- We’re looking for a GRC Analyst to join our security and compliance team
- You’ll help us mature our compliance program across frameworks like SOC 2, HIPAA, ISO 27001, ISO 27701, ISO 42001, and GDPR - supporting audits, managing risk, and partnering with engineering and operations teams to keep our controls effective as we scale
- From day one you’ll get hands-on with core operational areas of our program, including user access reviews, our security awareness program through the Adaptive Security platform, and third-party risk management, with clear room to grow into broader ownership, audit leadership, and program strategy over time
- This is a great fit for someone with solid working experience in security or compliance who’s looking to build hands-on ownership and deepen their skill set in a fast-moving SaaS environment
- Support day-to-day GRC operations including (but not limited to) user access reviews and certifications, security awareness and phishing/deepfake simulation facilitation, JML tracking, and triage of policy and control exceptions
- Support the risk management program help perform annual and ad-hoc risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure
- Support third-party risk management run vendor and subprocessor risk assessments, conduct ongoing monitoring, and track remediation across our critical vendors
- Execute internal audits using established test procedures to test control effectiveness, and support external audit cycles by coordinating evidence, control owners, and remediation
- Help maintain continuous control monitoring and evidence automation support administration of our GRC platform, keep automated control tests and evidence healthy, and help maintain audit readiness year-round rather than point-in-time
- Build relationships with cross-functional partners across engineering, IT, operations, legal, and sales - meeting teams where they are rather than gatekeeping
- Partner with control owners to help them understand their control responsibilities and expectations, prepare for audits, and operationalize controls rather than treat compliance as a checkbox
- Help keep the policy library current support reviews and updates to security policies, standards, and procedures so they stay practical and aligned to the frameworks we operate under
- Turn program data into insights help translate access review, awareness, and risk findings into insights and metrics that flag high-risk users, teams, or behaviors, and support reporting to leadership
- Take on additional GRC projects as the program evolves; we’re a growing team and priorities shift
- As you build context on our environment and program, you’ll take on broader ownership and move toward more senior scope:
- Greater ownership of core programs move from supporting established processes to owning entire workstreams (user access reviews, security awareness, third-party risk) end-to-end
- Audit leadership progress from executing established test procedures to helping design new ones, scoping audits, and coordinating auditors directly
- Program and control maturity contribute to control improvement and automation initiatives that raise the bar on how efficiently we run the program as we scale
- Growing influence as you build expertise, you’ll have opportunities to mentor newer team members and represent GRC in cross-functional projects
Comfort with cloud environments (AWS, GCP, or Azure) and how SaaS products are built and operatedExperience running user access reviews and a solid understanding of identity and access management concepts (RBAC, least privilege, segregation of duties, JML processes)Hands-on experience administering a security awareness or phishing simulation platform (Adaptive Security, KnowBe4, Hoxhunt, Proofpoint, or similar)Strong written communication; you can translate control requirements and security concepts into language engineers, customers, and non-technical employees understand3-5 years of experience in GRC, IT audit, information security, or a closely related fieldWorking knowledge of major security and privacy frameworks such as SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR, or CCPAA collaborative mindset; you enjoy working across teams rather than gatekeepingExperience with GRC platforms (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC)Detail-oriented and organized, with the ability to juggle multiple audits, campaigns, and deadlines