You will run the operational engine of Nelly's GRC: own the end-to-end cycles of third party risk, business continuity, control-testing and audit-evidence, so that our registers and evidence are audit-ready every day of the year.
About Nelly
We are building the AI-Driven Financial Operating System for European healthcare, solving the biggest challenges for patients and practices. We create what no bank or software platform can handle. Our all-in-one platform transforms chaotic administrative processes into intelligent, automated workflows, from patient care to billing to next-generation payments. Because we truly believe: healthcare should be less about paperwork and more about people.
Why? Because Europe is facing a massive shortage of medical professionals. And if we don't rethink the way practices work, the system won't be able to keep up. With our Series B funding of over €50 million from world-class investors, we are turning our vision into reality.
What sets us apart: We work with the best team, which is why we give everything together every day. We believe in Talent Density, because exceptional people make everyone around them better. At Nelly, we move fast and expect everyone to keep up. Stagnation isn’t an option, which is why we invest heavily in growth. AI isn't a nice-to-have at Nelly. We expect you to use it every day and give you everything you need to do so. You get trust and ownership and we expect you to speak up, even when it's uncomfortable.
Joining us, you will:
Operate the compliance platform day-to-day: monitor failing controls, chase remediation owners, keep evidence green
Run the third-party lifecycle: onboarding assessments, periodic reviews, evidence collection (SOC 2/ISO/C5 reports, DPAs), Supplier Directory and outsourcing register upkeep
Coordinate the BCM cycle: collect BIA inputs from process owners, organize tests/exercises, maintain plans
Maintain registers and trackers (risk register support, findings log)
Support external audits (C5, ISO, bank partners): prepare evidence packs, manage request lists
Administer the policy review cycle (controlled documents, review dates, approvals)
What you'll bring:
2–4 years in IT/process audit, BCM or GRC operations (Big4/audit firm, or in-house through a first ISO 27001/SOC 2/C5 certification)
you know what evidence an auditor accepts
workpaper discipline with a big attention to detail
you have run or supported vendor assessments
scale-up or fintech environment strongly preferred over big-bank silo experience
Our Interview Process:
First call with you TA Partner 30' online
Second call with your Hiring manager 60' online
Technical Interview on site with your future manager and a team member
What we offer:
Deutschlandticket (public transport pass covering all of Germany) or Swapfiets membership, so you get around the city fast
Urban Sports Club membership, for sport and balance
Flexible working hours and a hybrid setup
Up to 4 weeks of workation
A dog-friendly office with great vibes and a team that's fun to work with
Snacks and a fridge full of cold drinks
We welcome applications from people of all genders and backgrounds, regardless of origin or age. If you're convinced you're the right fit for this role - even if your CV doesn't match the requirements 100% - tell us why.
Description as published by Nelly Solutions.