Senior GRC Analyst

United States Digital Space LLC

Boston (MA)

On-site

USD 130,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

United States Digital Space LLC is seeking a Senior Governance, Risk, and Compliance Analyst to lead day-to-day GRC operations in a fast-growing environment. The role partners with Legal, Security, Product, and other teams to advance compliance objectives and reduce enterprise risk.

The ideal candidate has 6+ years in cybersecurity or ERM, and strong ability to translate risk for both technical and non-technical stakeholders. Based in Boston, MA, relocation may be required.

Qualifications

  • 6+ years in cybersecurity or enterprise risk management.
  • Experience conducting structured IT risk assessments.
  • Familiar with NIST CSF, ISO 27001, GDPR, HIPAA and privacy rules.
  • Translate technical findings for non-technical stakeholders.

Responsibilities

  • Lead cyber, AI, and technology risk assessments across systems and cloud environments.
  • Maintain enterprise cyber risk register and track mitigation plans.
  • Translate findings into clear business risk scenarios for decision making.
  • Support quantitative risk analyses to improve measurement and reporting.
  • Prepare materials for Cyber Risk Committee and executive reporting.
  • Collaborate with architecture, security, legal, IT and product teams on risk in initiatives.

Skills

Cybersecurity
Risk management
Communication
Regulatory awareness

Education

Certifications: CRISC, CISSP, CISA, CGRC

Job description

At the company, we are on a mission to unlock human performance and extend healthspan. TheGovernance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurityrisks are identified, assessed, and communicated clearly across the organization.

the company is seeking an execution-oriented Senior Governance, Risk, and Compliance Analyst tolead the day-to-day execution and support the ongoing operation of the GRC program in a fast-paced, high-growth environment. This role is responsible for operations of GRC initiatives -including but not limited to structured cybersecurity and AI risk assessments, exceptionsmanagement, SDLC reviews and security compliance process ownership. The role will partnerclosely with Legal, Security, Product, and other teams to advance compliance objectives, reduceenterprise risk, and strengthen operational resilience.

The ideal candidate combines strong analytical thinking, critical risk mind-set with the ability tocommunicate complex risk scenarios clearly to both technical and non-technical stakeholders.

RESPONSIBILITIES:
  • Lead cyber, AI, and technology risk assessments across systems, cloud environments, business processes, and major initiatives, evaluating threats, vulnerabilities, controleffectiveness, and residual risk
  • Maintain and operate the enterprise cyber risk register, including drafting risk statements, tracking mitigation plans, and supporting governance and reporting processes
  • Translate technical findings, architectural concerns, and control gaps into clear business risk scenarios that support prioritization and decision-making
  • Support and help mature quantitative cyber risk analysis approaches such as FAIR to improve how risk is measured and communicated
  • Prepare materials and analysis to support the Cyber Risk Committee and executive risk reporting
  • Partner with Security Architecture to assess risk in system designs, cloud architecture, identity models, data flows, and platform changes
  • Collaborate with Security Engineering, Product Security, Legal, IT, and business teams to evaluate new initiatives, technology changes, artificial intelligence use cases, and third-party integrations through a risk lens
  • Conduct risk assessments for emerging technologies including artificial intelligence and machine learning systems, evaluating data usage, model behavior, externaldependencies, and security implications
  • Develop dashboards and reporting that provide leadership with visibility into key cybersecurity risks and trends.
  • Contribute to the continued development of cyber risk management processes
QUALIFICATIONS:
  • 6+ years of experience in cybersecurity or enterprise risk management, information security, or a related field
  • Demonstrated experience conducting structured cybersecurity or IT risk assessment
  • Experience maintaining risk registers and tracking risk mitigation or treatment activities
  • Deep understanding of security frameworks such as NIST CSF, ISO 27001, or PCI DSS, and familiarity with regulatory environments such as GDPR, HIPAA or other privacy anddata protection requirements
  • Ability to translate technical findings into clear business risk for non-technical stakeholders
  • Strong written and verbal communication skills with experience presenting findings to cross-functional teams
  • Experience assessing risks related to artificial intelligence, machine learning systems, or emerging technologies, including familiarity with emerging AI governance frameworkssuch as NIST AI RMF, ISO/IEC 42001, or similar standards
  • Professional certifications such as CRISC, CISSP, CISA, or CGRC are a plus

This role is based in the the company office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.

the company is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility

The the company compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values.

At the company, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of the company and share in the company’s long-term growth and success.

The U.S. base salary range for this full-time position is $130,000 - $170,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training.

In addition to the base salary, the successful candidate will also receive benefits and a generous equity package.

These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate’s specific qualifications, expertise, and alignment with the role’s requirements.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Risk & Compliance Analyst
AI Risk & Compliance Analyst

United States Digital Space LLC • Boston (MA)

On-site
USD 100,000 - 140,000
GRC Analyst - Third Party Risk
GRC Analyst - Third Party Risk

United States Digital Space LLC • Boston (MA)

On-site
USD 70,000 - 110,000
Security Project Manager
Security Project Manager

United States Digital Space LLC • Boston (MA)

On-site
USD 130,000 - 170,000
Senior Director, GRC
Senior Director, GRC

United States Digital Space LLC • San Francisco (CA)

On-site
USD 264,000 - 363,000
Equity (where applicable)
Bonus
Health, dental and vision insurance
+3
Director, Information Security
Director, Information Security

United States Digital Space LLC • Boston (MA)

On-site
USD 190,000 - 220,000
GRC Engineer
GRC Engineer

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 250,000
Healthcare coverage
Vision & dental coverage
HSA & FSA
+7
Senior GRC Analyst
Senior GRC Analyst

Whoop • Boston (MA)

On-site
USD 130,000 - 170,000
Equity
GRC Analyst, Operations & Risk
GRC Analyst, Operations & Risk

WHOOP • Boston (MA)

On-site
USD 60,000 - 90,000
Competitive base salary
Equity package
Comprehensive benefits
GRC Engineer
GRC Engineer

DeWinter Group • San Jose (CA)

On-site
USD 150,000 - 190,000
GRC Engineer
GRC Engineer

Talanto • San Mateo (CA)

On-site
USD 200,000 - 250,000
Healthcare coverage
Paid holidays
Parental leave