Source Job

$100,000–$120,000/yr
US Unlimited PTO

  • Conduct ongoing risk reviews and maintain an up-to-date risk register.
  • Support risk assessments across critical business processes and systems.
  • Partner with stakeholders to develop and track risk mitigation plans through resolution.

GRC Risk Management Compliance Audit Information Security

16 jobs similar to GRC Analyst

Jobs ranked by similarity.

North America

  • Support CapIntel’s Governance, Risk, and Compliance program
  • Manage third-party risk and customer security reviews
  • Support operational security, privacy, and security awareness initiatives

CapIntel is a software platform built for wealth management enterprises to help financial advisors explain complex investment strategies to their clients. Since launching in 2019, CapIntel has seen rapid adoption and industry recognition, earning top placements in Deloitte’s Technology Fast 50 Canada and Fast 500 North America in 2025, ranking us among the fastest -growing technology companies.

4w paternity

  • Oversee third-party and internal risk assessments to support enterprise information security and governance, risk, and compliance (GRC) initiatives.
  • Manage vendor due diligence, maintains an accurate risk register, partners with internal stakeholders on mitigation strategies.
  • Drive continuous improvement of the risk and compliance framework.

Concorde Career Colleges is committed to a policy of Equal Employment Opportunity and will not discriminate against an applicant or employee based on race, color, religion, religious creed, national origin, ancestry, sex, age, veteran or military status, or any other legally protected characteristic. Concorde Career Colleges offer short career-focused programs preparing students for the healthcare industry.

US Canada India Europe

  • Vendor and contractor risk assessment process during onboarding, adhering to a defined Service Level Agreement (SLA).
  • Conduct annual vendor monitoring and re-assessment processes for existing vendors.
  • Maintain the vendor inventory and collaborate with vendors on an ongoing basis to reduce identified risks.

Juniper Square's mission is to unlock the full potential of private markets by digitizing them and bringing efficiency, transparency, and access. They have a values-driven organization that offers employees a variety of ways to work, ranging from a fully remote experience to working full-time in one of their physical offices.

Europe 5w PTO

  • Maintain documentation for ISO/IEC 27001 & ISO/IEC 42001; improve activities.
  • Extract security requirements from client MSAs; identify gaps and risks.
  • Coordinate internal and client audit requests; collect evidence.

Avalere Health's mission is to ensure every patient is identified, treated, supported, and cared for. They bring Advisory, Medical, and Marketing teams together to forge unconventional connections, building a future where healthcare is not a barrier and no patient is left behind.

$72,781–$83,698/yr
Canada

  • Perform GRC functions and maintain the Cyber Security Risk register.
  • Execute third party risk processes for cyber and perform/execute on awareness programs and phishing processes.
  • Liaise with the vendor management (VM) team to conduct security assessments of existing and prospective vendors.

Warner Music Group is a global collective of music makers and music lovers, tech innovators and inspired entrepreneurs, game-changing creatives and passionate team members. They turn dreams into stardom and audiences into fans. WMG is committed to creating a work environment that actively values, appreciates, and respects everyone and encourages applications from people with a wide variety of backgrounds and experiences.

Global

  • Lead end-to-end audit execution across SOC 2, ISO 27001, ISO 42001, ISO 27701, HIPAA, and GDPR and maintain year-round audit readiness.
  • Build and mature Atlan's risk management program and turn abstract risk conversations into measurable metrics with clear ownership and quarterly leadership reviews.
  • Integrate our GRC platform with cloud infrastructure, CI/CD pipelines, HR systems, and product engineering tooling to automate evidence collection and continuous control testing.

Atlan is building the missing context layer for data and AI, helping enterprises close the AI value chasm and finally move AI pilots into production. We are backed by world-class investors including GIC, Insight Partners, Meritech, Peak XV, and Salesforce Ventures and trusted by global enterprises like Mastercard, Workday, General Motors, Unilever and others.

$125,000–$140,000/yr
US

  • Collaborate with the engineering departments to implement security controls from approved security frameworks and drive best IT practices.
  • Interface with internal partner teams to help drive best practices and compliance.
  • Evaluate and perform Risk Assessments of new software solutions with internal partners.

Judi Health is an enterprise health technology company providing a comprehensive suite of solutions for employers and health plans. They consolidate all claim administration-related workflows in one scalable, secure platform and are working with clients, rebuilding trust in healthcare in the U.S.

Global

  • Lead audit readiness and execution for SOC 2, ISO 27001, PCI DSS, and other compliance frameworks relevant to our customer base
  • Manage the compliance lifecycle in a compliance platfom (such as Vanta, Drata etc) including evidence collection, control mapping, and continuous monitoring
  • Coordinate cross-functional audit activities with engineering, product, security, infrastructure, and support teams to gather evidence and remediate findings

Supabase is a born-remote and open-source-first company that provides tools developers love. They have 180+ team members across 40+ countries, and deeply believe in the open-source ecosystem and strive to support existing tools and communities.

North America 5w PTO

  • Enhances the strategic pillars of a security compliance program and facilitate day-to-day compliance operations.
  • Involved in multiple areas of the business where compliance and security impact operations.
  • Works on assignments that are complex and require professional skepticism, judgment, initiative, and knowledge of SaaS Company positions.

Optro is the leading audit, risk, ESG, and InfoSec platform on the market, surpassing $300M ARR and continuing to grow. More than 50% of the Fortune 500 leverage their award-winning technology. They inspire each other to innovate and are proud of what they are producing.

Europe

  • Own our security and compliance documentation accurate and up to date.
  • Support our commercial teams in complex information security and compliance negotiations.
  • Take ownership of maintaining our current ISO 27001 compliance and certification.

Gearset is trusted by some of the largest companies in the world to handle their Salesforce DevOps. They are committed to protecting data through a modern approach to security and compliance.

US

  • Develops and executes a robust control testing program.
  • Collaborates with business units to remediate control weaknesses.
  • Delivers regular reports to senior management.

The Bancorp Bank, N.A. is committed to providing individuals and small businesses with unique online banking and lending products and services. They foster a culture of innovation and provide growth opportunities.

$93,500–$182,850/yr
US

  • Coordinate risk exceptions across the enterprise.
  • Maintain the operational risk register.
  • Support business continuity and disaster recovery planning.

Commvault is the gold standard in cyber resilience, empowering customers to uncover, take action, and rapidly recover from cyberattacks. Over 100,000 organizations rely on Commvault to reduce risks, improve governance, and do more with data.

$235,000–$315,000/yr
US

  • Build automation into GRC
  • Deploy GRC-as-Code / Policy-as-Code
  • Deploy AI into our GRC processes where appropriate

Smartsheet helps people and teams achieve their goals with seamless work management and scalable solutions. They empower teams to automate manual tasks, uncover insights, and scale smarter, fostering a culture where challenge meets purpose and passion turns into progress.

Global

  • Support Business Continuity, Crisis Management, and Disaster Recovery processes.
  • Conduct Business Impact Analysis, including information gathering, impact assessment, and documentation of results.
  • Work closely with technical teams to plan, coordinate, and monitor disaster recovery tests, including existing tests and the development of new scenarios.

Pismo, founded in 2016, provides a comprehensive processing platform for banking, card issuing, and financial market infrastructure, helping customers innovate and build next-gen banking and payment solutions. With over 500 employees across 10 countries, Pismo joined Visa in 2024, leveraging Visa’s solutions.

US Unlimited PTO

  • Manage SOC 2 Type II audits, serving as the primary point of contact for auditors and collaborators.
  • Coordinate HIPAA compliance assessments, including risk analyses, policy reviews, and Business Associate Agreement (BAA) management.
  • Conduct structured gap analyses against applicable frameworks to identify control deficiencies and develop prioritized remediation roadmaps.

Rad AI is transforming healthcare with AI-driven solutions, revolutionizing radiology to save time, reduce burnout, and improve patient care. They have secured over $140M in funding and recognized as a fast-growing company, fostering transparency, inclusion, and close collaboration.

US

  • Partner with organizations of all sizes and industries
  • Evaluate IT and security controls for compliance and effectiveness
  • Advise on security + privacy requirements (state & federal)

Clark Schaefer Hackett provides customized solutions leveraging strategic skills, financial and operational leadership, and technological advances. They are an elite community that includes trusted advisors with Clark Schaefer Hackett, Clark Schaefer Consulting, and Clark Schaefer Strategic HR.