Remote job
Senior GRC Analyst
Job details
About this role
Role overview
Take ownership of day-to-day governance, risk, and compliance operations as a Senior GRC Analyst. This individual-contributor role is built for someone who can lead audits with confidence, translate complex control requirements into actionable work, and serve as a trusted partner to engineering and business teams. The position blends policy work, audit leadership, vendor oversight, and ongoing improvement of the control framework.
Responsibilities
- Own and coordinate compliance audits and certifications such as SOC 2 and ISO 27001, including evidence collection, auditor coordination, and remediation tracking. - Maintain and improve the control framework by mapping controls across multiple standards to reduce duplicate work. - Conduct risk assessments, documenting identified risks and tracking them through resolution. - Run the third-party risk program, including security reviews of vendors and ongoing monitoring. - Support customer security reviews, questionnaires, and trust-center content. - Develop, maintain, and socialize security policies and standards across the organization. - Partner with control owners to confirm controls operate effectively and drive remediation where gaps exist. - Identify opportunities to automate manual GRC work and collaborate with GRC engineering to deliver improvements.
Requirements
- Several years of experience, typically 4 or more, in GRC, compliance, audit, or risk. - Hands-on experience supporting or leading SOC 2 and/or ISO 27001 audits. - Solid understanding of control frameworks, risk assessment methodologies, and vendor risk management. - Strong organization and attention to detail, with the ability to manage multiple workstreams and deadlines. - Clear communicator who can work effectively with both technical and non-technical stakeholders. - Comfort working with GRC and compliance tooling.
Nice to have
- Relevant certifications such as CISA, CISSP, or CIPP. - Experience with compliance automation and continuous controls monitoring. - Familiarity with cloud environments and how technical controls are implemented. - Experience supporting enterprise sales and customer security due diligence.
Benefits and work setup
- Listed salary: $175,000. - Listed values include a client-first orientation, startup-speed execution, and an AI-forward approach to internal work.