Remote job
GRC Security Analyst - Information Security
Job details
About this role
Role overview This Governance, Risk, and Compliance (GRC) Security Analyst position sits within an information security team at a fast-growing software company. The analyst will own risk identification, documentation, and remediation tracking while partnering with business owners and vendors to strengthen the overall security posture. The role blends compliance program support with practical risk management across a portfolio of products.
Responsibilities - Coordinate security governance initiatives and align program goals with stakeholders across the organization. - Support sales channels by responding to prospect and customer security questionnaires, assessments, and audits, including articulating technical controls and acceptable risk mitigation paths. - Run vendor risk management assessments, track findings, and follow up through closure. - Provide hands-on support for regulatory and compliance initiatives such as ISO 27001, SOC 2, and GDPR. - Identify, document, and track non-conformities against security policies; build and monitor corrective action plans to completion. - Track security risk acceptances and exceptions, and oversee execution of remediation plans. - Assist with monitoring of business continuity and disaster recovery testing activities. - Perform periodic compliance checks throughout the organization and assist with post-acquisition integration plans. - Contribute to annual security awareness campaigns and the periodic review of security policies and processes.
Requirements - Bachelor's degree in Computer Science, Information Technology, or a related discipline. - Demonstrated understanding of GRC operations and information security practices in a growing company environment. - Highly organized with strong attention to detail and the ability to juggle multiple workstreams. - Excellent interpersonal and written communication skills, including the ability to speak to non-conformities diplomatically. - Self-starter who proactively identifies issues and recommends concrete actions. - Creative problem solver who can handle sensitive and confidential material with discretion.
Nice to have - CISA, CISSP, or comparable security or GRC-focused certification.
Benefits and work setup - Company equity eligibility for every team member. - Generous paid vacation, monthly wellness days, and paid volunteer time. - Access to an internal learning and development platform for continuous growth. - Private health insurance coverage and family support benefits. - Fully remote work arrangement with flexibility in how and where work gets done.