Governance, Risk & Compliance Analyst
Governance, Risk & Compliance Analyst responsible for implementing SOC2, ISO 27001, HIPAA and privacy regulations (GDPR/CCPA), building GRC tooling and audit processes, conducting risk assessments, and shaping AI regulatory policies. Requires 6+ years in audit/compliance, experience automating compliance with AI agents, and high-tech cloud-native background.
About the job
What You'll Do
- Implement and lead frameworks such as SOC2, ISO 27001 and HIPAA, ensuring compliance with certification requirements.
- Ensure and maintain compliance with GDPR, CCPA, CPRA and other privacy regulations.
- Design and build scalable audit management processes and documentation systems that will support future expansion to additional compliance frameworks.
- Build internal GRC platform and tooling.
- Conduct risk assessments and mitigate data security and compliance risks.
- Write, update and enact policies capturing security, privacy, and AI safety requirements.
- Follow and help shape the AI regulatory and standards landscape to keep the company at the forefront of industry developments and best practices.
What You'll Bring
- 6+ years of experience leading engagements in audit and compliance.
- Experience translating complex compliance requirements into scalable automation using AI agents and custom built tooling.
- Worked in high tech companies in cloud-native environments.
- Able to translate complex compliance requirements into clear and actionable work-streams.
- Strong commitment to cross-functional collaboration with IT, Security, GTM, and Engineering.
- Self-motivated, detailed and organized, with a diligent approach to project completion.
- Excellent written, verbal, and interpersonal communication skills.
Skills
Soc2, ISO 27001, HIPAA, GDPR, CCPA, Cpra, GRC, Risk Assessment, Audit Management, AI Agents, Compliance Automation, Policy Development, Ai Safety, Cloud Native
Similar jobs
Own external connectivity, backbone capacity planning, and carrier negotiations for multi-GW AI training networks across data center campuses. Requires scaled carrier/long-haul experience, dark fiber procurement, and capacity planning.
Leads the architecture, extensibility, integration, and AI strategy for Databricks’ SAP S/4HANA finance platform. Requires 10+ years in SAP technical roles, architecture or technical leadership experience, and delivery of a full S/4HANA program with BTP extensions.
Leads site-level environmental, health, and safety strategy for a rapidly scaling robotics portfolio, covering risk prevention, compliance, incident management, and contractor safety across complex operations. Requires 15+ years of progressive EHS leadership experience and strong OSHA/Cal-OSHA expertise.
Lead infrastructure sustainability and emerging energy technology strategy for OpenAI's AI data centers. Evaluate and deploy scalable low-carbon solutions balancing reliability, cost, carbon, and regulatory needs; requires 15+ years in energy tech or clean power.
Lead AV Engineer owning multi-site audiovisual standards, infrastructure, event production, and the Zoom-to-Google Meet migration. The role requires 8+ years of AV engineering experience, deep control/audio/video expertise, and strong live-event and vendor leadership.