Source Job

GRC Analyst

Mesh
US Unlimited PTO

  • Own and strengthen the controls environment, ensuring compliance requirements are effectively implemented and maintained.
  • Support and mature the GRC program, including SOC 2 operations and alignment with security frameworks such as NIST.
  • Build and maintain Business Continuity and Disaster Recovery programs, including BIAs, continuity plans, and recovery runbooks.

GRC SOC 2 NIST Risk Assessment Business Continuity

13 jobs similar to GRC Analyst

Jobs ranked by similarity.

$155,000–$225,000/yr
Global Unlimited PTO

  • Drive compliance efforts to unlock business capabilities
  • Secure Owner by helping teams successfully prevent and remediate vulnerabilities
  • Help teams build better and more secure systems by avoiding pitfalls of risk.

Owner is an AI-native system local business owners use to succeed, starting with restaurants. It's building the system that replaces the many tools owners use to run their business and powers everything from the restaurant’s website, online ordering, CRM, POS, and more. The team is in the low hundreds.

$130,000–$160,000/yr
US Canada Unlimited PTO

  • Maintain and improve information security policies, standards, and procedures.
  • Support SOC 2, ISO 27001, and HITRUST readiness, audit preparation, and evidence collection.
  • Support vendor security reviews, third-party risk assessments, and remediation tracking.

Benepass is making benefits easy through its customizable fintech platform. They enable People teams to implement, administer, and track benefits that meet employees where they are. The company has raised approximately $75 million in equity capital and is backed by leading investors.

12w maternity 12w paternity

  • Manage and expand Valon's security and privacy compliance program across key frameworks and regulations.
  • Build and scale modern Security GRC capabilities that leverage AI-enabled tools and processes, reducing manual overhead while optimizing risk and compliance operations.
  • Maintain and evolve Valon's risk management practices; facilitate risk assessments across teams and track remediation of identified issues to closure.

Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. We're a Series C company backed by a16z, transforming industries that others have written off as too complex to innovate.

US Canada

  • Design and implement automation, dashboards, and integrations that power our Governance, Risk, and Compliance (GRC) operations.
  • Operationalizing and expanding our GRC platform (Drata), building AI-assisted workflows that automate evidence collection, control monitoring, and vendor risk.
  • Manage project delivery across multiple GRC automation initiatives simultaneously — maintaining clear scope, milestones, and stakeholder visibility without sacrificing quality.

1Password is building the foundation for a safe, productive digital future. They innovated the market-leading enterprise password manager and pioneered Unified Access Management, a new cybersecurity category built for the way people and AI agents work today. 1Password has surpassed $400M in ARR and has over 180,000 businesses using their product.

US Canada

  • You'll partner directly with the Senior Manager of GRC to lead our commercial audit programs, from evidence collection and control testing to deep technical walkthroughs with external auditors and internal SMEs.
  • You'll own the question of what "good evidence" looks like across SOC 2 Type II, ISO 27001/27017/27018, and ISO 27701, and you'll know where to find it in the systems that generate it.
  • Help build the AI-assisted workflows and automation that make our audit programs more efficient and our compliance posture more continuous.

1Password is building the foundation for a safe, productive digital future. They ensure every identity is authentic, every application sign-in is secure, and every device is trusted. Over 180,000 businesses trust 1Password. We prioritize collaboration, clear and transparent communication, receptiveness to feedback.

US

  • Lead enterprise BC/DR program including strategy, governance, BIA, testing, and reporting to leadership.
  • Support risk assessments, policy exceptions, third-party resilience, and align with ERM and legal teams.
  • Drive continuous improvement of recovery capabilities, process automation, and regulatory compliance across IS frameworks.

BHG Financial provides leading-edge financial solutions to high-earning professionals, small businesses, and institutions through an extensive network of community banks. The company has a strong legacy in financial services, a positive mental attitude culture, and is Great Place to Work certified.

$3,780–$4,752/mo
Europe

  • Lead cyber risk assessments and control reviews to identify gaps.
  • Act as a bridge between GRC and technical teams.
  • Own and maintain the Internal Control Framework.

Inetum is a global leader in IT services, dedicated to delivering innovative solutions to our clients. They are committed to fostering a dynamic and inclusive work environment that values diversity, where creativity and collaboration can thrive. Present in 19 countries with more than 28,000 employees worldwide.

India Unlimited PTO

  • Build the function by creating delivery operating model and reusable IP.
  • Deliver and scale service lines, including framework digitization and packaged services.
  • Own commercial outcomes by defining service packaging and pricing models.

Sprinto is an AI-native GRC platform that helps organizations manage risks, audits, vendor oversight, and continuous monitoring from a single connected platform. With a team of 350+ employees serving 3,000+ customers across 75+ countries, they combine scale with expertise to deliver trust and compliance.

US Unlimited PTO

  • Serve as a senior security and compliance advisor for clients in finance, VC, PE, and biotech, translating complex requirements into practical action plans.
  • Lead consultative conversations on governance, risk, controls, AI adoption, and audit readiness, delivering clear executive-level recommendations.
  • Build and refine Outpost's service delivery playbooks, templates, and documentation to scale the offering and improve client experience.

Pliancy is fundamentally changing how businesses value technology, specializing in IT support for life sciences, capital management, and startups. With a people-first culture, the company prioritizes curiosity and empathy, investing in long-term employee success.

$4,750–$6,250/mo
Poland

  • Lead and maintain the IT Compliance Program, ensuring alignment with industry best practices and regulatory requirements.
  • Stay abreast of relevant laws, regulations, and industry standards (e.g. GDPR, ISO 27001, NIS2, SOC 2,...).
  • Serve as a main point of contact for senior management and stakeholders on regulatory and IT compliance matters.

EcoVadis is the leading provider of business sustainability ratings, offering solutions backed by experts and technology. They analyze data to provide companies with insights into their environmental, social, and ethical risks, fostering a culture of global sustainability change.

$95,000–$105,000/yr
US

  • Act as the primary point of contact for external auditors and lead the end-to-end execution of PCI DSS audits.
  • Orchestrate and lead the quarterly and semi-annual user access review process across all critical systems.
  • Execute and maintain a comprehensive, year-round Security Awareness Training program.

Subsplash builds The Ultimate Engagement Platform™ for churches, Christian ministries, non-profits, and businesses around the world. They are an award-winning team of 280+ mission-driven people who are committed to humility, innovation, and excellence.

$101,500–$159,500/yr
US

  • Serve as a member of Sword's GRC team, contributing to security compliance across all products and services.
  • Define and maintain the CMMC assessment boundary, working across infrastructure, engineering, and business teams to ensure the scope is accurate and defensible.
  • Translate identified gaps into prioritized remediation tasks with clear ownership, for audiences ranging from DevOps engineers to clinical operations managers.

Sword Health is building AI to heal billions and unlock humanity’s full potential. As both a clinical-centric frontier AI lab and an applied AI platform, Sword is reimagining how care is delivered at scale. They have over 700,000 members across three continents and have raised more than $500 million from leading investors.

US

  • Partner with Security Engineering, Risk, Product, and Infrastructure teams to bake security and compliance into the process.
  • Dive deep into the security stack to identify execution blockers and actively architect the technical solutions to implement them.
  • Define the technical milestones for high-stakes initiatives like Zero Trust and IAM overhauls, translating a broad vision into a precise execution roadmap.

Human Interest aims to provide all workers access to retirement benefits. They are a high-growth fintech company that is financially backed by investors such as BlackRock, TPG, and SoftBank.