Remote GRC Analyst: Cloud Security & Risk

Upwind Security, Inc.

Northern (KY)

Hybrid

USD 70,000 - 110,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Upwind Security, Inc. is seeking a GRC Analyst to join our Security & Compliance team and support SOC 2, ISO 27001, NIST, and FedRAMP. You will manage evidence, remediation tracking, and audits across Engineering, IT, Security, Legal, and HR, translating requirements into actionable tasks for tech and business groups.

You’ll help build scalable, AI-assisted GRC processes. The role requires 3–5 years in GRC, strong writing and documentation skills, and a proactive, cross-functional mindset with a

Qualifications

  • 3 to 5 years in GRC, cybersecurity, risk management, compliance, or audit.
  • Strong written communication and documentation skills.
  • Ability to turn audit findings into remediation plans that teams will actually adopt.

Responsibilities

  • Operate and improve Upwind's GRC and security compliance programs.
  • Support compliance work across SOC 2, ISO 27001, NIST, and FedRAMP, including control implementation, evidence collection, remediation tracking, continuous monitoring, and audit readiness.
  • Coordinate audit and compliance evidence from Engineering, IT, Security, Legal, and HR.
  • Translate compliance requirements into clear actions for technical and business teams.
  • Perform control assessments, gap analyses, and risk assessments, and recommend remediation.
  • Track vulnerabilities, risks, audit findings, and POA&Ms through completion.
  • Write and maintain policies, standards, procedures, and control documentation.
  • Maintain GRC systems, evidence repositories, and risk registers.
  • Research new regulatory and customer requirements and determine how they apply to us.
  • Use AI and automation to speed up research, documentation, evidence organization, and workflow, with appropriate validation and data handling.
  • Raise gaps and issues early, with a proposed fix.

Skills

GRC
Risk management
Audits
Documentation
Communications
Cloud security
Automation

Tools

Jira
GitHub

Job description

Upwind Security, Inc. is seeking a GRC Analyst to join our Security & Compliance team and support SOC 2, ISO 27001, NIST, and FedRAMP. You will manage evidence, remediation tracking, and audits across Engineering, IT, Security, Legal, and HR, translating requirements into actionable tasks for tech and business groups.

You’ll help build scalable, AI-assisted GRC processes. The role requires 3–5 years in GRC, strong writing and documentation skills, and a proactive, cross-functional mindset with a

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Analyst — Cloud Security & Compliance
GRC Analyst — Cloud Security & Compliance

Upwind Security, Inc. • United States

Remote
USD 90,000 - 130,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Senior GRC Engineer: Cloud Security & Compliance
Senior GRC Engineer: Cloud Security & Compliance

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 240,000
Healthcare benefits
401(k) match
Career development
GRC Analyst
GRC Analyst

Upwind Security, Inc. • Northern (KY)

Hybrid
USD 70,000 - 110,000
Security GRC Engineer: Risk, Audits and Compliance
Security GRC Engineer: Risk, Audits and Compliance

Whatnot • San Francisco (CA)

On-site
USD 175,000 - 230,000
Health Insurance
Home office setup allowance
Cell phone and internet allowance
+6
Remote GRC Analyst: Build Practical Compliance Programs
Remote GRC Analyst: Build Practical Compliance Programs

Insight Security • Northern (KY)

Hybrid
USD 68,000 - 95,000
Health, dental, and vision insurance
Fully remote work
Unlimited PTO
+2
Security GRC Engineer — Lead Compliance & Risk
Security GRC Engineer — Lead Compliance & Risk

Whatnot • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Health Insurance options
Work From Home Support
Home office setup allowance
+3
Senior GRC Analyst
Senior GRC Analyst

Averity • New York (NY)

On-site
USD 90,000 - 140,000
GRC Engineer: Compliance Automation & SecOps
GRC Engineer: Compliance Automation & SecOps

Forward • Santa Clara (CA)

On-site
USD 140,000 - 170,000
Remote GRC Analyst: Security Compliance & Risk
Remote GRC Analyst: Security Compliance & Risk

Districttechgroup • Washington

Hybrid
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2