GRC Analyst
GRC Analyst responsible for maintaining compliance with security and privacy frameworks (ISO 27001, SOC 2, HIPAA, PCI), managing audits, internal controls, remediation, and supporting customer security inquiries in a fast-paced cloud environment. Requires 3+ years audit experience and strong project management skills.
About the job
Responsibilities
- Collaborate with internal teams to maintain an effective suite of internal controls and drive remediation efforts to completion with clear documentation of progress.
- Build strong working relationships across the business so compliance accountability is shared and stakeholders are informed.
- Streamline annual audits by managing audit deliverables, developing treatment plans, and coordinating across teams to document and track completion to ensure audit success.
- Monitor and improve controls, processes, and evidence management practices; identify opportunities to automate and streamline GRC operations; contribute to controls maturity scoring and reporting.
- Enable go-to-market teams and accelerate deal cycles by supporting security questionnaires, addressing compliance inquiries, and maintaining clear, customer-facing documentation on Vercel’s security and compliance posture.
- Design and manage company training and enhance visibility on compliance-specific topics for internal stakeholders to ensure an understanding of compliance, ethics, and regulatory requirements.
Requirements
- At least 3 years of relevant experience in supporting the audit lifecycle in a cloud-centric environment (SOC 2, ISO 27001, PCI, HIPAA, etc.).
- Strong organizational skills to be flexible and proactive in a high-growth, start-up environment.
- Experience collaborating closely with internal partners to seamlessly incorporate policies and technical controls into the SDLC.
- Strong project management skills and sense of ownership with the ability to communicate and collaborate effectively, and execute projects across various business units and levels.
Nice-to-Haves
- Strong experience with cloud infrastructure (e.g., Azure, AWS).
- Familiarity with compliance or software development tools and systems (e.g., Drata, Linear, Datadog, etc.).
- Experience with frontend development and open source components.
- Relevant industry certifications (i.e., CISM, CISSP, CCEP).
Skills
SOC 2, ISO 27001, HIPAA, Pci Dss, Audit Lifecycle, Internal Controls, GRC, Cloud Infrastructure, AWS, Azure, Drata, Linear, Datadog, SDLC, Project Management
Similar jobs
Supply Chain Buyer responsible for executing purchases, managing order books, resolving vendor issues, and maintaining ERP data accuracy to support rapid data center buildout for AI compute infrastructure. Requires experience as a buyer in fast-moving supply chains, heavy PO management, expediting, and strong ERP hygiene.
Lead configuration, optimization, reporting, and support for Workday HCM, Payroll, and related modules to power HR and payroll processes at Gusto. Requires 5-7 years of hands-on Workday experience, advanced knowledge of security, business processes, and reporting, plus a bachelor's degree.
The Scientist performs molecular biology, biochemistry, chromatin, cell culture, and CRISPR/Cas9 genome-editing research involving cell lines and mice. The role requires a master’s degree, scientific biology experience, strong analytical skills, and laboratory documentation and presentation capabilities.
Own and maintain Primavera P6 CPM schedules, cost tracking, and productivity reporting for greenfield hyperscale data center construction projects. Drive critical path compression, lead reviews with GCs/executives, and deliver defensible as-built records on $500M+ programs.
Conduct HIV, cellular, and molecular biology research supporting NIH laboratory programs, including CRISPR/Cas9 gene editing, cell culture, assay development, data interpretation, and statistical analysis. Requires a master's degree and at least five years of laboratory experience.