Skip to content

GRC Analyst

The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.

About the job

Responsibilities

  • Support GRC operations, including user access reviews and certifications, security awareness and phishing/deepfake simulations, joiner-mover-leaver tracking, and policy/control exception triage.
  • Perform annual and ad hoc risk assessments, maintain the risk register, coordinate remediation, and track issues to closure.
  • Conduct vendor and subprocessor risk assessments, ongoing monitoring, and remediation tracking for critical third parties.
  • Execute internal audits and support external audit cycles by coordinating evidence, control owners, and remediation.
  • Maintain continuous control monitoring, automated control tests, evidence health, GRC platform administration, and year-round audit readiness.
  • Partner with engineering, IT, operations, legal, sales, and control owners to operationalize controls and prepare for audits.
  • Maintain and update security policies, standards, and procedures.
  • Analyze access review, security awareness, and risk data to produce metrics and leadership insights.
  • Take on additional GRC projects as the program evolves.

Requirements

  • 3–5 years of experience in GRC, IT audit, information security, or a related field.
  • Working knowledge of SOC 2, ISO 27001, ISO 27701, ISO 42001, NIST CSF, HIPAA, GDPR, or CCPA.
  • Experience with GRC platforms such as Anecdotes, Vanta, Drata, Secureframe, OneTrust, or ServiceNow GRC.
  • Experience running user access reviews and understanding IAM concepts including RBAC, least privilege, segregation of duties, and JML processes.
  • Hands-on experience administering security awareness or phishing simulation platforms.
  • Familiarity with AWS, Google Cloud, or Azure and SaaS operations.
  • Strong written communication, organization, attention to detail, and cross-functional collaboration skills.

Compensation

  • Annual salary: $160,000–$170,000.

Skills

SOC 2, ISO 27001, Iso 27701, Iso 42001, Nist Csf, HIPAA, GDPR, Grc Platforms, Identity And Access Management, RBAC, AWS, GCP, Microsoft Azure, Security Awareness

Vannevar

Vannevar

United States

Application Security Engineer
$160k+/yrRemote5+ YOESecurity Engineering

The Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.

Wiz

Wiz

Washington, DC

Cyber Threat Intel Analyst
$160k+/yrOn-site3+ YOESecurity Engineering

The Cyber Threat Intel Analyst tracks, investigates, attributes, and reports on advanced threats targeting cloud, AI, and developer environments. The role requires at least three years of security or threat research experience and strong technical analysis and writing skills.

Figma

Figma

United States

Federal Compliance Manager
$153k+/yrRemote5+ YOESecurity Engineering

Manages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.

Zoox

Zoox

Foster City, CA

Sensing and Perception System Safety Engineer
$170k+/yrHybrid3+ YOESecurity Engineering

Develops safety requirements, analyses, and fail-operational architectures for autonomous-vehicle sensing and perception systems. The role requires 3+ years analyzing safety-critical systems and familiarity with functional-safety standards, sensing hardware, perception, and cross-functional systems engineering.

Greptile

Greptile

San Francisco, CA

Security Engineer
$170k+/yrOn-site3+ YOESecurity Engineering

Own the security posture of a fast-growing developer product across application, infrastructure, cloud, and internal systems. The role requires at least three years of relevant engineering or security experience, strong vulnerability judgment, and hands-on JavaScript or TypeScript expertise.