Source Job

20 jobs similar to Information Security - GRC Analyst

Jobs ranked by similarity.

North America

  • Support CapIntel’s Governance, Risk, and Compliance program
  • Manage third-party risk and customer security reviews
  • Support operational security, privacy, and security awareness initiatives

CapIntel is a software platform built for wealth management enterprises to help financial advisors explain complex investment strategies to their clients. Since launching in 2019, CapIntel has seen rapid adoption and industry recognition, earning top placements in Deloitte’s Technology Fast 50 Canada and Fast 500 North America in 2025, ranking us among the fastest -growing technology companies.

US

  • Support the development, implementation, and maintenance of IT compliance policies, standards, procedures, and controls.
  • Coordinate and support internal and external audits, including preparation of documentation, evidence collection, and remediation tracking.
  • Perform periodic compliance assessments, gap analyses, and risk assessments against applicable frameworks and standards.

Xcelerate Solutions, founded in 2009 and located in McLean, VA, is a fast-growing company. The company is defined by a diversified workforce of dynamic and versatile professionals, with growth and development opportunities that contribute to individual and firm growth.

Global

  • Lead end-to-end audit execution across SOC 2, ISO 27001, ISO 42001, ISO 27701, HIPAA, and GDPR and maintain year-round audit readiness.
  • Build and mature Atlan's risk management program and turn abstract risk conversations into measurable metrics with clear ownership and quarterly leadership reviews.
  • Integrate our GRC platform with cloud infrastructure, CI/CD pipelines, HR systems, and product engineering tooling to automate evidence collection and continuous control testing.

Atlan is building the missing context layer for data and AI, helping enterprises close the AI value chasm and finally move AI pilots into production. We are backed by world-class investors including GIC, Insight Partners, Meritech, Peak XV, and Salesforce Ventures and trusted by global enterprises like Mastercard, Workday, General Motors, Unilever and others.

$72,781–$83,698/yr
Canada

  • Perform GRC functions and maintain the Cyber Security Risk register.
  • Execute third party risk processes for cyber and perform/execute on awareness programs and phishing processes.
  • Liaise with the vendor management (VM) team to conduct security assessments of existing and prospective vendors.

Warner Music Group is a global collective of music makers and music lovers, tech innovators and inspired entrepreneurs, game-changing creatives and passionate team members. They turn dreams into stardom and audiences into fans. WMG is committed to creating a work environment that actively values, appreciates, and respects everyone and encourages applications from people with a wide variety of backgrounds and experiences.

US 5w PTO

  • Seek out opportunities to evangelize AuditBoard’s value to partners.
  • Lead compelling demonstrations and training of AuditBoard’s IT Risk and Compliance (ITRC) solutions to AuditBoard’s strategic partners tailored to a partners GTM approach.
  • Maintain accurate mapping of partners’ field teams, penetration rates across our practice lines, and identify opportunities to increase our footprint.

AuditBoard is the leading audit, risk, ESG, and InfoSec platform on the market, surpassing $300M ARR and continuing to grow. More than 50% of the Fortune 500 leverage their award-winning technology to move their businesses forward with greater clarity and agility. They are one of the 500 fastest-growing tech companies in North America.

$125,000–$140,000/yr
US

  • Collaborate with the engineering departments to implement security controls from approved security frameworks and drive best IT practices.
  • Interface with internal partner teams to help drive best practices and compliance.
  • Evaluate and perform Risk Assessments of new software solutions with internal partners.

Judi Health is an enterprise health technology company providing a comprehensive suite of solutions for employers and health plans. They consolidate all claim administration-related workflows in one scalable, secure platform and are working with clients, rebuilding trust in healthcare in the U.S.

Europe

  • Implement security policies and standards into the company environment.
  • Develop and improve security concepts, policies, processes and awareness.
  • Act as main admin for respective Security Management systems and applications.

Deutsche Telekom IT Solutions Slovakia is a company providing innovative information and communication technology services. They are the second largest employer in the eastern part of Slovakia with more than 3900 employees and aim to proactively improve and transform.

4w paternity

  • Oversee third-party and internal risk assessments to support enterprise information security and governance, risk, and compliance (GRC) initiatives.
  • Manage vendor due diligence, maintains an accurate risk register, partners with internal stakeholders on mitigation strategies.
  • Drive continuous improvement of the risk and compliance framework.

Concorde Career Colleges is committed to a policy of Equal Employment Opportunity and will not discriminate against an applicant or employee based on race, color, religion, religious creed, national origin, ancestry, sex, age, veteran or military status, or any other legally protected characteristic. Concorde Career Colleges offer short career-focused programs preparing students for the healthcare industry.

$175,000–$195,000/yr
US

  • Own and evolve the GRC program in partnership with Legal and our CCO.
  • Develop, maintain, and enforce clear, practical security policies across all departments.
  • Develop and execute a comprehensive information security roadmap aligned with business objectives.

Allocate is a fintech company handling sensitive investor data and financial transactions. They are a rapidly growing organization that values client service, relentless problem-solving, and continuous improvement.

US Canada India Europe

  • Vendor and contractor risk assessment process during onboarding, adhering to a defined Service Level Agreement (SLA).
  • Conduct annual vendor monitoring and re-assessment processes for existing vendors.
  • Maintain the vendor inventory and collaborate with vendors on an ongoing basis to reduce identified risks.

Juniper Square's mission is to unlock the full potential of private markets by digitizing them and bringing efficiency, transparency, and access. They have a values-driven organization that offers employees a variety of ways to work, ranging from a fully remote experience to working full-time in one of their physical offices.

US

  • Support ongoing FedRAMP authorization including SSP, POA&M, evidence, and 3PAO coordination.
  • Manage and oversee NIST SP 800-53 compliance.
  • Oversee continuous monitoring, vulnerabilities, incidents.

IFS is a billion-dollar revenue company with 7000+ employees on all continents. Their leading AI technology is the backbone of their award-winning enterprise software solutions, enabling customers to be their best when it really matters–at the Moment of Service™.

Europe

  • Manage and improve the Information Security Management System.
  • Maintain compliance with key frameworks and certifications.
  • Translate regulatory requirements into technical controls.

Jobgether uses an AI-powered matching process to ensure applications are reviewed quickly, objectively, and fairly against the role's core requirements. Their system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company.

US

  • Lead the end-to-end Certification & Authorization (C&A) process for information systems.
  • Maintain and update System Security Plans (SSPs), POA&Ms, and other FedRAMP/GovRAMP/NIST documentation artifacts.
  • Oversee control gap analysis and drive remediation efforts across technical and administrative domains.

EBSCO Information Services (EBSCO) delivers a fully optimized research experience, seamlessly integrated with a powerful discovery platform to support the information needs of our end-users. Headquartered in Ipswich, MA, EBSCO employs more than 2,700 people worldwide, with most embracing hybrid or remote work models.

US

  • Conduct structured interviews with partner organizations, operational teams, and technical stakeholders.
  • Documents end‑to‑end operational workflows and surface implicit, non‑documented practices.
  • Identify workflow fragility zones, handoff risks, and transition‑period vulnerabilities.

Element serves as a partner at the intersection of innovation and our clients' needs, efficiently crafting meaningful user experiences for government and commercial customers. Our talented professionals bring unparalleled energy engagement, setting a higher standard for impactful work.

Global

  • Lead audit readiness and execution for SOC 2, ISO 27001, PCI DSS, and other compliance frameworks relevant to our customer base
  • Manage the compliance lifecycle in a compliance platfom (such as Vanta, Drata etc) including evidence collection, control mapping, and continuous monitoring
  • Coordinate cross-functional audit activities with engineering, product, security, infrastructure, and support teams to gather evidence and remediate findings

Supabase is a born-remote and open-source-first company that provides tools developers love. They have 180+ team members across 40+ countries, and deeply believe in the open-source ecosystem and strive to support existing tools and communities.

Europe

  • You will be responsible for company-wide IT security and its processes.
  • Evaluate and plan preventive measures to minimize security risks.
  • Create, maintain, and develop concepts, processes, and guidelines to strengthen our IT security.

TIMOCOM is an innovation driver that transforms and moves the logistics industry with pioneering and digital solutions. They connect over 55,000 customers in one of Europe's largest, dynamic logistics networks, helping them solve their logistical challenges in a smart, safe, and simple way.

US 2w PTO

  • Manage certification frameworks, including CMMC, NIST, and SOC 2.
  • Develop, track, and maintain security and compliance policy documents.
  • Analyze and review system configurations for security vulnerabilities.

Rubris Inc. provides transformational legal technology and solutions for complex business and legal processes in the mass tort industry. They streamline and automate processes to improve efficiency while delivering unprecedented insights and analytics.

Global

  • Support Business Continuity, Crisis Management, and Disaster Recovery processes.
  • Conduct Business Impact Analysis, including information gathering, impact assessment, and documentation of results.
  • Work closely with technical teams to plan, coordinate, and monitor disaster recovery tests, including existing tests and the development of new scenarios.

Pismo, founded in 2016, provides a comprehensive processing platform for banking, card issuing, and financial market infrastructure, helping customers innovate and build next-gen banking and payment solutions. With over 500 employees across 10 countries, Pismo joined Visa in 2024, leveraging Visa’s solutions.

$220,000–$240,000/yr

  • Manage and develop staff members under Product Compliance.
  • Oversee and contribute to the vulnerability management lifecycle.
  • Assess and serve as a subject matter expert for regulatory and compliance requirements.

ExtraHop is a company that focuses on network detection and response (NDR) to help organizations stay ahead of emerging threats. They integrate network threat detection, network performance management, intrusion detection, and packet forensics into a single console.

US Unlimited PTO

  • Manage SOC 2 Type II audits, serving as the primary point of contact for auditors and collaborators.
  • Coordinate HIPAA compliance assessments, including risk analyses, policy reviews, and Business Associate Agreement (BAA) management.
  • Conduct structured gap analyses against applicable frameworks to identify control deficiencies and develop prioritized remediation roadmaps.

Rad AI is transforming healthcare with AI-driven solutions, revolutionizing radiology to save time, reduce burnout, and improve patient care. They have secured over $140M in funding and recognized as a fast-growing company, fostering transparency, inclusion, and close collaboration.