Remote IT GRC Analyst: SOC 2 & Vendor Risk Lead

Cloud for Good

Northern (KY)

Hybrid

USD 70,000 - 110,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Travel up to 30%
Fully remote company
Video meetings via Zoom

Job summary

Cloud for Good seeks an IT GRC Analyst to own the day-to-day operation of the security compliance program. This role coordinates external vendors and auditors, responds to client due-diligence requests, and keeps policies and controls current.

You’ll manage vendor relationships for pen test teams, translate audit findings into remediation actions, and maintain an audit-ready evidence trail across SOC 2 and related frameworks. This is a fully remote role with travel up to 30%.

Qualifications

  • 2+ years in a GRC, IT compliance, or security operations role.
  • Familiarity with SOC 2 lifecycle and audit processes.
  • Experience managing vendors or external service providers.
  • Strong written communication for policies and audits.
  • Able to coordinate across services, IT, sales and legal.
  • Detail-oriented with multiple concurrent deadlines.

Responsibilities

  • Serve as the primary point of contact for third-party penetration testing vendors.
  • Coordinate scoping, scheduling, and rules of engagement for pen test engagements.
  • Review vendor findings and translate into remediation tickets.
  • Track remediation timelines and confirm fixes are validated.
  • Evaluate and assist in selecting new pen test vendors when needed.
  • Own SOC 2 audit coordination with auditors and automation platforms.
  • Collect, organize, and submit evidence across control owners.
  • Track audit timelines and deliverables; accelerate blockers.
  • Maintain an audit-ready evidence trail between cycles.
  • Respond to inbound client security questionnaires and due-diligence requests.
  • Maintain a library of standard responses, control descriptions and docs.
  • Coordinate with sales, legal, and services for non-standard questions.
  • Monitor turnaround times and address documentation gaps.

Skills

GRC/IT compliance
Vendor management
Security operations
Written communication
Cross-functional coordination

Tools

SOC 2
Vanta
Drata
Secureframe
Tugboat Logic

Job description

Cloud for Good seeks an IT GRC Analyst to own the day-to-day operation of the security compliance program. This role coordinates external vendors and auditors, responds to client due-diligence requests, and keeps policies and controls current.

You’ll manage vendor relationships for pen test teams, translate audit findings into remediation actions, and maintain an audit-ready evidence trail across SOC 2 and related frameworks. This is a fully remote role with travel up to 30%.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst — Cybersecurity & Vendor Risk Lead
GRC Analyst — Cybersecurity & Vendor Risk Lead

ANP Advanced Network Products, Inc: A Coretelligent Company • United States

On-site
USD 70,000 - 88,000
Health
Dental
Vision
+4
Remote GRC Analyst - Cybersecurity & Compliance
Remote GRC Analyst - Cybersecurity & Compliance

Coretelligent • United States

On-site
USD 70,000 - 88,000
Holidays
Flexible vacation
Monthly rewards
+6
Remote Senior IT GRC Analyst – SOC 2 Readiness
Remote Senior IT GRC Analyst – SOC 2 Readiness

cmgfi • United States

On-site
USD 120,000 - 160,000
GRC Analyst: Cyber Risk & Vendor Compliance
GRC Analyst: Cyber Risk & Vendor Compliance

Coretelligent, LLC. • Northern (KY)

Hybrid
USD 70,000 - 88,000
Health insurance
401k
Paid parental leave
+1
Remote IT GRC Analyst: Healthcare Compliance & Security
Remote IT GRC Analyst: Healthcare Compliance & Security

Remote Jobs • Town of Texas (WI)

On-site
USD 76,000 - 110,000
Remote work
Flexible scheduling
Remote GRC Analyst: Drive Compliance & Risk
Remote GRC Analyst: Drive Compliance & Risk

YipitData (Alternative) • United States

Remote
USD 92,000 - 113,000
Flexible work hours
Flexible vacation
401K match
+5
Security GRC Analyst: Remote-Ready, High-Impact Compliance
Security GRC Analyst: Remote-Ready, High-Impact Compliance

Whatnot • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Holiday and time off
Health insurance
Work from home
+8
Remote Information Security Analyst: GRC & Vendor Risk
Remote Information Security Analyst: GRC & Vendor Risk

Scale Up Recruiting Partners • San Juan (PR)

On-site
USD 90,000 - 130,000
Remote GRC Analyst: Cloud Security & Compliance Lead
Remote GRC Analyst: Cloud Security & Compliance Lead

vercel.com • Austin (NY)

Hybrid
USD 134,000 - 202,000
Equity
Healthcare
Mentorship
+2
GRC Analyst — Remote/Hybrid, Cloud Security & Compliance
GRC Analyst — Remote/Hybrid, Cloud Security & Compliance

Vercel • New York (NY)

Hybrid
USD 134,000 - 202,000
Competitive compensation
Inclusive Healthcare Package
Mentorship & events
+2