Source Job

Global Unlimited PTO

  • Own and mature the compliance framework, including continuous controls monitoring, security awareness, and audit coordination.
  • Automate GRC processes using compliance platforms and AI tooling for evidence collection and risk management.
  • Develop policies, manage third-party risk, and scale customer security assurance end-to-end.

Compliance Risk Management SOC 2 AI Tooling

20 jobs similar to Senior Security GRC Analyst

Jobs ranked by similarity.

US

  • Lead and mature the GRC program across SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, including audit preparation and evidence collection.
  • Own the annual security risk assessment process using NIST SP 800-30 methodology, including stakeholder interviews and risk scoring.
  • Drive security awareness training, AI governance, and Data Loss Prevention program development while collaborating with cross-functional teams.

RainFocus is a rapidly growing software company that provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, growing fast, and building a culture that is challenging, fun, and exciting.

United States Unlimited PTO

  • Own and strengthen the controls environment, ensuring compliance requirements are effectively implemented and maintained.
  • Support and mature the GRC program, including SOC 2 operations and alignment with frameworks such as NIST.
  • Manage vendor risk assessments, regulatory licensing, and security issue lifecycle across jurisdictions.

Mesh enables consumers to pay and be paid with any asset, bridging crypto payments into everyday commerce. Backed by investors like PayPal Ventures and Paradigm, the company is building infrastructure for the global economy with a small, fast-moving team.

Global 5w PTO

  • Automate governance, risk, and compliance frameworks including ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials.
  • Engineer GRC workflows with internal systems to support compliance by design.
  • Translate compliance requirements into technical specifications for engineering teams and non-technical stakeholders.

Pleo builds spend solutions that make managing money seamless for finance teams and employees. They are a driven, progressive team of 850+ people from over 100 nationalities, committed to delivering the future of business spending.

Canada

  • Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
  • Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
  • Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.

Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.

$102,500–$102,500/yr
US Unlimited PTO

  • Own GRC workstreams from initial request through evidence collection, testing, and remediation.
  • Test security controls and conduct risk assessments to identify gaps and drive realistic remediation.
  • Support audits, vendor reviews, customer questionnaires, and policy maintenance across teams.

YipitData is a leading market research and analytics firm for the disruptive economy, providing actionable insights from alternative data. The company has a global presence with offices in the US, APAC, and India, and is recognized as an Inc. Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.

$150,000–$200,000/yr
US

  • Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
  • Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer-facing discussions and security due diligence reviews.

Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.

$115,000–$180,000/yr
US

  • Conduct third-party security assessments and evaluate vendor security controls to manage risk.
  • Build and maintain automation using Python and agentic coding tools to replace manual GRC workflows.
  • Partner with cross-functional teams including Procurement, Legal, Engineering, and Compliance on risk-informed decisions.

Affirm is a financial technology company that reinvents credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without hidden fees. It is a remote-first company with a culture focused on innovation and engineering-driven security.

US Unlimited PTO

  • Own the security program day-to-day, pursuing ISO 27001 certification and FedRAMP readiness.
  • Manage GRC tool (Vanta), maintain SOC 2 Type II, and run vendor security reviews.
  • Answer customer security questionnaires and ensure compliance documents are accurate.

Massed Compute is building a modern GPU cloud platform for AI and high-performance compute workloads. We are a lean, ambitious team operating in one of the most important technology markets in the world.

$114,000–$139,000/yr
US

  • Monitor and enforce compliance with security frameworks like NIST CSF, ISO 27001, SOC 2, and regulations such as GLBA, CCPA, and GDPR.
  • Conduct comprehensive risk assessments, develop security policies, and lead internal and external security audits with cross-functional teams.
  • Evaluate third-party vendor security posture, maintain compliance records, and define metrics to assess the success of the security program.

Clear Capital is a national real estate analytics, data solutions and valuation technology company with a simple purpose: to build confidence in real estate decisions to strengthen communities and improve lives. The company values integrity, kindness, and grit, and has been committed to excellence since 2001.

US Unlimited PTO

  • Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
  • Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
  • Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.

$230,000–$270,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Own and manage federal compliance frameworks including FedRAMP, NIST, CMMC, DFARS, and StateRAMP.
  • Translate regulatory controls into automated tests and machine-readable specifications for continuous authorization.
  • Collaborate with Engineering, Product, and Design to shape product capabilities and influence strategy.

Our partner company is a technology organization focused on federal compliance automation, serving organizations from emerging companies to large enterprises. They operate with a remote-first culture and value autonomy, accuracy, and scalability.

$73,730–$110,230/yr
Canada

  • Conduct third-party security assessments, reviewing vendor questionnaires and evaluating security controls.
  • Build and maintain automation using Python and agentic coding tools to reduce manual GRC workflows.
  • Partner with Procurement, Legal, Engineering, and other teams on risk reviews and risk-informed decisions.

Affirm is a financial technology company that offers buy now, pay later services. The company values security as critical to its success and has a culture focused on engineering-driven risk management.

US

  • Own end-to-end audit evidence collection and validation across multiple compliance frameworks including FedRAMP, ISO 27001, and SOC 2.
  • Maintain and continuously verify technical controls across GCP, GitHub, and Microsoft 365 environments.
  • Serve as the primary liaison between GRC and technical teams to reduce audit burden and ensure continuous audit readiness.

A-LIGN is a leading provider of cybersecurity compliance programs, offering services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. They are the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor, operating in a high-growth, PE-backed environment.

US Unlimited PTO 16w maternity 16w paternity

  • Build and own federal compliance frameworks for FedRAMP, NIST, and CMMC.
  • Interpret controls at the mechanics level and author precise technical guidance.
  • Lead Vanta's machine-readable future with OSCAL and FedRAMP 20x.

Vanta helps businesses earn and prove trust by automating security monitoring and compliance. Founded in 2018, the company has a kind and talented team and is used by thousands of companies.

  • Build and lead the Cyber GRC function, including policy, NIST/CIS/ISO frameworks, and regulatory compliance.
  • Manage vendor risk and security assessments across the vendor lifecycle.
  • Drive security awareness, AI governance, and quantified cyber risk reporting.

Mariner is a leading financial services firm providing wealth management and advisory solutions to individuals and institutions. The company fosters a collaborative, innovative culture focused on professional growth, diversity, and work-life balance.

$114,800–$173,250/yr
US

  • Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, and remediation.
  • Drive recurring continuous monitoring and evidence workflows across multiple teams.
  • Support vulnerability detection and response, including reconciling findings from tools like Wiz, Nessus, and Burp.

Abnormal protects the humans behind the world's most critical organizations from AI-powered cybercrime. 4,500+ enterprises trust their behavioral AI platform.

$139,000–$218,000/yr
US

  • Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
  • Support ISO 27001 and SOC 2 Type 2 audits from readiness through certification, including evidence preparation.
  • Lead the security policy program and collaborate across teams to translate compliance requirements into practical practices.

Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.

Germany

  • Drive end-to-end execution of GRC programs, leading audit strategy and cross-functional compliance projects.
  • Manage internal risk workflows, evidence collection, and remediation efforts for audits like SOC 2 and PCI DSS.
  • Translate regulatory requirements into actionable business processes and enable engineering teams to embed security controls.

They are a global leader in event ticketing technology, transforming ticketing for major events like the Grammys and Golden Globes. With over 160 employees and six offices worldwide, they have received over $65 million in funding and are known for their fast-growing, merit-driven culture.

US Australia 18w maternity 18w paternity

  • Own the full technology and security remit, including enterprise infrastructure, security, identity, applications, and workplace technology.
  • Lead and grow three functions: IT & Security Operations, Cloud Platform Engineering, and GRC.
  • Mature security operations with automation and serve as customer zero for the company's own platform.

UpGuard builds a Cyber Risk Posture Management platform that integrates security ratings, threat intel, and agentic AI to help organizations manage cyber risk. They are a certified Great Place to Work with a lean, high-growth culture and a global remote team.

$175,000–$210,000/yr
Global Unlimited PTO

  • Own the compliance programs and audits end to end, including SOC 2, PCI DSS, GDPR, and ISO 27001.
  • Manage identity and access, device fleet, and vendor security with ownership over control state.
  • Drive compliance as a sales enabler and own the customer-facing security package.

Footprint is the agentic platform that learns compliance programs and runs them end to end for banks and fintechs. The team is small, senior, and ships fast.