Junior GRC Analyst
About kaiko
Clinicians and nurses work under heavier pressure than ever. More patients, more data, more decisions to make. kaiko give them back the focus, time, and headspace they need to give patients the best possible care.
kaiko is a European clinical AI lab, and one of the only companies working across the full stack. Our approach spans three layers: our own frontier models, a clinical AI workspace built for complex hospital needs and workflows ranging from preparation and decision support to diagnostics and interpretation.
Our product is in daily use at leading European hospitals, reducing preparation time and cognitive workload for clinical teams. The next decade of European healthcare will be shaped by AI. We're here to shape it in the best way possible. kaiko is a well-funded company with a growing international team, operating from Amsterdam and Zurich.
About the role
kaiko processes sensitive health data while shipping platform and product features at startup pace. That combination demands a compliance system that is well-run day-to-day, not built once and left to drift.
As a Junior GRC Analyst on our Security & Governance team, you’ll be the operational backbone of that system: risk, exceptions, incident records, ISMS operations, third-party reviews, and the registers and evidence that keep our ISO 27001 and NEN 7510 posture defensible. You’ll partner day-to-day with our Compliance System Manager, who owns the compliance system, while reporting to the CISO.
This is a hands-on role in a regulated healthcare AI environment, with high exposure to real audit and regulatory work and a clear path to grow into a Senior GRC Analyst.
You will be based in either The Netherlands with the expectation of spending at least 50% of your time at the office.
Some areas of responsibility
Risk and exception management: operate the risk register and exception lifecycle end-to-end — intake, tracking, periodic review, closure — keeping both complete, current, and visible to leadership.
ISMS operation and audit readiness: maintain the policy and SOP library, run the review cycle, and prepare evidence packs for ISO 27001 and NEN 7510 surveillance audits.
Third-party security risk: support vendor reviews end-to-end — intake, questionnaires, DPA and sub-processor tracking, data residency, and ongoing monitoring — alongside the DPO and privacy counsel.
Compliance operations and reporting: own the accuracy of the supplier register, DPIA tracker, incident records, and post-incident action tracking; produce monthly metrics on risk, exceptions, incidents, and audit posture for leadership.
About you
1–3 years in GRC, information security, internal audit, or a closely related field. Recent graduates with a strong information security, law-and-technology, or auditing background and clear interest in the role are welcome to apply.
Working knowledge of at least one major framework (ISO 27001, NEN 7510, SOC 2, or NIS2) and a solid grasp of how an ISMS actually runs.
You understand the difference between a risk, an issue, and an exception, and you can hold a register accountable to its owners.
Foundational technical literacy: you can read a system architecture diagram, understand what RBAC means, and follow an engineering conversation about cloud infrastructure.
Detail-oriented and organized — you can hold a register of 50+ open items in your head and chase loose ends without being asked twice.
Pragmatic; you distinguish between what an auditor needs to see and what genuinely reduces risk.
Comfortable asking questions and pushing back politely when something doesn’t add up.
Nice to have:
Exposure to healthcare, medical devices, or another regulated environment (GDPR, MDR, HIPAA).
Familiarity with Jira and Confluence as compliance and governance tooling.
Foundational certification such as ISO 27001 Lead Implementer, CompTIA Security+, or equivalent.
We are excited to gather a broad range of perspectives in our team, as we believe it will help us build better products to support a broader set of people. If you’re excited about us but don’t fit every single qualification, we still encourage you to apply: we’ve had incredible team members join us who didn’t check every box!
Why kaiko
At kaiko, we believe the best ideas come from collaboration, ownership and ambition. We’ve built a team of international experts where your work has a direct impact. Here’s what we value:
Ownership: You’ll have the autonomy to set your own goals, make critical decisions, and see the direct impact of your work.
Collaboration: You’ll have to approach disagreement with curiosity, build on common ground, and create solutions together.
Ambition: You’ll be surrounded by people who set high standards for themselves and others, who see obstacles as opportunities, and who are relentless in their work to create better outcomes for patients.
In addition, we offer:
An attractive and competitive salary, a good pension plan, and 25 vacation days per year.
Great offsites and team events to strengthen the team and celebrate successes together.
A EUR 1000 learning and development budget to help you grow.
Autonomy to do your work the way that works best for you, whether you have a kid or prefer early mornings.
An annual commuting subsidy.
Our interview process
Our interview process is designed to assess mutual fit across skills, motivation, and values. It typically includes the following steps:
Screening call: A short conversation to align on your motivation, professional goals, and initial fit for the role.
Technical interview: A deep dive into your problem-solving approach through a governance scenario or role-specific case.
Onsite meeting (optional): You’ll meet team members across functions to explore collaboration dynamics, team fit, and day-to-day context.
Final executive conversation: A discussion with a member of the executive team focused on long-term alignment and shared expectations for impact.
- Department
- Engineering
- Role
- Security
- Locations
- Amsterdam
- Remote status
- Hybrid