Senior Remote GRC & Security Risk Analyst

Xbow

California (MO)

Hybrid

USD 121,000 - 161,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Stock options
Remote-first

Job summary

XBOW, redefining cybersecurity with an AI-driven autonomous pentester, seeks an Information Security Analyst, GRC to scale security reviews, vendor risk, and regulatory compliance. You will coordinate with Legal on contracts and drive risk management across IT, Security, Engineering, and Sales in a fast-moving environment.

You’ll help shape policies, risk registers, and evidence for SOC 2, ISO 27001, and other frameworks while advocating pragmatic, scalable risk practices across the company.

Qualifications

  • 7+ years of experience in risk, compliance, security assurance, or related roles.
  • Hands-on technical experience in Engineering, IT or security operations.
  • Experience completing or reviewing technical security questionnaires and customer risk assessments.
  • Familiarity with common security frameworks (SOC 2, ISO 27001, NIST, GDPR, HIPAA).
  • Experience conducting or supporting vendor/ third-party risk assessments.
  • Strong written communication; ability to explain complex security concepts clearly.
  • Highly organized and detail-oriented, with pragmatic risk approach.
  • Comfortable in a fast-moving, remote-first startup environment.
  • Familiar with using modern AI tooling to improve productivity whilst managing risk.

Responsibilities

  • Support customers with security questionnaires, risk assessments, and due-diligence requests.
  • Explain XBOW’s security controls, architecture, and compliance posture to Sales and Customer teams.
  • Assess and manage third-party and vendor security risk.
  • Investigate and resolve alerts using the Vanta product.
  • Maintain risk assessment frameworks, methodologies, and documentation.
  • Track remediation of identified risks with internal stakeholders.
  • Contribute to compliance initiatives aligned with SOC 2, FedRAMP, ISO 27001, and ISO 42001.
  • Maintain clear risk registers, policies, and supporting evidence.
  • Coordinate risk management sessions and processes.
  • Identify opportunities to streamline and automate risk and compliance as the company scales.
  • Support audits, customer reviews, and internal assurance activities.

Skills

Risk management
Compliance
Security assurance
Security questionnaires
Vendor risk
Written communication
Regulatory frameworks
Remote work

Tools

Vanta

Job description

XBOW, redefining cybersecurity with an AI-driven autonomous pentester, seeks an Information Security Analyst, GRC to scale security reviews, vendor risk, and regulatory compliance. You will coordinate with Legal on contracts and drive risk management across IT, Security, Engineering, and Sales in a fast-moving environment.

You’ll help shape policies, risk registers, and evidence for SOC 2, ISO 27001, and other frameworks while advocating pragmatic, scalable risk practices across the company.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC & Security Risk Analyst — Remote
Senior GRC & Security Risk Analyst — Remote

XBOW • United States

Remote
USD 120,000 - 190,000
Competitive stock options
Remote-first culture
Information Security Analyst, GRC
Information Security Analyst, GRC

Xbow • California (MO)

Hybrid
USD 121,000 - 161,000
Stock options
Remote-first
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Remote GRC Lead: PCI/SOX, AI-Driven Compliance
Remote GRC Lead: PCI/SOX, AI-Driven Compliance

Subsplash • United States

On-site
USD 95,000 - 105,000
Generous paid time off
Medical, dental, vision coverage
401(k) matching
+2
GRC Analyst: Risk, Compliance & Security Awareness
GRC Analyst: Risk, Compliance & Security Awareness

Protective • United States

Remote
USD 70,000 - 77,000
Health insurance
Dental insurance
Vision insurance
+5
Remote GRC Analyst: Security Controls & Risk Champion
Remote GRC Analyst: Security Controls & Risk Champion

Yipitdatajobs • United States

Remote
USD 92,000 - 113,000
Flexible work hours
Flexible vacation
401K match
+4
Senior GRC & InfoSec Risk Analyst (Remote)
Senior GRC & InfoSec Risk Analyst (Remote)

Golden Technology • North Carolina

Hybrid
USD 120,000 - 160,000
Senior GRC Consultant — Remote, Strategic Risk & Compliance
Senior GRC Consultant — Remote, Strategic Risk & Compliance

Cyberr • United States

On-site
USD 90,000 - 130,000
Senior GRC & InfoSec Systems Analyst
Senior GRC & InfoSec Systems Analyst

Dorsey & Whitney LLP • Wilmington (DE)

On-site
USD 114,000 - 150,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000