Source Job

$126,480–$175,000/yr
US

  • Lead the configuration and management of GRC tools to ensure integration with security systems.
  • Manage the main dashboard for SOC 2 reporting, ensuring accuracy and compliance.
  • Develop and maintain a comprehensive risk management program and conduct risk assessments.

ISO 27001 SOC 2 GDPR CCPA

20 jobs similar to New Staff GRC Analyst

Jobs ranked by similarity.

Europe

  • Acting as the primary subject matter expert for all security and compliance inquiries.
  • Taking end-to-end ownership of certification lifecycles, such as ISO 27001 and Cyber Essentials.
  • Working closely with the GRC team to improve existing programs.

Sword Health is shifting healthcare from human-first to AI-first through its AI Care platform, making world-class healthcare available anytime, anywhere. They have over 1,000 enterprise clients and are backed by 42 clinical studies and over 44 patents.

US

  • Play a critical role in the technical development, implementation, and maintenance of the GRC platform.
  • Drive integration strategies between GRC platforms and enterprise systems for automated data sharing and reporting.
  • Provide expert guidance and leadership on GRC technical matters to senior leadership and business stakeholders.

Jobgether is a platform helping candidates find jobs. They use AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements.

US Unlimited PTO

  • Design and test prompts to shape AI behavior and review outputs.
  • Build and maintain the “truth layer” for real-world GRC answers.
  • Evaluate and improve AI quality, ensuring responsible AI use.

Vanta helps businesses earn and prove trust by continuously monitoring and verifying their security. They empower companies to practice better security and prove it with ease, with a kind and talented team that consists of both people with and without prior security experience.

Europe US

  • Collaborate with cross-functional teams to maintain and improve the company's comprehensive compliance program.
  • Manage the end-to-end audit process for SOC 2 compliance, ensuring timely and accurate completion.
  • Oversee the Information Security Risk Management Program, documenting identified risks, coordinating mitigation efforts.

airSlate is a global SaaS technology company that develops no-code workflow automation, electronic signature, and document management solutions. They have teammates in more than 20 countries across three continents and main hubs in the United States, Poland, Romania, Ukraine and Philippines.

5w PTO

  • Own our information security strategy and build our security roadmap.
  • Maintain our ISO 27001 certification, preparing for SOC 2 readiness.
  • Operate strategically and tactically, developing policy and reviewing cloud configurations.

ApprovalMax is redefining how finance teams manage the Money Out cycle — from purchase orders and supplier bills to employee expense management and payroll. Trusted by 18,000+ businesses worldwide, our platform empowers companies to automate financial controls, ensure compliance, and scale efficiently.

US

  • Collaborate with business leadership, Legal, Procurement, and Cyber to review terms and conditions.
  • Track status of risk remediations in the risk register with business stakeholders.
  • Contribute to overall program enhancements and drive automation with various IT and Cybersecurity stakeholders.

NBCUniversal is a leading media and entertainment company that creates world-class content across film, television, and streaming. They own and operate entertainment and news brands, with a focus on improving communities, championing an inclusive culture, and attracting a talented workforce.

$108,890–$184,028/yr
US

  • Own the end-to-end process for client and prospect security questionnaires.
  • Collaborate with internal stakeholders, managing timelines to ensure accurate responses.
  • Develop and maintain a "Trust Center" to proactively address common security questions.

Included Health is a healthcare company that delivers integrated virtual care and navigation. They aim to break down barriers to provide high-quality care for every person, offering care guidance, advocacy, and access to personalized virtual and in-person care.

Europe

  • Maintain and improve security policies and controls across the platform.
  • Perform compliance validation and prepare for audits.
  • Conduct risk assessments on new workloads and track mitigation actions.

Jobgether is a platform that connects job seekers with companies. They use AI to match candidates with roles and ensure fair application reviews.

US

  • Coordinate compliance with standards (PCI, HIPAA, ISO 27002, SOC 1/2/3, FISMA/FedRAMP, etc.) under guidance.
  • Maintain evidence repositories and partner with SMEs to refresh artifacts.
  • Coordinate audits and certification efforts, partnering with support teams on timelines and resourcing.

Experian is a global data and technology company, powering opportunities for people and businesses around the world. As a FTSE 100 Index company listed on the London Stock Exchange (EXPN), they have a team of 22,500 people across 32 countries.

Europe

  • Contribute to the cybersecurity governance framework, aligned with international standards.
  • Perform security audits, gap analyses, and cyber risk assessments.
  • Support Business Continuity Management (BCM) and IT Disaster Recovery (DR) activities.

Prima uses data and tech to rethink motor insurance, offering a great experience at a great price. They are a trusted provider for over 4 million drivers and are expanding in the UK and Spain, with over 300 engineers in the Engineering Department.

North America

  • Own the 24‑month global security roadmap developed with an external partner; drive planning, resource allocation, cross‑region rollout, milestone tracking, and KPI delivery.
  • Lead the cybersecurity transformation: redesign the security operating model, establish regional capability hubs, hire and upskill teams, and integrate security into engineering and product lifecycles.
  • Modernize security tooling and architecture: define global architecture for IAM, cloud security, vulnerability management, SIEM/XDR, DLP, and secure SDLC integrations; manage vendor selection and lifecycle.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. With a combination of industry-leading tools, services, and expertise, Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

$88,900–$101,600/yr
UK 6w PTO

  • Manage information security incidents and security risks across the organisation
  • Own and maintain the Information Security Management System (ISMS), including creating and updating policies, procedures, and guidance
  • Ensure adherence to information security policies and standards

TwinStream was formed in 2019 by engineers solving complex cross-domain problems within government organisations. They provide technical excellence and exceptional service to their clients with teams working both on-site and remotely.

US Unlimited PTO

  • Deliver world-class cyber security assessment and advisory services across multiple Compliance offerings.
  • Work effectively as a team member on large engagements and remain current on technical knowledge.
  • Demonstrate GuidePoint’s Core Values at all times and achieve and maintain relevant cyber security and audit certifications.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. Since its inception in 2011, GuidePoint has grown to over 1000 employees and firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere.

Canada

  • Lead comprehensive security audits of client security operations programs.
  • Analyze security monitoring and alerting to perform a gap analysis.
  • Conduct cyber risk assessments using industry frameworks.

They build cybersecurity software and solutions. Palo Alto Networks challenges the status quo, and they are looking for innovators who are as committed to shaping the future of cybersecurity as they are.

$117,763–$147,204/yr
Canada

  • Lead, mentor, and grow a team of international and domestic risk analysts.
  • Conduct and oversee complex risk assessments across cloud environments and on-premise telecommunications systems.
  • Develop and deliver high-impact, executive-level risk reporting.

At Twilio, they're shaping the future of communications. They deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences, with a strong culture of connection and global inclusion.

Global

  • Perform internal audits and vulnerability testing, ensuring security controls are monitored.
  • Lead security architecture governance for internal IT and projects, using Unified Architecture Framework.
  • Maintain compliance with security requirements and develop roadmaps to address evolving threats.

Jobgether is a platform connecting job seekers with companies. It uses AI-powered matching to ensure applications are reviewed quickly and fairly, identifying top candidates for employers.

US

  • Own vulnerability management, SIEM tuning and monitoring, incident response, and threat investigation.
  • Maintain secure baseline configurations based on industry standards.
  • Oversee AWS security controls and enforce cloud security guardrails.

Jobgether posts this position on behalf of a partner company. They use an AI-powered matching process to ensure applications are reviewed quickly and fairly.

Middle East

  • Define Canonical's security risk management standards and playbooks
  • Analyse and improve Canonical's security risk practices
  • Evaluate, select and implement new security requirements, tools and practices

Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects, they recruit on a global basis and set a very high standard for people joining the company.

CISO

ButterflyMX
US 5w PTO

  • Lead and scale a small, talented security team.
  • Shape our security strategy, implementing practical controls.
  • Partner with Engineering, Product, and Infrastructure leaders.

ButterflyMX empowers people to open and manage doors & gates from a smartphone. As a distributed, primarily remote workforce, they're looking for more intelligent, passionate, collaborative, ai-forward, and down-to-earth individuals to join their growing team.

$0–$56,480/yr
UK

  • Supporting the implementation and operation of Monzo’s new GRC system.
  • Acting as the primary point of contact for all things related to the GRC system across Monzo.
  • Identifying opportunities to streamline processes, automate tasks, and improve system usability.

Monzo is on a mission to make money work for everyone, waving goodbye to traditional banking complexities. They offer personal and business accounts and more in the UK, aiming to solve problems and change lives.