Associate GRC Analyst
KAYAK · Cambridge, MA · Yesterday
Hybrid$85k–$95k/yrFull-time
About the role
KAYAK, part of Booking Holdings (NASDAQ: BKNG), is seeking an Associate GRC Analyst to join our Cyber Governance, Risk, and Compliance team. This role offers an opportunity for an early-career professional to contribute to a dynamic cybersecurity and risk management environment.
Responsibilities
- Support the execution of risk assessments, including identifying, documenting, and tracking risks across business and technology areas
- Maintain and update policies, standards, and procedures aligned with security and compliance frameworks such as NIST CSF, SOC 2, PCI DSS, and GDPR
- Cook up internal and external audits by gathering evidence, tracking findings, and following up on remediation steps
- Contribute to control testing and monitoring, verifying that implemented controls are working as intended
- Maintain the risk register and support risk treatment tracking
- Aid with customer-facing security reviews, including completing security questionnaires and preparing due diligence documentation
- Support the development, maintenance, and testing of Business Continuity and Disaster Recovery plans, including Business Impact Analyses (BIAs) and recovery strategies
- Collaborate with engineering, security, and business teams to gather evidence, clarify requirements, and communicate compliance obligations
- Contribute to efforts to automate and streamline GRC processes, for example, helping to reduce manual evidence collection through scripts, APIs, or compliance platform integrations
- Stay current on regulatory changes, emerging frameworks, and evolving approaches to governance and compliance
Requirements
- Bachelor's degree in a relevant field (such as cybersecurity, information systems, computer science, risk management, or business) — or equivalent practical experience, training, or transferable skills
- A foundational understanding of GRC concepts, including risk management, controls, compliance frameworks, and audit processes
- Basic familiarity with Business Continuity and Disaster Recovery principles, including concepts like Business Impact Analyses, recovery time objectives, and recovery point objectives
- Some familiarity with at least one major security or compliance framework (such as NIST CSF, SOC 2, or PCI DSS)
- Experience in a GRC, cybersecurity, internal audit, IT risk, or business continuity context — paid, academic, capstone, or volunteer experience is all considered
Qualifications
- Clear written and verbal communication skills, including the ability to explain risk and compliance concepts to a range of audiences
- Strong organizational skills and the ability to manage multiple priorities at once
- A curious, analytical mindset and a genuine interest in learning and asking questions
Skills
- Exposure to or interest in treating GRC processes as code — for example, automating controls, using APIs, or applying engineering approaches to scale compliance work (no prior coding experience required; we'll support your learning)
- Prior experience with a compliance or business continuity platform such as Drata or RiskConnect
Benefits & Perks
- Work from (almost) anywhere for up to 20 days per year
- Focus on mental health and well-being: Company-paid therapy sessions through SpringHealth, Company-paid subscription to HeadSpace, Company-wide week off a year – the whole team fully recharges (and returns without a pile-up of work!)
- No meeting Fridays
- Paid parental leave
- Generous paid vacation + time off for your birthday
- Paid volunteer time
- Competitive salary range: $85,000 - 95,000.00, not inclusive of annual bonus
- Benefits including: health benefits; flexible spending account; retirement benefits; life insurance; paid time off (including PTO, paid sick leave, medical leave, bereavement leave, floating holidays and paid holidays); and parental leave benefits
- Free lunch 2 days per week
- Fun quarterly events such as boat trips, arcades, ski trips, Thursday happy hours, and more