# Governance, Risk, Compliance & Trust Analyst

**Company:** [Everlaw](https://hotfix.jobs/companies/everlaw)
**Location:** Oakland, CA
**Role:** Other
**Experience:** 5+ years
**Skills:** FedRAMP, SOC 2, ISO 27001, iso 27017, iso 27018, compliance operations, Risk Management, audit readiness, vendor risk assessment, security training, control narratives, evidence management, security questionnaires
**Posted:** 2026-06-30

> Individual contributor role driving compliance, customer trust, vendor reviews, and security training workstreams to support audit readiness (FedRAMP, SOC 2, ISO) and earn stakeholder trust. Requires 5+ years GRC experience, strong knowledge of compliance frameworks, documentation, and cross-functional execution with minimal oversight.

## Job Description

## Compliance
- Support audit readiness across core frameworks such as FedRAMP, SOC 2, and ISO 27001/27017/27018 by organizing evidence, maintaining documentation quality, and partnering with control owners to close gaps.
- Manage compliance operations including evidence requests, policy and procedure updates, control narrative maintenance, and recurring review cycles.
- Partner cross-functionally with Security Engineering, DevOps, IT, Legal, People, Procurement, and other stakeholders to gather inputs, validate implementation details, and produce audit-ready outputs.
- Maintain strong execution against defined compliance SLAs, milestones, and recurring obligations, escalating risks early.
- Translate technical, operational, and regulatory topics into clear written deliverables for internal and external audiences.
- Support internal risk and governance processes, including security impact analyses, change-related compliance reviews, and other structured review workflows.
- Contribute to the operation of the Public Sector Clearance Program, guiding cohorts, maintaining status, tracking issues, and communicating updates.

## Customer Trust
- Manage customer security questionnaires, trust inquiries, and diligence requests with minimal supervision, including researching answers, validating claims, gathering evidence, and producing accurate responses.
- Maintain and improve customer-facing trust content across repositories, trust portals, knowledge resources, and standard response libraries.
- Partner with Security Engineering, DevOps, Legal, GTM, Product, IT, and other stakeholders to collect inputs and ensure responses reflect current implementation.
- Maintain execution against trust-related SLAs including turnaround time and response quality.
- Identify gaps in trust materials and proactively drive updates.
- Support trust enablement initiatives including trust center improvements, evidence library maintenance, and process improvements.
- Use workflow data to identify recurring concerns and recommend changes to content, process, or tooling.

## Vendor Reviews
- Own end-to-end delivery of moderately complex vendor review workstreams including intake, scoping, stakeholder coordination, and completion with limited oversight.
- Conduct security and compliance reviews of third parties by analyzing documentation such as security questionnaires, architecture details, attestations, policies, and contracts.
- Evaluate vendor security posture against requirements for confidentiality, integrity, availability, privacy, access control, incident response, change management, and regulatory obligations.
- Partner with Procurement, Legal, Security Engineering, IT, and business owners to validate use cases and ensure risks are understood.
- Document identified gaps, assumptions, compensating controls, and recommended next steps.
- Maintain execution against vendor review SLAs and recurring obligations, escalating higher-risk issues.

## Security Training
- Own end-to-end delivery of moderately complex security training program workstreams including planning, content coordination, rollout tracking, and continuous improvement with limited oversight.
- Support the design, maintenance, and execution of security and compliance training, with focus on role-based, environment-specific, and regulatory obligations.
- Maintain training content to align with policies, practices, and requirements such as FedRAMP, CJIS, export control.
- Partner with GRCT, Legal, HR, Security, IT, and stakeholders to validate training materials.
- Coordinate recurring training cycles, onboarding assignments, acknowledgements, re-certifications, and evidence collection for audit readiness.
- Track status, identify gaps, and drive follow-through against program deadlines and obligations.

## Requirements
- 5+ years of experience working as an individual contributor with a Governance, Risk, Compliance and Trust team.
- Strong working knowledge of customer trust, compliance operations, risk, and the evidence and control narratives needed to support questionnaires, reviews, and audits.
- Experience supporting FedRAMP, SOC 2, ISO 27001/27017/27018, or similar compliance frameworks.
- Ability to independently drive moderately complex workstreams, navigate ambiguity, communicate clearly with stakeholders, and improve processes.
- High attention to detail, disciplined execution, and commitment to quality, integrity, and cross-functional partnership.

## Similar roles

- [Scientific Strategy, Oncology](https://hotfix.jobs/jobs/281d17d1-7bf7-495c-80ce-103e4b3a8864) - Ataraxis AI - New York, NY - $115k – $255k/yr
- [Compliance Operations](https://hotfix.jobs/jobs/b4bc2ec7-4366-462c-ac49-c81979fcf226) - Poetic - San Francisco, CA - $180k – $225k/yr
- [Process Modeling Engineer](https://hotfix.jobs/jobs/ed442db8-473e-4228-b06e-facf85688905) - Mariana Minerals - San Francisco, CA - $100k – $160k/yr
- [Executive Business Partner](https://hotfix.jobs/jobs/7c002187-7607-46bf-82d7-a2f46e90e4e5) - Lyft - Washington, DC - $66k – $83k/yr
- [AI Operations Manager, Emma](https://hotfix.jobs/jobs/5d9fe3fa-96e8-42e7-a41e-054081aa05cf) - Clutch - Remote

**Apply:** https://hotfix.jobs/jobs/b29f8a8f-1ddc-413d-8870-be4fe5b2b643
**Canonical:** https://hotfix.jobs/jobs/b29f8a8f-1ddc-413d-8870-be4fe5b2b643