# Senior GRC Analyst

**Company:** [Gusto](https://hotfix.jobs/companies/gusto)
**Location:** San Francisco, CA
**Role:** Security Engineering
**Salary:** $183k – $205k/yr
**Experience:** 8+ years
**Skills:** SOC 2, It General Controls, Data Governance, Vendor Risk Management, Risk Assessments, Vanta, Drata, Optro, Viso Trust, AI Agents, Analytics, Cisa, Crisc
**Posted:** 2026-08-27

> The Senior GRC Analyst will manage security governance, risk, and compliance programs, including SOC 2 controls, risk assessments, vendor reviews, audits, and data governance. The role requires 8+ years of GRC experience, a bachelor’s degree, and familiarity with compliance platforms and SaaS environments.

## Job Description

## Responsibilities
- Develop, maintain, and enforce security and compliance SOPs, internal documentation, and company-wide policies, particularly for SOC 2 and future framework adoption.
- Manage trust management platforms covering controls, risks, vendors, and exceptions.
- Implement AI agents to automate and improve controls-framework operations and evidence collection.
- Establish and maintain data governance policies, including classification, retention, and handling.
- Conduct internal risk assessments, identify control gaps, and coordinate remediation plans.
- Manage the third-party vendor risk program, including onboarding reviews, monitoring, and renewal assessments.
- Lead interactions with external auditors and regulatory bodies during compliance assessments, including SOC 2 Type 2.
- Oversee responses to client security assessments and due diligence requests.
- Monitor relevant compliance frameworks, laws, and regulations.
- Partner with Security, Legal, Engineering, Sales, and IT to implement scalable GRC processes, harmonize systems, educate employees, and develop KPI-driven insights.

## Requirements
- 8+ years of governance, risk, and compliance experience within SaaS; HCM, payroll, or fintech experience is preferred.
- Bachelor’s degree in Business, Information Systems, or a related field.
- Strong understanding of SaaS business models and experience implementing controls and policies in fast-paced, product-driven environments.
- Experience leading or supporting a SOC 2 Type 2 compliance initiative and collaborating with auditors and cross-functional teams.
- Familiarity with compliance platforms such as Optro, Vanta, Drata, Viso Trust, or similar tools.
- Ability to translate complex GRC requirements into actionable, scalable processes.
- Excellent written and verbal communication skills, including the ability to educate and influence cross-functional stakeholders.
- Data-informed approach with the ability to use analytics to assess GRC performance and maturity.
- Relevant certification preferred, such as CISA, CRISC, or GRCP.

## Nice-to-haves
- CGEIT, CRMA, or PMI-RMP certification.
- Experience in HCM, payroll, or fintech sectors.

## Compensation and Benefits
- Cash compensation target: $183,000–$205,000 in the San Francisco Bay Area.
- Stock equity is additional.
- Full-time employees receive benefits and equity.

## Similar jobs

- [Senior Security Engineer, Detection & Response](https://hotfix.jobs/jobs/37a7b1d8-92a0-48d2-8ee3-02ab2a21f5ae) - Flexport - San Francisco, CA - $183k – $229k/yr
- [Senior GRC Engineer](https://hotfix.jobs/jobs/d697c300-f74b-4139-a767-9387816d3aa4) - Square - Remote - $185k – $327k/yr
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Senior Security Engineer, Threat & Offensive Security](https://hotfix.jobs/jobs/9e88bf55-b93e-4acd-ae0b-a8850f2c805e) - Valon - Remote - $180k – $230k/yr
- [Senior Product Security Engineer](https://hotfix.jobs/jobs/ee4b6e89-8ca0-45e7-9cbf-da0994206d99) - Anyscale - $180k – $210k/yr

**Apply:** https://hotfix.jobs/jobs/e5ffc43b-dac8-4c0a-be09-d1fa4e9cd8c5
**Canonical:** https://hotfix.jobs/jobs/e5ffc43b-dac8-4c0a-be09-d1fa4e9cd8c5