Technical GRC Analyst
The Technical GRC Analyst evaluates technical controls, validates evidence, performs risk assessments, and advances AI governance, compliance automation, and assurance reporting. The role requires 8+ years in technical security, Security GRC, or regulatory compliance, with cloud and enterprise technology experience.
About the job
Responsibilities
- Evaluate the design and operating effectiveness of technical controls.
- Review and validate evidence to determine whether controls are implemented, effective, and appropriately documented.
- Perform technical risk assessments for technologies, systems, and business initiatives.
- Partner with Engineering and Security to align technical controls with compliance requirements and industry best practices.
- Support and improve the AI governance program, including policies, acceptable-use standards, risk assessments, vendor evaluations, and ISO 42001-aligned security controls.
- Develop compliance intelligence, metrics, dashboards, and analytics to support business decisions and program maturity.
- Identify opportunities to automate compliance activities and improve operational efficiency.
- Support internal assessments, customer due diligence, and external audits.
Requirements
- 8+ years of experience in technical security, Security GRC, regulatory compliance, or a related discipline.
- Experience evaluating technical controls and validating supporting evidence.
- Experience performing technical risk assessments and working cross-functionally.
- Experience in technology organizations with modern cloud and enterprise environments.
- Working knowledge of cloud and security architecture, vulnerability and risk management, secure software development and DevSecOps, data protection and encryption, AI governance, dashboard development, reporting, analytics, or automation.
Nice-to-haves
- Experience with FedRAMP authorization activities, including NIST 800-53 control implementation, SSP development, evidence collection, POA&M management, or readiness assessments.
Compensation
- Salary range: 50,000–60,000 (currency not specified).
Skills
Security Grc, Technical Controls, Risk Assessments, Cloud Security, Security Architecture, Vulnerability Management, DevSecOps, Data Protection, Encryption, Ai Governance, Iso 42001, FedRAMP, Nist 800-53, Dashboard Development, Compliance Automation
Similar jobs
Security Engineering jobsSenior Product Security Engineer who partners with developers to secure web applications and APIs throughout the SDLC. The role leads threat modeling, security reviews, penetration testing, secure code review, and security-tooling programs.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Build and automate technical security controls, compliance workflows, and audit evidence for enterprise readiness. The role requires strong scripting or programming skills, security fundamentals, and the ability to collaborate across engineering, security, legal, and customer-facing teams.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.