Skip to content
EverlawEverlaw

Governance, Risk, Compliance & Trust Analyst

Individual contributor role driving compliance, customer trust, vendor reviews, and security training workstreams to support audit readiness (FedRAMP, SOC 2, ISO) and earn stakeholder trust. Requires 5+ years GRC experience, strong knowledge of compliance frameworks, documentation, and cross-functional execution with minimal oversight.

About the job

Compliance

  • Support audit readiness across core frameworks such as FedRAMP, SOC 2, and ISO 27001/27017/27018 by organizing evidence, maintaining documentation quality, and partnering with control owners to close gaps.
  • Manage compliance operations including evidence requests, policy and procedure updates, control narrative maintenance, and recurring review cycles.
  • Partner cross-functionally with Security Engineering, DevOps, IT, Legal, People, Procurement, and other stakeholders to gather inputs, validate implementation details, and produce audit-ready outputs.
  • Maintain strong execution against defined compliance SLAs, milestones, and recurring obligations, escalating risks early.
  • Translate technical, operational, and regulatory topics into clear written deliverables for internal and external audiences.
  • Support internal risk and governance processes, including security impact analyses, change-related compliance reviews, and other structured review workflows.
  • Contribute to the operation of the Public Sector Clearance Program, guiding cohorts, maintaining status, tracking issues, and communicating updates.

Customer Trust

  • Manage customer security questionnaires, trust inquiries, and diligence requests with minimal supervision, including researching answers, validating claims, gathering evidence, and producing accurate responses.
  • Maintain and improve customer-facing trust content across repositories, trust portals, knowledge resources, and standard response libraries.
  • Partner with Security Engineering, DevOps, Legal, GTM, Product, IT, and other stakeholders to collect inputs and ensure responses reflect current implementation.
  • Maintain execution against trust-related SLAs including turnaround time and response quality.
  • Identify gaps in trust materials and proactively drive updates.
  • Support trust enablement initiatives including trust center improvements, evidence library maintenance, and process improvements.
  • Use workflow data to identify recurring concerns and recommend changes to content, process, or tooling.

Vendor Reviews

  • Own end-to-end delivery of moderately complex vendor review workstreams including intake, scoping, stakeholder coordination, and completion with limited oversight.
  • Conduct security and compliance reviews of third parties by analyzing documentation such as security questionnaires, architecture details, attestations, policies, and contracts.
  • Evaluate vendor security posture against requirements for confidentiality, integrity, availability, privacy, access control, incident response, change management, and regulatory obligations.
  • Partner with Procurement, Legal, Security Engineering, IT, and business owners to validate use cases and ensure risks are understood.
  • Document identified gaps, assumptions, compensating controls, and recommended next steps.
  • Maintain execution against vendor review SLAs and recurring obligations, escalating higher-risk issues.

Security Training

  • Own end-to-end delivery of moderately complex security training program workstreams including planning, content coordination, rollout tracking, and continuous improvement with limited oversight.
  • Support the design, maintenance, and execution of security and compliance training, with focus on role-based, environment-specific, and regulatory obligations.
  • Maintain training content to align with policies, practices, and requirements such as FedRAMP, CJIS, export control.
  • Partner with GRCT, Legal, HR, Security, IT, and stakeholders to validate training materials.
  • Coordinate recurring training cycles, onboarding assignments, acknowledgements, re-certifications, and evidence collection for audit readiness.
  • Track status, identify gaps, and drive follow-through against program deadlines and obligations.

Requirements

  • 5+ years of experience working as an individual contributor with a Governance, Risk, Compliance and Trust team.
  • Strong working knowledge of customer trust, compliance operations, risk, and the evidence and control narratives needed to support questionnaires, reviews, and audits.
  • Experience supporting FedRAMP, SOC 2, ISO 27001/27017/27018, or similar compliance frameworks.
  • Ability to independently drive moderately complex workstreams, navigate ambiguity, communicate clearly with stakeholders, and improve processes.
  • High attention to detail, disciplined execution, and commitment to quality, integrity, and cross-functional partnership.

Skills

FedRAMP, SOC 2, ISO 27001, Iso 27017, Iso 27018, Compliance Operations, Risk Management, Audit Readiness, Vendor Risk Assessment, Security Training, Control Narratives, Evidence Management, Security Questionnaires

Similar jobs

Ascertain

Ascertain

United States

Prior Authorization Assistant, Cardiology
$45k+/yrRemote4+ YOEOther

Processes and oversees cardiology prior authorizations, coordinates documentation with healthcare providers and payors, and helps improve AI-powered healthcare workflows. Requires 4+ years of cardiology prior authorization and billing experience plus athenahealth or NextGen proficiency.

OpenAI

OpenAI

San Francisco, CA

Child Safety Enforcement Specialist
$158k+/yrHybridOther

Leads child safety investigations, enforcement decisions, mandatory-reporting workflows, and process improvements involving sensitive content and abuse signals. The role requires Trust & Safety investigation experience, sound judgment, strong documentation, and cross-functional collaboration.

Gusto

Gusto

San Francisco, CA
Workday Developer
$128k+/yrHybrid5+ YOEOther

Lead configuration, optimization, reporting, and support for Workday HCM, Payroll, and related modules to power HR and payroll processes at Gusto. Requires 5-7 years of hands-on Workday experience, advanced knowledge of security, business processes, and reporting, plus a bachelor's degree.

Applied Intuition

Applied Intuition

Sunnyvale, CA

Mapping Specialist
$85k+/yrOn-site3+ YOEOther

Creates and maintains centimeter-precise HD maps for Level 4 autonomous vehicles using lidar, imagery, and 3D geospatial data. The role requires 3+ years of mapping experience, a bachelor’s degree, and familiarity with autonomous-vehicle mapping standards and tools.

Axle

Axle

Baltimore, MD

Scientist
$115k+/yrOn-siteOther

The Scientist performs molecular biology, biochemistry, chromatin, cell culture, and CRISPR/Cas9 genome-editing research involving cell lines and mice. The role requires a master’s degree, scientific biology experience, strong analytical skills, and laboratory documentation and presentation capabilities.