Source Job

US

  • Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
  • Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
  • Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.

Information Security GRC Risk Assessment Compliance Audit

20 jobs similar to Sr. Lead Information Security Governance, Risk, and Compliance (GRC) Analyst

Jobs ranked by similarity.

US

  • Develop and maintain the enterprise IT GRC strategy, framework, and roadmap, presenting updates to executive leadership.
  • Lead enterprise IT risk assessments, maintain risk registers, and oversee remediation efforts.
  • Ensure compliance with regulations like NIST, ISO 27001, SOC, PCI-DSS, HIPAA, GDPR, and SOX.

Mission Critical Group is an end-to-end power solutions and services provider that accelerates time-to-power for mission critical environments. With over 1.5 million square feet of U.S. manufacturing capacity, the company supports data centers, healthcare, and industrial facilities where uptime is non-negotiable.

US

  • Monitor security alerts, vulnerabilities, and incidents across enterprise systems and assist in incident response.
  • Maintain compliance with standards such as NIST CSF, ISO 27001, and SOC 2 through audits and policy development.
  • Conduct security risk assessments, evaluate controls, and track remediation plans.

Mission Critical Group is an end-to-end power solutions and services provider that accelerates time-to-power for mission critical environments. With over 1.5 million square feet of U.S. manufacturing capacity, they support data centers, healthcare, and industrial facilities.

$198,238–$233,221/yr
US

  • Own and manage the compliance program including SOC 2 and ISO 27001 readiness and audits.
  • Lead risk assessments, control testing, and enterprise risk management processes.
  • Partner with Engineering, Security, Product, Legal, HR, and Operations to embed compliance into business processes.

Calendly is a scheduling platform used by millions to automate meetings and streamline time management. They are a rapidly growing SaaS company fostering a culture of learning and high performance.

$105,000–$130,000/yr
US

  • Consult onsite and remotely with customers to collect and analyze data related to policies, infrastructure, and compliance requirements.
  • Perform gap analyses of current environments and recommend remediation steps.
  • Assist with sales and marketing activities as a subject matter expert and prepare industry presentations.

CampusGuard provides information security and privacy consulting and compliance services for campus-based organizations. It is a full-service firm leveraging industry standards to deliver world-class security and compliance services.

$115,000–$145,000/yr
Global

  • Serve as a hands-on GRC advisor for customers, guiding them through risk assessments, audit preparation, and control rollouts.
  • Help customers navigate audits like SOC 2, ISO 27001, HIPAA, PCI-DSS, and NIST, translating requirements into practical steps.
  • Spot GRC complexity early and partner with Support and Customer Success to own escalations requiring real GRC expertise.

Compyl is a GRC and automated security compliance platform built by security practitioners. Backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures, it is a high-growth Series A company.

$70,000–$77,000/yr
US

  • Perform enterprise risk assessments using NIST CSF, SOC 2, and CIS frameworks.
  • Develop and execute security awareness programs including training and phishing simulations.
  • Support governance and control management by maintaining policies and control libraries.

Protective helps protect customers against life's uncertainties by providing insurance and peace of mind. The company offers a collaborative environment with a focus on employee wellbeing and work-life balance.

$120,000–$140,000/yr
US

  • Conduct IT and cybersecurity risk assessments across systems, applications, and business processes.
  • Lead audit readiness activities for frameworks like SOC 2, HIPAA, and NYDFS.
  • Manage security policies, third-party vendor assessments, and develop risk dashboards.

Jobgether uses an AI-powered matching process to connect candidates with hiring companies. They focus on efficient, objective application review and are a remote-first organization.

$150,000–$170,000/yr
US Unlimited PTO

  • Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, and third-party risk.
  • Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, and more.
  • Manage third-party and supply chain risk management, including vendor security reviews, due diligence, and remediation tracking.

Accela provides government software solutions to improve efficiency, increase citizen engagement, and enable thriving communities. They have been an industry leader for nearly 20 years and are committed to diversity, equity, and inclusion.

US Unlimited PTO

  • Manage and implement complex controls frameworks for large systems consisting of Cloud infrastructure and SaaS services.
  • Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
  • Conduct risk assessments across business units and processes, identifying risk findings and recommending remediation strategies.

Virtru is a data protection platform that enables secure sharing without sacrificing security or privacy. Backed by top venture capital firms, the company helps Fortune 500 companies and government agencies achieve true data security with freedom to share.

$132,000–$165,000/yr
US Unlimited PTO

  • Manage and support compliance certifications including SOC 2, HITRUST, and ISO 27001 audits across the audit lifecycle.
  • Serve as the subject matter expert across the company on compliance frameworks and primary point of contact for external auditors.
  • Maintain the risk register, drive risk identification and reporting, and scale GRC function with AI and automation.

Garner transforms the healthcare economy by partnering with employers to redesign healthcare benefits using data-driven insights. It is a fast-growing healthcare technology company with a mission-driven team focused on making healthcare more affordable and high-quality.

US 24w maternity 24w paternity

  • Own the end-to-end GRC strategy and roadmap, driving compliance maturity and reducing audit risk.
  • Design and implement policy-as-code systems, translating compliance frameworks into enforceable code.
  • Lead full audit cycles, manage evidence collection, and architect GRC platform strategy for continuous compliance.

Smartsheet empowers teams to manage work and scale solutions, now uniting human teams with AI agents to automate tasks and uncover insights. With a history of over 20 years, the company fosters a culture of inclusion, creativity, and big thinking, offering professional growth and a supportive environment.

$110,100–$143,100/yr
North America

  • Defines program goals, governance frameworks, and measurable objectives for cyber risk and compliance programs.
  • Manages user attestations, third-party risk, cyber contract negotiation, and coordination of IT audits/assessments.
  • Implements GRC tooling and monitors program effectiveness through KPIs, QA reviews, and control testing.

Velera is a credit union service organization providing fintech solutions to over 4,000 financial institutions. The company fosters a remote-first, inclusive culture with a focus on employee wellbeing and belonging.

United States Unlimited PTO

  • Partner with the CISO to drive security strategy, roadmap, and execution across application security, GRC, and operations.
  • Support compliance initiatives including PCI, SOC 2, ISO 27001, DORA, and FedRAMP readiness.
  • Serve as a trusted security leader in customer-facing settings, translating technical risks into business language.

Sardine is the leading agentic risk platform for fighting financial crime, integrating data across risk teams to stop fraud and automate AML operations. With over 6 billion profiled devices and 800 million consumers, we maintain a remote-first culture that values performance over hours worked.

$51,840–$64,800/yr
Europe

  • Support the ISO 27001 program by maintaining audit readiness, running evidence collection, and managing access reviews.
  • Perform recurring security operations including vulnerability scanning, risk assessments, and vendor reviews.
  • Collaborate cross-functionally to harden identity and access management, respond to security questionnaires, and support AI governance initiatives.

Didomi is a consent management platform that helps companies manage user consent and data privacy. The company is a growing SaaS organization with a collaborative culture, emphasizing automation and efficiency.

US

  • Maintain Risk Management Framework artifacts for DevSecOps pipeline inheritance of NIST SP 800-53 controls.
  • Complete and validate STIG/SRG checklists quarterly and provide monthly application STIG status reports.
  • Evaluate program risks, document mitigation strategies, and recommend courses of action to ensure continuous ATO compliance.

DecisionPoint is a company providing cloud services and DevSecOps solutions, supporting ARTRANS AWS environments. It is a regular full-time employer fostering a culture of security and compliance, with an active Secret clearance required for this role.

India

  • Manage internal audits and support external compliance assessments across business functions.
  • Perform gap analyses and track remediation actions for compliance frameworks.
  • Maintain and improve compliance documentation, policies, and risk registers.

Our partner is a growing SaaS organization serving global industries. It fosters a collaborative and inclusive culture with a focus on employee development and well-being.

US

  • Lead ISSO activities to ensure confidentiality, integrity, availability, and compliance of enterprise applications and information systems.
  • Manage RMF processes including ATO packages, continuous monitoring, risk assessments, and accreditation documentation within eMASS.
  • Implement and maintain compliance with DISA STIGs, NIST 800-53 controls, and federal cybersecurity requirements.

Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. The company facilitates the hiring process by sharing top-fitting candidate shortlists with partner companies, focusing on efficiency and objectivity.

$210,000–$350,000/yr
US

  • Partner with Sales, Customer Success, and Marketing on strategic enterprise opportunities, bringing security and GRC expertise into customer conversations.
  • Lead executive briefings and CISO-to-CISO conversations to build trust and confidence in Drata's platform.
  • Represent Drata at industry conferences, CISO dinners, and roundtables across the Americas, EMEA, and APAC, building relationships and credibility.

Drata helps companies earn and keep trust by providing a proof layer that shows they deserve it. The company has over 600 employees worldwide and fosters a culture built on trust, speed, and continuous growth.

$130,000–$145,000/yr
US Unlimited PTO 20w maternity 12w paternity

  • Support and scale the Assurance & Compliance function through an engineering-driven, automation-first approach.
  • Partner with Engineering, Security, Legal, and other teams to support compliance programs and audit readiness.
  • Help transform compliance into a continuous, measurable capability embedded into operations.

Flock builds technology that reduces crime and protects privacy, partnering with cities, businesses, schools, and neighborhoods. With over $1B in funding and an $8.3B valuation, the company is a high-performance team united by urgency, ownership, and a shared commitment to meaningful impact.

Global

  • Own RMF authorizations across Department of War components and FedRAMP High, alongside CMMC 2.0 and SOC 2 compliance for corporate systems.
  • Maintain authorization and audit evidence, including SSPs, SARs, POA&Ms, STIGs, and control mappings.
  • Partner with Engineering, Product, and Security to embed compliance requirements into system design and CI/CD workflows.

Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. Founded in 2019, valued at over $2 billion, they are a distributed team of builders from military, operational, and technology backgrounds.