We are seeking a highly motivated GRC (Governance, Risk, and Compliance) Analyst to join our growing Security & Compliance team. In this role, you will be responsible for supporting the implementation, operation, and continuous improvement of our GRC framework. You will help ensure our organizations policies, procedures, and controls align with regulatory requirements and industry best practices.
Responsibilities:
Support the execution and enhancement of the organizations GRC strategy, including policy governance, risk assessments, compliance monitoring, and audit support.
Assist in maintaining compliance with security frameworks and standards such as ISO 27001, SOC 2, NIST, and GDPR.
Conduct periodic risk assessments and control gap analyses across departments.
Track remediation of audit findings, risks, and control deficiencies, and validate completion of corrective actions.
Support third-party risk management activities including vendor due diligence and ongoing assessments.
Help maintain the GRC tool and ensure timely updates of risk registers, controls, and evidence repositories.
Collaborate cross-functionally with IT, Legal, Engineering, and other business units to promote a culture of security and compliance.
Assist in the creation and maintenance of documentation such as policies, standards, and procedures.
Prepare reports and dashboards for management review.
Stay updated on emerging regulations, standards, and security trends.
Requirements: Bachelors degree in Information Security, Risk Management, Computer Science, or a related field.
4-6 years of experience in GRC, cybersecurity, risk management, or a compliance-focused role.
Familiarity with common regulatory and compliance frameworks (e.g., ISO 27001, SOC 2, HIPAA, PCI-DSS, NIST CSF).
Experience working with GRC platforms such as Vanta, Drata, OneTrust, or similar tools is a plus.
Excellent communication, documentation, and stakeholder engagement skills.
Strong attention to detail and organizational skills.
Relevant certifications (e.g., CISA, CISM, CRISC, ISO 27001 LA, or similar) are a plus.
This position is open to all candidates.