Source Job

$102,500–$102,500/yr
US Unlimited PTO

  • Own GRC workstreams from initial request through evidence collection, testing, and remediation.
  • Test security controls and conduct risk assessments to identify gaps and drive realistic remediation.
  • Support audits, vendor reviews, customer questionnaires, and policy maintenance across teams.

Risk Assessment SOC 2 NIST CSF Vendor Risk Management Policy Development

20 jobs similar to GRC Analyst

Jobs ranked by similarity.

United States Unlimited PTO

  • Own and strengthen the controls environment, ensuring compliance requirements are effectively implemented and maintained.
  • Support and mature the GRC program, including SOC 2 operations and alignment with frameworks such as NIST.
  • Manage vendor risk assessments, regulatory licensing, and security issue lifecycle across jurisdictions.

Mesh enables consumers to pay and be paid with any asset, bridging crypto payments into everyday commerce. Backed by investors like PayPal Ventures and Paradigm, the company is building infrastructure for the global economy with a small, fast-moving team.

US

  • Lead and mature the GRC program across SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, including audit preparation and evidence collection.
  • Own the annual security risk assessment process using NIST SP 800-30 methodology, including stakeholder interviews and risk scoring.
  • Drive security awareness training, AI governance, and Data Loss Prevention program development while collaborating with cross-functional teams.

RainFocus is a rapidly growing software company that provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, growing fast, and building a culture that is challenging, fun, and exciting.

Global 5w PTO

  • Automate governance, risk, and compliance frameworks including ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials.
  • Engineer GRC workflows with internal systems to support compliance by design.
  • Translate compliance requirements into technical specifications for engineering teams and non-technical stakeholders.

Pleo builds spend solutions that make managing money seamless for finance teams and employees. They are a driven, progressive team of 850+ people from over 100 nationalities, committed to delivering the future of business spending.

$150,000–$200,000/yr
US

  • Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
  • Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer-facing discussions and security due diligence reviews.

Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.

$127,200–$205,100/yr
Global Unlimited PTO

  • Own and continuously improve Camunda's Information Security Management System (ISMS), driving measurable improvements.
  • Drive security audit cycles for ISO 27001, SOC 2, and future frameworks with minimal supervision.
  • Review information security requirements in customer contracts and lead responses to complex security questionnaires.

We are the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex business processes. We are a fully remote, global team trusted by over 700 organizations, named a GP Bullhound Next Unicorn and Great Place to Work certified.

US Unlimited PTO

  • Own the security program day-to-day, pursuing ISO 27001 certification and FedRAMP readiness.
  • Manage GRC tool (Vanta), maintain SOC 2 Type II, and run vendor security reviews.
  • Answer customer security questionnaires and ensure compliance documents are accurate.

Massed Compute is building a modern GPU cloud platform for AI and high-performance compute workloads. We are a lean, ambitious team operating in one of the most important technology markets in the world.

US Unlimited PTO 16w maternity 16w paternity

  • Build and own federal compliance frameworks for FedRAMP, NIST, and CMMC.
  • Interpret controls at the mechanics level and author precise technical guidance.
  • Lead Vanta's machine-readable future with OSCAL and FedRAMP 20x.

Vanta helps businesses earn and prove trust by automating security monitoring and compliance. Founded in 2018, the company has a kind and talented team and is used by thousands of companies.

$114,000–$139,000/yr
US

  • Monitor and enforce compliance with security frameworks like NIST CSF, ISO 27001, SOC 2, and regulations such as GLBA, CCPA, and GDPR.
  • Conduct comprehensive risk assessments, develop security policies, and lead internal and external security audits with cross-functional teams.
  • Evaluate third-party vendor security posture, maintain compliance records, and define metrics to assess the success of the security program.

Clear Capital is a national real estate analytics, data solutions and valuation technology company with a simple purpose: to build confidence in real estate decisions to strengthen communities and improve lives. The company values integrity, kindness, and grit, and has been committed to excellence since 2001.

Philippines

  • Drive compliance, risk management, and security assurance as a GRC Specialist.
  • Own third-party risk management and maintain security documentation.
  • Support audits, self-assessments, and customer security inquiries.

Avid provides technology and collaboration tools for creators to entertain, inform, educate, and enlighten the world. The company fosters a culture of passion, customer focus, and innovation, with employees who believe in their mission.

$77,245–$95,200/yr
US

  • Support governance, risk, privacy, and compliance programs to ensure alignment with regulatory requirements.
  • Conduct risk assessments for vendors and new technologies, and maintain compliance with GDPR and other regulations.
  • Manage data governance, privacy evaluations, and cybersecurity awareness training.

RMI is an independent nonprofit transforming global energy systems for a zero-carbon future. Founded in 1982, the organization has a global team and a remote-ready culture.

Germany

  • Drive end-to-end execution of GRC programs, leading audit strategy and cross-functional compliance projects.
  • Manage internal risk workflows, evidence collection, and remediation efforts for audits like SOC 2 and PCI DSS.
  • Translate regulatory requirements into actionable business processes and enable engineering teams to embed security controls.

They are a global leader in event ticketing technology, transforming ticketing for major events like the Grammys and Golden Globes. With over 160 employees and six offices worldwide, they have received over $65 million in funding and are known for their fast-growing, merit-driven culture.

$230,000–$270,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Own and manage federal compliance frameworks including FedRAMP, NIST, CMMC, DFARS, and StateRAMP.
  • Translate regulatory controls into automated tests and machine-readable specifications for continuous authorization.
  • Collaborate with Engineering, Product, and Design to shape product capabilities and influence strategy.

Our partner company is a technology organization focused on federal compliance automation, serving organizations from emerging companies to large enterprises. They operate with a remote-first culture and value autonomy, accuracy, and scalability.

$115,000–$180,000/yr
US

  • Conduct third-party security assessments and evaluate vendor security controls to manage risk.
  • Build and maintain automation using Python and agentic coding tools to replace manual GRC workflows.
  • Partner with cross-functional teams including Procurement, Legal, Engineering, and Compliance on risk-informed decisions.

Affirm is a financial technology company that reinvents credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without hidden fees. It is a remote-first company with a culture focused on innovation and engineering-driven security.

  • Build and lead the Cyber GRC function, including policy, NIST/CIS/ISO frameworks, and regulatory compliance.
  • Manage vendor risk and security assessments across the vendor lifecycle.
  • Drive security awareness, AI governance, and quantified cyber risk reporting.

Mariner is a leading financial services firm providing wealth management and advisory solutions to individuals and institutions. The company fosters a collaborative, innovative culture focused on professional growth, diversity, and work-life balance.

US 3w PTO

  • Lead and advance governance, risk management, compliance, and information security programs to support organizational objectives and regulatory requirements.
  • Manage vulnerability management, third-party risk, security governance, policy development, and AI governance initiatives.
  • Partner with leaders to foster a culture of accountability, risk awareness, and continuous improvement.

Ultimate Medical Academy is a non-profit healthcare educational institution with a national presence, headquartered in Tampa, Florida and founded in 1994. The organization offers online and on-campus programs and fosters a culture of integrity, student success, and team member development.

$73,730–$110,230/yr
Canada

  • Conduct third-party security assessments, reviewing vendor questionnaires and evaluating security controls.
  • Build and maintain automation using Python and agentic coding tools to reduce manual GRC workflows.
  • Partner with Procurement, Legal, Engineering, and other teams on risk reviews and risk-informed decisions.

Affirm is a financial technology company that offers buy now, pay later services. The company values security as critical to its success and has a culture focused on engineering-driven risk management.

$147,050–$220,800/yr
US

  • Lead IT governance and risk management, including executive reporting and risk register maintenance.
  • Develop KPI and KRI dashboards to translate complex data into actionable insights for senior leadership.
  • Oversee ITSM governance, ServiceNow optimization, and vendor risk management.

Our partner is a global organization operating in a sophisticated Governance, Risk & Compliance environment, connecting technology, cybersecurity, privacy, and operational risk. It fosters a collaborative culture with a focus on work-life balance and professional development.

US

  • Support enterprise cybersecurity governance, compliance, and risk management programs.
  • Conduct security control assessments, audit readiness, and policy development.
  • Coordinate with technical teams and executive leadership to drive cybersecurity modernization.

ERP International is a nationally respected provider of health, science, and technology solutions supporting government and commercial clients. The company has been named a Top Workplace by WTOP News for 7 years and offers a culture of employee recognition, community outreach, and professional development.

$139,000–$218,000/yr
US

  • Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
  • Support ISO 27001 and SOC 2 Type 2 audits from readiness through certification, including evidence preparation.
  • Lead the security policy program and collaborate across teams to translate compliance requirements into practical practices.

Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.

Brazil

  • Lead the GRC strategy, shifting from bureaucratic to strategic enabler focused on real business risk.
  • Manage cyber risk quantification, third-party risk, and continuous compliance programs.
  • Oversee information security governance, AI governance, and IAM governance, reporting to the CISO.

Grupo QuintoAndar is the largest real estate ecosystem in Latin America, covering all phases of the housing journey. The company is valued at over USD 5.1 billion, with a culture of innovation, collaboration, and high performance working with top professionals.