GRC Security Analyst — ISO 27001 & SOC 2 Focus

Cognism Limited

United States

Remote

USD 70,000 - 110,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Cognism is seeking a GRC Analyst to help mature governance, risk and compliance in a fast-growing data platform. You will own evidence, monitoring, and risk-based prioritisation across ISO 27001 and SOC 2, partnering with Engineering, IT Operations, and Compliance.

The role offers an opportunity to strengthen audit readiness, document controls, and support vendor assessments while building AI risk awareness. Experience with security controls, risk registers, and policy maintenance is preferred.

Qualifications

  • 1–2 years experience in security, GRC, IT audit, or related risk function.
  • Familiar with ISO 27001 and SOC 2 fundamentals.
  • Detail-oriented with strong written and verbal communication.
  • Ability to explain risk concepts to technical and non-technical audiences.
  • Comfortable collaborating with Engineering, IT Operations, and Compliance teams.
  • Curious about AI risks and compliance applications.

Responsibilities

  • Support day-to-day GRC programme operations.
  • Maintain and improve documentation: policies, risk registers, control mappings.
  • Support audits, questionnaires, vendor risk assessments.
  • Track remediation closure with cross-functional teams.
  • Identify process improvements for efficiency and automation.

Skills

GRC
ISO 27001
SOC 2
IT audit

Job description

Cognism is seeking a GRC Analyst to help mature governance, risk and compliance in a fast-growing data platform. You will own evidence, monitoring, and risk-based prioritisation across ISO 27001 and SOC 2, partnering with Engineering, IT Operations, and Compliance.

The role offers an opportunity to strengthen audit readiness, document controls, and support vendor assessments while building AI risk awareness. Experience with security controls, risk registers, and policy maintenance is preferred.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Analyst III - SOC 2/ISO 27001 Expert
GRC Analyst III - SOC 2/ISO 27001 Expert

Advance America, Cash Advance Centers, Inc. • Greenville (SC)

On-site
USD 90,000 - 140,000
Competitive wages
401(k) savings with company match
Company paid holidays
+5
GRC & Risk Analyst – SOC 2, ISO 27001, PCI
GRC & Risk Analyst – SOC 2, ISO 27001, PCI

CloudData • United States

On-site
USD 80,000 - 100,000
GRC Analyst – SecOps
GRC Analyst – SecOps

Bright Defense, LLC. • United States

On-site
USD 70,000 - 90,000
GRC Cybersecurity Analyst (SOX/ISO) — Hybrid
GRC Cybersecurity Analyst (SOX/ISO) — Hybrid

Urbint • United States

Hybrid
USD 28,000 - 44,000
Private healthcare
Hybrid work
Professional development
Senior GRC Analyst
Senior GRC Analyst

Averity • New York (NY)

On-site
USD 90,000 - 140,000
GRC Analyst
GRC Analyst

Apex B2Bi Solutions • Illinois

On-site
USD 90,000 - 130,000
Audit-Ready GRC & Security Compliance Lead
Audit-Ready GRC & Security Compliance Lead

Openkrill • Northern (KY)

On-site
USD 120,000 - 190,000
Remote GRC Analyst — SOC 2 & ISO 27001 Expert
Remote GRC Analyst — SOC 2 & ISO 27001 Expert

Parallels • United States

Remote
USD 120,000 - 130,000
Fully remote
Governance, Risk & Compliance Senior Analyst
Governance, Risk & Compliance Senior Analyst

Tier4 Group • Atlanta (GA)

On-site
USD 90,000 - 150,000
Remote GRC Analyst: SOX, ISO 27001 & Compliance
Remote GRC Analyst: SOX, ISO 27001 & Compliance

Itron • New York (NY)

Hybrid
USD 28,000 - 44,000
Accident and life insurance
Private outpatient care support
Cafeteria
+2