Senior Governance Risk and Compliance Analyst

Embedded Shishya

Orem (UT)

On-site

USD 120,000 - 160,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary
401k
Generous PTO

Job summary

RainFocus is hiring a Senior GRC Analyst to own and grow the company’s governance, risk, and compliance program. You will report to the CISO and drive program maturity, not just maintenance, across multiple frameworks.

You will lead risk assessments, update security policies, and partner with Engineering to advance vulnerability management and DLP initiatives while supporting audits and client inquiries.

Qualifications

  • Bachelor's degree in Technology, Cybersecurity or related field.
  • 6+ years of experience in GRC, IT audit, information security compliance, or related field.
  • Knowledge of SOC 2, ISO 27001, PCI DSS, NIST 800-series, GDPR.

Responsibilities

  • Lead and mature RainFocus's GRC program across SOC 2, ISO 27001, PCI DSS, and other frameworks.
  • Own annual security risk assessment process (NIST SP 800-30).
  • Maintain security policies, standards, and documentation.
  • Partner with Engineering to mature vulnerability management and secrets-scanning practices.
  • Grow and operationalize a Data Loss Prevention (DLP) program.
  • Drive AI governance policy, tooling, and monitoring.

Skills

GRC program leadership
SOC 2
ISO 27001
PCI DSS
NIST SP 800-30
Audit management
Policy development
Risk assessment
Regulatory compliance
Stakeholder communication

Education

Bachelor's degree in Technology, Cybersecurity

Tools

Drata
OneTrust
Vanta

Job description

RainFocus, one of the most innovative software companies, is in search of an Exceptional Senior Governance, Risk, and Compliance (GRC) Analyst.

About RainFocus

RainFocus cares about its employees, customers, and the world in which we live. Our rapidly growing team serves Fortune 500 companies like Adobe, Cisco, IBM, Oracle, VMware, and others to prepare and execute in-person, virtual, and hybrid events across the world. Those events are delivered through our industry-disrupting software platform, with groundbreaking business intelligence, to elevate the attendee experience, streamline event operations, and accelerate marketing results. We are well-funded, growing fast, and building a company that is changing the market — it will be challenging, fun, and exciting.

About the Role

We are seeking a highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team. In this role, you will own and grow RainFocus's governance, risk, and compliance program — maintaining our control framework, leading risk assessments, supporting audits, and driving the program's maturity forward rather than simply maintaining the status quo. You will report directly to the CISO and have significant ownership from day one.

Key Responsibilities
  • Lead RainFocus's GRC program across SOC 2, ISO 27001, PCI DSS, and other client/regulatory compliance frameworks, including audit prep, evidence collection, and auditor relationships.
  • Manage and mature our control framework, mapping new regulations and conducting gap assessments.
  • Own the annual security risk assessment process (NIST SP 800-30 methodology), including stakeholder interviews, risk scoring, and residual risk tracking.
  • Maintain and update security policies, standards, and documentation to ensure compliance with industry best practices.
  • Partner with Engineering and Security to mature vulnerability management and secrets‑scanning practices, moving these from reactive to proactive, pre‑deployment controls.
  • Help build out and operationalize a Data Loss Prevention (DLP) program, including policy design and rollout across email, endpoint, and cloud storage.
  • Grow and mature RainFocus's security awareness training program.
  • Drive AI governance efforts — policy, tooling, and monitoring for approved vs. unapproved AI tool usage across the company.
  • Identify and help close Shadow IT / unmanaged SaaS visibility gaps in partnership with IT.
  • Collaborate with cross‑functional teams to implement risk management practices and ensure compliance across the organization.
  • Respond to security and privacy inquiries from clients, partners, and employees.
  • Prepare and present reports on the organization's security and privacy compliance status, including program maturity and remediation progress.
  • Stay abreast of emerging security threats, vulnerabilities, and compliance requirements.
Qualifications
  • Bachelor's degree in Technology, Cybersecurity, or a related field is highly desirable.
  • 6+ years of proven experience in GRC, IT audit, information security compliance, or a related field.
  • In-depth knowledge of relevant regulations, standards, and frameworks (e.g., SOC 2, ISO 27001, PCI DSS, NIST 800‑series, GDPR, and others).
  • Experience running or contributing heavily to formal risk assessments — not just tracking a compliance checklist.
  • Professional certifications such as CISA, CRISC, CISSP, CIPP, or CIPM are highly desirable.
  • Familiarity with modern security tooling such as Drata, OneTrust, Vanta, etc.
  • Strong analytical and problem‑solving skills, with keen attention to detail.
  • Excellent communication and interpersonal skills to work effectively with technical and non‑technical stakeholders.
  • Ability to manage multiple projects and meet deadlines in a fast‑paced environment.
  • Experience with cloud security and compliance frameworks is a plus.
  • Experience with OneTrust or related GRC technologies is a plus.
Personal Characteristics
  • Strong work ethic and commitment to excellence.
  • Ability to work independently and as part of a team.
  • Excellent problem‑solving and analytical skills.
  • Strong communication and interpersonal skills.
  • Ability to adapt to change and learn quickly.
  • Passion for security and privacy.
Why work at RainFocus?

At RainFocus we delight millions of attendees at large‑scale events by delivering better insights, experiences, and marketing. We were able to pivot our product and services offering in 2020 to continue growing and serving new clients and events.

As a member of the RainFocus team, you will have the opportunity to experience first‑hand the impact of our platform at events around the world. Additionally, RainFocus offers competitive salaries, competitive benefits, 401k, generous PTO, and countless other team building activities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Governance Risk and Compliance Analyst
Senior Governance Risk and Compliance Analyst

RainFocus • United States

On-site
USD 120,000 - 160,000
401k
PTO
Senior Governance, Risk, and Compliance (GRC) Analyst (Remote)
Senior Governance, Risk, and Compliance (GRC) Analyst (Remote)

Socket.dev • Orem (UT)

Remote
USD 110,000 - 140,000
Senior GRC Analyst: AI, Security & Compliance Lead
Senior GRC Analyst: AI, Security & Compliance Lead

Embedded Shishya • Orem (UT)

On-site
USD 120,000 - 160,000
Competitive salary
401k
Generous PTO
Senior GRC & Security Risk Leader | AI & Compliance
Senior GRC & Security Risk Leader | AI & Compliance

RainFocus • United States

On-site
USD 120,000 - 160,000
401k
PTO
Senior GRC & Security Leader - Remote
Senior GRC & Security Leader - Remote

RainFocus • Orem (UT)

Remote
USD 120,000 - 160,000
Senior GRC Analyst - Remote: Own Governance & Compliance
Senior GRC Analyst - Remote: Own Governance & Compliance

Socket.dev • Orem (UT)

Remote
USD 110,000 - 140,000
CISO New York, NY, Remote
CISO New York, NY, Remote

raincards.xyz • New York (NY)

Hybrid
USD 150,000 - 200,000
Unlimited vacation
Flexible workplace
Comprehensive health and wellness benefits
+4
CISO
CISO

Rain • New York (NY)

Hybrid
USD 200,000 - 250,000
Unlimited vacation
Flexible working
Comprehensive health benefits
+4
Senior Analyst, GRC
Senior Analyst, GRC

procore • United States

On-site
USD 140,000 - 180,000
Event Delivery Consultant
Event Delivery Consultant

Rainfocus • Orem (UT)

Hybrid
USD 70,000 - 90,000
Competitive salaries
Generous PTO
401k benefits
+1