# GRC Analyst II

**Company:** [Metropolis](https://hotfix.jobs/companies/metropolis)
**Location:** Los Angeles, CA
**Role:** Security Engineering
**Salary:** $100k – $135k/yr
**Experience:** 3+ years
**Skills:** GRC, SOC 2, pci-dss, Cybersecurity, Risk Assessment, security policies, security awareness training, ai governance, cisa, crisc
**Posted:** 2026-07-29

> GRC Analyst responsible for authoring security policies, managing company-wide security awareness training programs, establishing AI governance frameworks, conducting risk assessments on AI tools and models, and ensuring compliance with frameworks like SOC 2 and PCI-DSS. Requires 3+ years in information security GRC or compliance plus a Bachelor's degree.

## Job Description

## What you'll do
- Author, update, and enforce corporate security policies to guarantee cross-departmental compliance
- Deploy and manage required information security training campaigns as the platform owner
- Transform static policies into interactive modules with comprehension quizzes for mandatory sign-offs
- Establish and enforce an internal AI governance framework with Data, Legal, and Tech teams
- Conduct structured risk assessments on emerging tools and internal AI models to maintain behavioral guardrails
- Report training metrics, policy exceptions, and risk postures directly to senior management
- Review vendor security profiles and software pipelines to mitigate security risk

## What we're looking for
- 3+ years of experience in information security GRC, cybersecurity training, or technology compliance
- Proven track record of managing required security awareness programs and driving cross-functional accountability
- Experience with modern training orchestration platforms and understanding of AI and machine learning data security
- Working knowledge of standard industry frameworks, specifically SOC 2 and PCI-DSS
- Communication skills with the ability to explain complex regulatory needs to non-technical employees
- Bachelor’s degree in Cybersecurity, Information Systems, or an equivalent technical discipline

## Nice-to-haves
- GRC certifications such as CISA or CRISC

## Compensation
- Anticipated base salary: $100,000 - $135,000 USD annually
- Total compensation package may also include healthcare benefits, 401(k) plan, disability coverage, life insurance, stock options, bonus plans and more.

## Similar roles

- [Application Security Engineer](https://hotfix.jobs/jobs/d240253e-6098-4419-8f04-aaf793f42c03) - Zocdoc - Remote - $100k – $140k/yr
- [Security Engineer, Application Security](https://hotfix.jobs/jobs/18d79ceb-6c9b-4ecf-819a-fcd37324835f) - Trail of Bits - Remote - $100k – $200k/yr
- [Compliance Analyst](https://hotfix.jobs/jobs/b1657e99-edcc-41eb-b820-8b3e05df4e67) - Harvey - San Francisco, CA - $99k – $149k/yr
- [Security Engineer](https://hotfix.jobs/jobs/0300fefe-8e6f-405b-ae59-0d7e2c0145cf) - Chainguard - Remote - $105k – $123k/yr
- [Product Security Engineer, Server](https://hotfix.jobs/jobs/94042e5e-7f7d-4afd-817e-a25955521f49) - MongoDB - Remote - $106k – $209k/yr

**Apply:** https://hotfix.jobs/jobs/1f0167c1-8545-42d4-a889-8117246be343
**Canonical:** https://hotfix.jobs/jobs/1f0167c1-8545-42d4-a889-8117246be343