Security Governance Risk & Compliance Analyst I

BigCommerce Pty.

Northern (KY)

On-site

USD 50,000 - 73,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Commerce is seeking a GRC Analyst to join our Governance, Risk & Compliance team. You’ll support day-to-day risk and vendor assessments, ensure documentation, and assist audits.

This is an opportunity for early career professionals to grow within a globally distributed team, with exposure to AI tools like Claude Code and a strong emphasis on accuracy and cross-functional collaboration. The role focuses on risk assessments, control testing, and audit coordination, offering growth in enterprise

Qualifications

  • 0–2 years of GRC, risk operations, or compliance experience.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Business, or related field.
  • Genuine interest in GRC engineering and a willingness to learn quickly in a fast-paced environment required
  • Hands‑on familiarity with Claude Code or similar AI coding tools, and an ability to think through how they could be applied to cybersecurity or GRC work (hobby projects welcome)
  • Strong written and verbal communication skills - you'll be working cross-functionally and with external vendors
  • High attention to detail and comfort working with documentation, spreadsheets, and tracking tools
  • Proficiency in Microsoft Office or Google Workspace
  • Nice To Have Coursework or certification in cybersecurity or risk management (Security+, CISA, etc.)
  • Exposure to compliance frameworks such as SOC 2, ISO 27001, NIST, or PCI-DSS
  • Experience in an operations or process-driven role (internship or otherwise)

Responsibilities

  • Support third-party risk assessments by reviewing vendor security questionnaires, documentation, and due diligence materials
  • Maintain and update the vendor risk register and track remediation activities to closure
  • Assist with internal control testing and evidence collection for compliance frameworks (SOC 2, ISO 27001, PCI-DSS, etc.)
  • Help coordinate audit requests and liaise with internal stakeholders to gather required documentation
  • Monitor policy and procedure documentation, flagging items due for review or update
  • Assist in tracking risk exceptions, escalating items that require senior review
  • Support reporting and metrics preparation for leadership and committee-level reviews
  • Contribute to process improvement initiatives as the program scales

Skills

Written communication
Verbal communication
Detail orientation
Cross-functional collaboration

Education

Bachelor's degree in Computer Science
Bachelor's degree in Cybersecurity
Bachelor's degree in Information Systems
Bachelor's degree in Business

Tools

Claude Code
Microsoft Office
Google Workspace

Job description

Welcome to the Agentic Commerce Era At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce, Feedonomics, and Makeswift, we connect the tools and systems that power growth, enabling businesses to unlock the full potential of their data, deliver seamless and personalized experiences across every channel, and adapt swiftly to an ever-changing market. We believe in harnessing AI responsibly to unlock new possibilities, and we’re looking for individuals who use it intentionally to solve problems, accelerate outcomes, and expand what’s possible in their role. Our purpose is to help businesses confidently solve complex commerce challenges so they can build smarter, adapt faster, and grow on their own terms. If you want to be part of a team of bold builders, sharp thinkers, and technical trailblazers who shape the future of commerce, this is the place for you. We're looking for a detail-oriented and curious GRC Analyst to join our Governance, Risk & Compliance team. In this role, you'll support the day-to-day operations of our risk and compliance program, helping assess third-party vendors, maintain policy documentation, track control evidence, and support audit activities. We're especially interested in candidates who've explored tools like Claude Code and are curious about how AI can be applied to cybersecurity and compliance work. This is a great opportunity for someone early in their career who wants to build a strong foundation in enterprise risk management and information security compliance, joining a senior, globally distributed team that will invest in your growth from day one.

What You’ll Do
  • Support third-party risk assessments by reviewing vendor security questionnaires, documentation, and due diligence materials
  • Maintain and update the vendor risk register and track remediation activities to closure
  • Assist with internal control testing and evidence collection for compliance frameworks (SOC 2, ISO 27001, PCI-DSS, etc.)
  • Help coordinate audit requests and liaise with internal stakeholders to gather required documentation
  • Monitor policy and procedure documentation, flagging items due for review or update
  • Assist in tracking risk exceptions, escalating items that require senior review
  • Support reporting and metrics preparation for leadership and committee-level reviews
  • Contribute to process improvement initiatives as the program scales
What We’re Looking For
  • 0–2 years of experience in GRC, risk operations, compliance, or a related function (internships count)
  • Bachelor's degree Computer Science, Cybersecurity, Information Systems, Business, or a related field. Equivalent work experience also considered.
  • Genuine interest in GRC engineering and a willingness to learn quickly in a fast-paced environment required
  • Hands‑on familiarity with Claude Code or similar AI coding tools, and an ability to think through how they could be applied to cybersecurity or GRC work (hobby projects welcome)
  • Strong written and verbal communication skills - you'll be working cross-functionally and with external vendors
  • High attention to detail and comfort working with documentation, spreadsheets, and tracking tools
  • Proficiency in Microsoft Office or Google Workspace
  • Nice To Have Coursework or certification in cybersecurity or risk management (Security+, CISA, etc.)
  • Exposure to compliance frameworks such as SOC 2, ISO 27001, NIST, or PCI-DSS
  • Experience in an operations or process-driven role (internship or otherwise)

Salary Transparency Range: $49,729.00 - $73,130.00

Where applicable, this role may also be eligible for variable compensation (such as bonus or commission), equity, and benefits in accordance with local policies.

Inclusion and Belonging

At Commerce, we believe that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community.

We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive.

We are committed to creating an inclusive and accessible hiring experience for all candidates. If you require accommodations or adjustments at any stage of the recruitment process, please let us know and we will work with you to meet your needs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Governance Risk & Compliance Analyst I
Security Governance Risk & Compliance Analyst I

BigCommerce Pty • Northern (KY)

Hybrid
USD 50,000 - 73,000
Security Governance Risk & Compliance Analyst I
Security Governance Risk & Compliance Analyst I

Commerce • Northern (KY)

Hybrid
USD 50,000 - 73,000
Equity
Benefits
Bonus potential
Security Governance Risk & Compliance Analyst I at Commerce
Security Governance Risk & Compliance Analyst I at Commerce

Matcha • Northern (KY)

Hybrid
USD 50,000 - 73,000
Security Governance Risk & Compliance Analyst I
Security Governance Risk & Compliance Analyst I

Commerce • Town of Texas (WI)

On-site
USD 50,000 - 73,000
Security Governance Risk & Compliance Analyst I
Security Governance Risk & Compliance Analyst I

bigcommerce • United States

On-site
USD 50,000 - 73,000
Bonus eligibility
Equity
Benefits
GRC Analyst I - AI-Driven Commerce Security
GRC Analyst I - AI-Driven Commerce Security

BigCommerce Pty. • Northern (KY)

Hybrid
USD 50,000 - 73,000
Staff Software Engineer
Staff Software Engineer

BigCommerce Pty. • Austin (TX)

On-site
USD 186,000 - 280,000
Hybrid work model
Pay transparency
Staff Software Engineer
Staff Software Engineer

BigCommerce Pty • Austin (TX)

Hybrid
USD 186,000 - 280,000
Staff Software Engineer
Staff Software Engineer

Commerce • Austin (TX)

Hybrid
USD 186,000 - 280,000
GRC Analyst I: AI-Driven Security & Compliance
GRC Analyst I: AI-Driven Security & Compliance

Commerce • Northern (KY)

Hybrid
USD 50,000 - 73,000
Equity
Benefits
Bonus potential