GRC Analyst

Embedded Shishya

Gopalganj

Hybrid

INR 12,823,000 - 19,330,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive compensation with equity
Inclusive healthcare package
Mentorship and event opportunities

Job summary

Vercel is seeking a GRC Analyst to join the Governance, Risk & Compliance team. You’ll manage ongoing compliance with security and privacy frameworks, including ISO 27001, SOC 2, PCI DSS, and HIPAA, ensuring ethical and regulatory adherence.

Reports to the Head of GRC and may operate in remote/onsite/hybrid arrangements. You will partner with multiple teams to embed policies and controls into the SDLC, coordinate audits, and develop training to promote a culture of integrity and accountability

Qualifications

  • Experience supporting audits in cloud-centric environments (SOC 2, ISO 27001, PCI, HIPAA).
  • Ability to collaborate with internal partners to integrate policies and controls into SDLC.

Responsibilities

  • Collaborate with internal teams to maintain internal controls and drive remediation to completion.
  • Build cross-functional relationships to ensure accountability for compliance.
  • Streamline annual audits by managing deliverables and documenting progress.

Skills

SOC 2
ISO 27001
PCI DSS
HIPAA
Cloud security

Tools

Drata
Linear
Datadog

Job description

Headquarters: Remote - United States

About Vercel:

Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.

For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.

Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.

We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.

About the role:

We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy frameworks, policies, procedures, and commercial assessments, including ISO 27001, SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company operates ethically, responsibly, and in accordance with regulatory requirements.

You will collaborate with cross-functional teams to promote a culture of accountability and integrity throughout the organization and foster an environment where everyone understands the importance of adhering to established guidelines and ethical practices. You will report to the Head of GRC and will be located ((remote, onsite, hybrid)).

Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics.

If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team.

What you will do:
  • Collaborate with internal teams to maintain an effective suite of internal controls and driving remediation efforts to completion with clear documentation of progress.
  • Build strong working relationships across the business so compliance accountability is shared and stakeholders are informed.
  • Streamline annual audits by managing audit deliverables, developing treatment plans, and coordinating across teams to document and track completion to ensure audit success.
  • Monitor and improve controls, processes, and evidence management practices, identify opportunities to automate and streamline GRC operations, and contribute to controls maturity scoring and reporting
  • Enable go-to-market teams and accelerate deal cycles by supporting security questionnaires, addressing compliance inquiries, and maintaining clear, customer-facing documentation on Vercel’s security and compliance posture.
  • Design and manage company training and enhance visibility on compliance-specific topics for internal stakeholders to ensure an understanding of compliance, ethics, and regulatory requirements within the organization.
About you:
  • At least 3 years of relevant experience in supporting the audit lifecycle in a cloud-centric environment (SOC 2, ISO 27001, PCI, HIPAA, etc.), with strong organizational skills to be flexible and proactive in a high-growth, start-up environment.
  • Experience collaborating closely with internal partners to seamlessly incorporate policies and technical controls into the SDLC.
  • Strong project management skills and sense of ownership with the ability to communicate and collaborate effectively, and execute projects across various business units and levels.
Bonus if you have :
  • Strong experience with cloud infrastructure (e.g., Azure, AWS)
  • Familiarity with compliance or software development tools and systems (e.g., Drata, Linear, Datadog, etc.)
  • Experience with frontend development and open source components
  • Relevant industry certifications (i.e., CISM, CISSP, CCEP) is a plus, but not required
Benefits:
  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $134,000-$202,000. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Member of the Technical Staff, Internal Agent
Member of the Technical Staff, Internal Agent

Embedded Shishya • Gopalganj

Hybrid
INR 19,904,000 - 29,856,000
Competitive compensation including equ
Inclusive healthcare package
Mentorship and events
Senior Financial Systems Administrator
Senior Financial Systems Administrator

Vercel • India

Hybrid
INR 11,429,000 - 17,143,000
Competitive compensation package
Equity
WFH budget
GRC Analyst
GRC Analyst

Cyderes • Bengaluru

Hybrid
INR 1,200,000 - 2,400,000
Medical Insurance
Life Insurance
Retirement Match Program
+6
Senior GRC Analyst - 26157
Senior GRC Analyst - 26157

Enverus • India

On-site
INR 800,000 - 1,200,000
Senior InfoSec GRC Specialist
Senior InfoSec GRC Specialist

Velsera • Pune District

Hybrid
INR 4,000,000 - 6,500,000
Unlimited paid time off
Group medical & life insurance
EAP for mental health
+2
Senior GRC Analyst - 26157
Senior GRC Analyst - 26157

Pearl Street Technologies • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Director of Trust & Safety Engineering
Director of Trust & Safety Engineering

remote zest jobs • India

On-site
INR 4,000,000 - 8,000,000
Equity
Mentorship
WFH budget
+1
Senior GRC Analyst
Senior GRC Analyst

Tetuan Valley • India

On-site
INR 900,000 - 1,200,000
Variable Compensation
GRC /SOC Analyst
GRC /SOC Analyst

Fulcrum Digital • Pune District

On-site
INR 800,000 - 1,200,000
GRC /SOC Analyst
GRC /SOC Analyst

fulcrumdigital • Pune District

Hybrid
INR 600,000 - 900,000