Source Job

India

  • Perform cybersecurity and technology risk assessments across systems, vendors, and business processes.
  • Support compliance with SOC 2, HIPAA, HITRUST, and PCI DSS frameworks.
  • Manage third-party risk assessments and track remediation of security findings.

Risk Assessment Compliance Security+

20 jobs similar to GRC - Security Analyst

Jobs ranked by similarity.

India

  • Conduct internal audits and compliance reviews against ISO 27001, ISO 42001, HIPAA, and GDPR frameworks.
  • Analyze control evidence and documentation within GRC platforms like Vanta to identify gaps and deficiencies.
  • Develop remediation plans and coordinate multiple audit initiatives in a fast-paced global environment.

Jobgether uses AI-powered matching to connect candidates with hiring companies. They are a growing platform focused on fair and objective candidate review.

$102,500–$102,500/yr
US Unlimited PTO

  • Own GRC workstreams from initial request through evidence collection, testing, and remediation.
  • Test security controls and conduct risk assessments to identify gaps and drive realistic remediation.
  • Support audits, vendor reviews, customer questionnaires, and policy maintenance across teams.

YipitData is a leading market research and analytics firm for the disruptive economy, providing actionable insights from alternative data. The company has a global presence with offices in the US, APAC, and India, and is recognized as an Inc. Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.

Canada

  • Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
  • Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
  • Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.

Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.

India Unlimited PTO

  • Own the audit journey for a portfolio of global customers from gap assessment through external audit closure.
  • Identify security and compliance gaps, turning them into practical remediation plans with engineering and leadership teams.
  • Serve as the coordination point between customers and independent auditors, facilitating evidence requests and communication.

Sprinto is an autonomous trust platform that centralizes compliance and security requirements across frameworks, vendors, and customers. Backed by Accel and Elevation, with $31.8M in funding, Sprinto serves over 4,000 organizations and fosters a remote-first culture of ownership and impact.

Europe 5w PTO

  • Build and maintain compliance frameworks in the Secfix platform, including ISO 27001, TISAX, SOC 2, GDPR, and more.
  • Own internal audits end-to-end for customers, ensuring they are prepared for external audits.
  • Collaborate with product and engineering to translate compliance gaps into structured product work and enhance platform quality.

Secfix automates security compliance for European companies, helping them achieve ISO 27001, GDPR, TISAX, and SOC 2 efficiently. They are a 100% remote team with hubs in Munich, Berlin, and London, recently raised a $12M Series A, and are backed by top VCs.

Global Unlimited PTO

  • Own and mature the compliance framework, including continuous controls monitoring, security awareness, and audit coordination.
  • Automate GRC processes using compliance platforms and AI tooling for evidence collection and risk management.
  • Develop policies, manage third-party risk, and scale customer security assurance end-to-end.

Monarch is an all-in-one personal finance platform that simplifies finances. Since 2021, they have become the top-recommended app, with a fully remote, AI-driven team focused on building a product people love.

Europe 4w PTO

  • Lead and develop the Information Security GRC strategy, roadmap, operating model, and governance cadence.
  • Coordinate SOC 2, DORA/CySEC-related assurance, internal and external audits, and regulatory requests.
  • Build, develop, and manage the GRC team and improve GRC efficiency through automation and reusable evidence.

JustMarkets is an international FinTech company. It is a growing organization with a focus on information security and compliance.

Global 5w PTO

  • Automate governance, risk, and compliance frameworks including ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials.
  • Engineer GRC workflows with internal systems to support compliance by design.
  • Translate compliance requirements into technical specifications for engineering teams and non-technical stakeholders.

Pleo builds spend solutions that make managing money seamless for finance teams and employees. They are a driven, progressive team of 850+ people from over 100 nationalities, committed to delivering the future of business spending.

US Unlimited PTO

  • Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
  • Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
  • Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.

India Unlimited PTO

  • Guide customers through setup and go-live, ensuring they reach their first audit milestone.
  • Collaborate with founders, CTOs, and security teams to map goals to actionable milestones.
  • Own next steps when stuck, partnering with internal teams to keep the project moving.

Sprinto is an autonomous trust platform that centralizes compliance, audits, risk management, and more for organizations worldwide. Backed by top investors, it serves over 4,000 companies in 75+ countries and fosters a remote-first, ownership-driven culture.

US

  • Own end-to-end audit evidence collection and validation across multiple compliance frameworks including FedRAMP, ISO 27001, and SOC 2.
  • Maintain and continuously verify technical controls across GCP, GitHub, and Microsoft 365 environments.
  • Serve as the primary liaison between GRC and technical teams to reduce audit burden and ensure continuous audit readiness.

A-LIGN is a leading provider of cybersecurity compliance programs, offering services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. They are the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor, operating in a high-growth, PE-backed environment.

$112,000–$140,000/yr
US

  • Ensure day-to-day compliance activities across PCI DSS, SOC 2, NIST, GDPR, and ISO frameworks.
  • Lead preparation and execution of internal and external audits, including evidence collection and remediation tracking.
  • Perform technical security and compliance reviews of third-party vendors and service providers.

iSeatz drives enduring brand loyalty through digital commerce and technology solutions for travel and lifestyle bookings. The company processes over $9B per year in transactions and has been honored as an Inc. Magazine Best Workplace for three consecutive years, emphasizing transparency, trust, and open communication.

US

  • Evaluate security controls and assess alignment with ISO 27001, SOC 2, NIST, and other frameworks.
  • Coordinate with internal teams and external auditors to support audit engagements and maintain control evidence.
  • Apply risk-based monitoring and contribute to compliance oversight, security operations, and secure-by-design initiatives.

The company is a mission-driven cybersecurity partner focused on strengthening information security, privacy, and organizational resilience. While specific size details are not provided, the team fosters a collaborative, high-impact environment with opportunities for continuous learning and career development.

Europe

  • Act as Information Security Officer for FinTech, supporting ISO 27001, SOCv2, and DORA implementation.
  • Coordinate security activities across teams, ensuring alignment with cyber security strategy and governance.
  • Track risks, gaps, and remediation, while preparing updates for security leadership.

Coinspaid Dev is the engineering brand behind the technology and infrastructure built within Coinspaid. With over 120 engineers and 11 years of industry experience, the team builds distributed systems and blockchain infrastructure across more than 20 blockchain networks.

US

  • Review system documentation and technical evidence against NIST, FISMA, RMF, FedRAMP, and Zero Trust requirements.
  • Perform control-gap analyses, maturity assessments, and compliance reviews; identify risks and recommend corrective actions.
  • Support authorization activities by preparing security plans, control implementation statements, and remediation documentation.

9th Way Insignia is a service-disabled, veteran-owned small business providing transformative technology solutions including cybersecurity, cloud modernization, software development, and data analytics to government customers. As a small business, it empowers its people to fearlessly drive change and offers a comprehensive benefits package.

$104,000–$140,000/yr
US

  • Develops and maintains information security policies, procedures, and controls ensuring compliance with HITRUST, SOC 2, HIPAA, and other frameworks.
  • Leads audit readiness and execution, managing HITRUST and SOC 2 Type II examinations from planning through report issuance.
  • Drives continuous improvement of security processes, risk management, and incident response across the organization.

MRO specializes in information security assurance and regulatory compliance, helping organizations manage risk and maintain audit readiness. The company fosters a security-focused culture with a team of experienced professionals.

$80,208–$83,372/yr
Poland

  • Lead the design, implementation, and maintenance of Hyland's enterprise ISO governance and certification program across multiple certifications, business units, and regions.
  • Drive strategic expansion of ISO scope, including advanced certifications like TISAX and C5, and establish governance models and control ownership across teams.
  • Measure and report ISO program health through metrics, dashboards, and reporting, while providing leadership and mentorship to compliance specialists.

Hyland is the pioneer of the Content Innovation Cloud, delivering enterprise intelligence through solutions that unlock actionable insights and drive automation. Trusted by thousands of organizations worldwide, including many Fortune 100 companies, Hyland has nearly 4,000 employees and fosters an employee-centric, inclusive culture.

India 4w PTO

  • Manage the information security ticketing process and serve as initial point of contact for security events.
  • Provide technical support, investigate alerts, and document resolutions.
  • Collaborate with GRC and other teams to improve security processes and awareness.

The partner company is a distributed organization focused on information security. The company size is not specified, but it offers a remote-first culture with comprehensive benefits.

India

  • Manage IT Compliance program and strategy, including SOX ITGC and ITAC scoping, risk assessment, and testing readiness.
  • Conduct control design assessments and effectiveness testing, driving remediation and validation with cross-functional teams.
  • Own ITAC portfolio, system inventory, and compliance outcomes, embedding automation and guiding AI-enabled technology adoption.

HighLevel is an AI-powered business operating system for agencies, entrepreneurs, and SMBs to build, automate, and scale. With over 2,000 team members across 10+ countries, it operates as a global, remote-first organization known for speed and ownership.

$6,000–$7,500/mo
US

  • Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, and other enterprise requirements.
  • Automate compliance workflows, evidence collection, access reviews, and security checks.
  • Partner with Engineering and Security to implement controls around access management, infrastructure, data protection, logging, and vulnerability management.

Retell AI is reimagining the call center with cutting-edge voice AI. Backed by Y Combinator, the company has scaled to $60M ARR with a team of 40 people, and is looking for ambitious builders to tackle hard technical problems.