Senior GRC & Security Risk Analyst — Remote

XBOW

United States

Remote

USD 120,000 - 190,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Competitive stock options
Remote-first culture

Job summary

XBOW is seeking an Information Security Analyst, GRC, to scale security and trust as we grow. You will support customer reviews, contract reviews with legal, and vendor risk assessments while collaborating with IT, Security, Legal, Sales, and Customer teams.

You’ll work in a fast-moving, remote-first startup, helping mature risk programs, maintain risk registers, and drive compliance with SOC 2, ISO 27001, NIST, GDPR, and HIPAA.

Qualifications

  • 7+ years in risk, compliance, security assurance, or related roles
  • Hands-on experience in technical roles (Engineering, IT, or security)
  • Experience completing or reviewing security questionnaires and risk assessments
  • Familiar with SOC 2, ISO 27001, NIST, GDPR, HIPAA frameworks
  • Experience with vendor/third-party risk assessments
  • Strong written communication; highly organized and detail-oriented
  • Comfortable in a fast-moving, remote-first startup
  • Knowledge of AI tooling to improve productivity while managing risk

Responsibilities

  • Handle technical security questionnaires, risk assessments, and due-diligence requests for customers and prospects
  • Explain XBOW’s security controls, architecture, and compliance posture to Sales and Customer teams
  • Assess and manage third-party/vendor security risk, including SaaS providers
  • Investigate alerts to stay compliant with compliance programs using Vanta
  • Maintain risk assessment frameworks, methodologies, and documentation
  • Track remediation of risks with internal stakeholders
  • Support audits, customer reviews, and internal assurance activities
  • Coordinate risk management sessions and streamline processes as the company scales

Skills

Security communications
Organization
Remote work adaptability
AI tooling familiarity

Tools

Vanta

Job description

XBOW is seeking an Information Security Analyst, GRC, to scale security and trust as we grow. You will support customer reviews, contract reviews with legal, and vendor risk assessments while collaborating with IT, Security, Legal, Sales, and Customer teams.

You’ll work in a fast-moving, remote-first startup, helping mature risk programs, maintain risk registers, and drive compliance with SOC 2, ISO 27001, NIST, GDPR, and HIPAA.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Remote GRC & Security Risk Analyst
Senior Remote GRC & Security Risk Analyst

Xbow • California (MO)

Hybrid
USD 121,000 - 161,000
Stock options
Remote-first
Information Security Analyst, GRC
Information Security Analyst, GRC

Xbow • California (MO)

Hybrid
USD 121,000 - 161,000
Stock options
Remote-first
Senior GRC & InfoSec Risk Analyst (Remote)
Senior GRC & InfoSec Risk Analyst (Remote)

Golden Technology • North Carolina

Hybrid
USD 120,000 - 160,000
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

Hybrid
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Remote Senior Security GRC Analyst — Scale Compliance
Remote Senior Security GRC Analyst — Scale Compliance

Monarch Money • Covina (CA)

On-site
USD 140,000 - 190,000
Work anywhere, fully remote
Equity compensation
Home-office stipend
+3
GRC Analyst I — SOC 2 & ISO 27001 | Remote
GRC Analyst I — SOC 2 & ISO 27001 | Remote

Sensiba LLP • United States

On-site
USD 49,000 - 79,000
Leave entitlements
Pension scheme
Flexible remote work
+3
Senior GRC Advisor (Remote) – Risk & Compliance Leader
Senior GRC Advisor (Remote) – Risk & Compliance Leader

Soteria-LLC • Charleston (SC)

On-site
USD 120,000 - 180,000
Senior GRC Analyst - Remote: Own Governance & Compliance
Senior GRC Analyst - Remote: Own Governance & Compliance

Socket.dev • Orem (UT)

Remote
USD 110,000 - 140,000
Remote GRC Lead: PCI/SOX, AI-Driven Compliance
Remote GRC Lead: PCI/SOX, AI-Driven Compliance

Subsplash • United States

On-site
USD 95,000 - 105,000
Generous paid time off
Medical, dental, vision coverage
401(k) matching
+2
Remote GRC Analyst: Security Controls & Risk Champion
Remote GRC Analyst: Security Controls & Risk Champion

Yipitdatajobs • United States

Remote
USD 92,000 - 113,000
Flexible work hours
Flexible vacation
401K match
+4