Senior GRC Analyst
The Senior GRC Analyst will manage security governance, risk, and compliance programs, including SOC 2 controls, risk assessments, vendor reviews, audits, and data governance. The role requires 8+ years of GRC experience, a bachelor’s degree, and familiarity with compliance platforms and SaaS environments.
About the job
Responsibilities
- Develop, maintain, and enforce security and compliance SOPs, internal documentation, and company-wide policies, particularly for SOC 2 and future framework adoption.
- Manage trust management platforms covering controls, risks, vendors, and exceptions.
- Implement AI agents to automate and improve controls-framework operations and evidence collection.
- Establish and maintain data governance policies, including classification, retention, and handling.
- Conduct internal risk assessments, identify control gaps, and coordinate remediation plans.
- Manage the third-party vendor risk program, including onboarding reviews, monitoring, and renewal assessments.
- Lead interactions with external auditors and regulatory bodies during compliance assessments, including SOC 2 Type 2.
- Oversee responses to client security assessments and due diligence requests.
- Monitor relevant compliance frameworks, laws, and regulations.
- Partner with Security, Legal, Engineering, Sales, and IT to implement scalable GRC processes, harmonize systems, educate employees, and develop KPI-driven insights.
Requirements
- 8+ years of governance, risk, and compliance experience within SaaS; HCM, payroll, or fintech experience is preferred.
- Bachelor’s degree in Business, Information Systems, or a related field.
- Strong understanding of SaaS business models and experience implementing controls and policies in fast-paced, product-driven environments.
- Experience leading or supporting a SOC 2 Type 2 compliance initiative and collaborating with auditors and cross-functional teams.
- Familiarity with compliance platforms such as Optro, Vanta, Drata, Viso Trust, or similar tools.
- Ability to translate complex GRC requirements into actionable, scalable processes.
- Excellent written and verbal communication skills, including the ability to educate and influence cross-functional stakeholders.
- Data-informed approach with the ability to use analytics to assess GRC performance and maturity.
- Relevant certification preferred, such as CISA, CRISC, or GRCP.
Nice-to-haves
- CGEIT, CRMA, or PMI-RMP certification.
- Experience in HCM, payroll, or fintech sectors.
Compensation and Benefits
- Cash compensation target: $183,000–$205,000 in the San Francisco Bay Area.
- Stock equity is additional.
- Full-time employees receive benefits and equity.
Skills
SOC 2, It General Controls, Data Governance, Vendor Risk Management, Risk Assessments, Vanta, Drata, Optro, Viso Trust, AI Agents, Analytics, Cisa, Crisc
Similar jobs
Security Engineering jobsOwn end-to-end security detection engineering, incident response, automation, and threat hunting across endpoint, identity, SaaS, and cloud environments. The role requires substantial hands-on experience with production detection logic, incident response, programming, and modern SIEM or detection pipelines.
Build data pipelines, integrations, policy-as-code, and agentic AI workflows that automate security governance and continuous compliance. The role requires 7+ years of production software engineering experience plus expertise in LLMs, APIs, distributed data, and cloud infrastructure.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.
Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.