Source Job

Global Unlimited PTO

  • Scale, automate, and optimize existing GRC, compliance, and customer assurance programs.
  • Optimize and automate an existing third-party risk program by improving risk signal quality.
  • Evaluate, implement and maintain GRC tooling with a focus on AI-powered automation to minimize operational overhead.

SOC2 CCPA GDPR GRC Compliance

14 jobs similar to Security GRC Analyst

Jobs ranked by similarity.

$126,480–$175,000/yr
US

  • Lead the configuration and management of GRC tools to ensure integration with security systems.
  • Manage the main dashboard for SOC 2 reporting, ensuring accuracy and compliance.
  • Develop and maintain a comprehensive risk management program and conduct risk assessments.

Engine is transforming business travel into something personalized, rewarding, and simple. They have over 20,000 companies relying on Engine to support over 1 million travelers and billions in annual bookings each year and have been recognized as one of the fastest-growing travel and fintech platforms in North America.

US Unlimited PTO

  • Lead SOC 2 and ISO programs through the full audit lifecycle.
  • Build integrations that continuously gather compliance evidence from AWS, GitHub, identity providers, and internal systems.
  • Evaluate and monitor third-party vendors for security and compliance risk.

Fieldguide is establishing a new state of trust for global commerce and capital markets through automating and streamlining the work of assurance and audit practitioners. The company is based in San Francisco, CA, and built as a remote-first company with a team that is inclusive, driven, humble and supportive.

GRC Analyst

Astra
US

  • Own day-to-day execution of SOC 1, SOC 2, PCI DSS, and ISO 27001 readiness and audit cycles.
  • Develop and maintain policies, procedures, risk assessments, control narratives, and supporting documentation.
  • Facilitate risk assessments for systems, vendors, products, and business initiatives.

Astra is building mission-critical infrastructure for moving money at scale. Their platform processes billions in annual transaction volume with 99.9%+ uptime, powering real-time transfers, bank debits, card disbursements, and complex financial compliance systems.

$162,000–$230,000/yr
US

  • Own and operate compliance programs such as SOC 2, ISO 27001, ISO27701, HIPAA, and TISAX.
  • Lead and manage internal, external, and customer audits end-to-end.
  • Track, remediate, and validate 100% of audit findings within agreed SLAs.

Airtable is the no-code app platform that empowers people closest to the work to accelerate their most critical business processes. More than 500,000 organizations rely on Airtable to transform how work gets done and they strive to create a workplace where everyone has an equal opportunity to thrive.

US Unlimited PTO

  • Own and maintain the compliance platform (Drata), including control mapping, evidence collection, continuous monitoring, and audit workflows
  • Manage control documentation, policies, procedures, and supporting artifacts across multiple compliance frameworks
  • Perform risk assessments, vendor security reviews, and control gap analyses, and track remediation through to completion

Payabli is a next-generation Payments Infrastructure and Monetization Platform purpose-built for vertical software companies. They empower software companies to manage and move money through a single infrastructure stack that delivers total control over the payments experience, scaling with PCI DSS 4.0 and SOC 2-compliant security.

US Unlimited PTO

  • Design and test prompts to shape AI behavior and review outputs.
  • Build and maintain the “truth layer” for real-world GRC answers.
  • Evaluate and improve AI quality, ensuring responsible AI use.

Vanta helps businesses earn and prove trust by continuously monitoring and verifying their security. They empower companies to practice better security and prove it with ease, with a kind and talented team that consists of both people with and without prior security experience.

$135,000–$150,000/yr
US Unlimited PTO 12w maternity 4w paternity

  • Lead customer due diligence questionnaire (DDQ) and RFP response process and third-party risk management process.
  • Support enterprise sales with technical customer security discussions.
  • Lead SOC 2 Type II audit preparation, evidence collection, and remediation.

Vanilla is an AI-powered estate advisory platform that aims to modernize estate planning. They are a startup distributed across the U.S. with a mix of fully remote and hybrid roles that embraces flexibility and values curious builders and problem-solvers.

$0–$56,480/yr
UK

  • Supporting the implementation and operation of Monzo’s new GRC system.
  • Acting as the primary point of contact for all things related to the GRC system across Monzo.
  • Identifying opportunities to streamline processes, automate tasks, and improve system usability.

Monzo is on a mission to make money work for everyone, waving goodbye to traditional banking complexities. They offer personal and business accounts and more in the UK, aiming to solve problems and change lives.

US

  • Serve as the primary vCISO and subject matter expert for multiple clients.
  • Lead data-centric cybersecurity programs aligned to business risk.
  • Manage, mentor, and develop vCISO team members.

Coretelligent partners with growing, highly regulated organizations that need secure, dependable IT environments built to scale. They deliver managed IT, cybersecurity, cloud, and strategy, through a model designed for consistency, transparency, and trust. They are building a team of professionals who care deeply about quality, ownership, and continuous improvement.

Canada US Europe

  • Lead current ISO 27001, SOC 2, and PCI compliance initiatives.
  • Spearhead initiatives to identify and improve security risks.
  • Conduct Risk Assessments within customer systems.

Canadian Bank Note Company (CBN) is a leader and trusted provider of secure document and adjacent enterprise-level system solutions across various domains. They seek long-term relationships with their employees and offer a competitive compensation package, including health, medical, life insurance benefits, and a defined contribution pension plan with company matching.

US

  • Play a critical role in the technical development, implementation, and maintenance of the GRC platform.
  • Drive integration strategies between GRC platforms and enterprise systems for automated data sharing and reporting.
  • Provide expert guidance and leadership on GRC technical matters to senior leadership and business stakeholders.

Jobgether is a platform helping candidates find jobs. They use AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements.

US

  • Own and drive the GRC project portfolio, defining project goals and execution plans.
  • Support audit and certification efforts, translating complex technical requirements into clear project plans.
  • Leverage AI tools to automate reporting and enhance visibility, maintaining consistent communication with stakeholders.

Jobgether is a platform that connects job seekers with companies. They use an AI-powered matching process to ensure applications are reviewed quickly and fairly.

Global

  • Lead and mature Material Bank’s enterprise information security program.
  • Own the security risk management framework, including risk identification, scoring, tracking, and executive reporting.
  • Own detection, incident response, and resilience strategy.

Material Bank operates the world’s largest material marketplace for the architecture and design industry, connecting designers with materials from leading brands. They operate in 37 countries and their platform is the standard for design professionals around the globe.

US

  • Collaborate with business leadership, Legal, Procurement, and Cyber to review terms and conditions.
  • Track status of risk remediations in the risk register with business stakeholders.
  • Contribute to overall program enhancements and drive automation with various IT and Cybersecurity stakeholders.

NBCUniversal is a leading media and entertainment company that creates world-class content across film, television, and streaming. They own and operate entertainment and news brands, with a focus on improving communities, championing an inclusive culture, and attracting a talented workforce.