GRC Analyst — Lead Security & Compliance at Scale

Zip

United States

On-site

USD 95,000 - 150,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Start-up equity
Health, vision & dental coverage
Catered meals
Flexible PTO
401k plan
Home office stipend
Phone/internet reimbursement
Paid parental leave
Fertility stipend
Unlimited AI token usage

Job summary

Zip is seeking a GRC Analyst in the United States to drive compliance programs and security assurance as the company scales. You will help design and scale the GRC program, supporting growth into new markets and regulated industries.

Responsibilities include leading periodic audits, guiding control owners, and preparing customer responses during due diligence. You’ll collaborate with internal teams and external auditors on SOC 1, SOC 2, ISO 27001 and related certifications.

Qualifications

  • 2+ years of experience in GRC, information security consulting, cybersecurity risk, audits, or similar roles.
  • Strong written and verbal communication with technical and non-technical stakeholders.
  • Familiarity with SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP.

Responsibilities

  • Drive and perform periodic compliance-related activities, such as user access reviews, internal audits, and vendor risk assessments
  • Lead conversations and curate responses for customers’ security, compliance, and governance teams in due diligence and security questionnaires
  • Guide internal control owners and stakeholders to understand requirements, take accountability, and operationalize their controls.
  • Collaborate with internal stakeholders and external auditors to support third party audits including SOC 1, SOC 2, and ISO 27001
  • Develop, maintain, and lead the adoption of security policies, standards, and guidelines to ensure compliance with applicable regulatory requirements

Skills

GRC
Information security
Security risk assessment
Stakeholder communication

Education

Bachelor's degree

Job description

Zip is seeking a GRC Analyst in the United States to drive compliance programs and security assurance as the company scales. You will help design and scale the GRC program, supporting growth into new markets and regulated industries.

Responsibilities include leading periodic audits, guiding control owners, and preparing customer responses during due diligence. You’ll collaborate with internal teams and external auditors on SOC 1, SOC 2, ISO 27001 and related certifications.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst | AI Security & Compliance
GRC Analyst | AI Security & Compliance

Zip • San Francisco (CA)

On-site
USD 95,000 - 150,000
Start-up equity
Health, vision & dental coverage
Catered meals
+5
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
GRC Security Analyst: Automate Compliance & Risk
GRC Security Analyst: Automate Compliance & Risk

Discord • San Francisco (CA)

Hybrid
USD 144,000 - 162,000
Equity
Relocation assistance
GRC Analyst: Security & Compliance Lead for SaaS
GRC Analyst: Security & Compliance Lead for SaaS

Fireworks AI • San Mateo (CA)

On-site
USD 110,000 - 170,000
Senior Security GRC Analyst (FedRAMP, SOC 2, ISO 27001)
Senior Security GRC Analyst (FedRAMP, SOC 2, ISO 27001)

Rescale • United States

Remote
USD 150,000 - 230,000
GRC Analyst II – Remote, SOC 2 & Compliance
GRC Analyst II – Remote, SOC 2 & Compliance

Payscale • United States

On-site
USD 65,000 - 90,000
401(k) company match
Comprehensive health benefits
Remote‑first with stipend
+1
GRC Analyst II - Security Governance & Compliance Lead
GRC Analyst II - Security Governance & Compliance Lead

Bright Defense, LLC. • United States

Remote
USD 70,000 - 90,000
Remote GRC Analyst: Risk, Controls & Compliance
Remote GRC Analyst: Risk, Controls & Compliance

YipitData • Northern (KY)

Hybrid
USD 92,000 - 113,000
GRC Engineering Manager: Lead Secure Cloud Compliance
GRC Engineering Manager: Lead Secure Cloud Compliance

Workstreet • Northern (KY)

Hybrid
USD 150,000 - 190,000
Career Development
Role-Related Training
Competitive Compensation
+2
GRC Analyst: Scale AI Security & Compliance
GRC Analyst: Scale AI Security & Compliance

Fluidstack • San Francisco (CA)

On-site
USD 218,000 - 269,000
Equity
Health, dental, and vision insurance
Generous PTO
+1