Associate GRC Analyst
KAYAK, part of Booking Holdings (NASDAQ: BKNG), is a leading travel search engine helping people find flights, stays, rental cars, and vacation packages. As part of a global portfolio including momondo, Cheapflights, and HotelsCombined, KAYAK fosters innovation and offers employees the opportunity to make an impact in a dynamic environment.
About the role
This is an exciting opportunity for an early-career professional to grow within a dynamic cybersecurity and risk management environment. You will work alongside an experienced team to support risk assessments, compliance activities, policy management, control monitoring, and business continuity and disaster recovery (BC/DR) efforts—while contributing to the modernization of our GRC program. This position is required to work from our Cambridge or Concord, MA office 3 days per week.
Responsibilities
- Support the execution of risk assessments, including identifying, documenting, and tracking risks across business and technology areas
- Help maintain and update policies, standards, and procedures aligned with security and compliance frameworks such as NIST CSF, SOC 2, PCI DSS, and GDPR
- Help coordinate internal and external audits by gathering evidence, tracking findings, and following up on remediation steps
- Contribute to control testing and monitoring, verifying that implemented controls are working as intended
- Maintain the risk register and support risk treatment tracking
- Assist with customer-facing security reviews, including completing security questionnaires and preparing due diligence documentation
- Support the development, maintenance, and testing of Business Continuity and Disaster Recovery plans, including Business Impact Analyses (BIAs) and recovery strategies
- Collaborate with engineering, security, and business teams to gather evidence, clarify requirements, and communicate compliance obligations
- Contribute to efforts to automate and streamline GRC processes — for example, helping to reduce manual evidence collection through scripts, APIs, or compliance platform integrations
- Stay current on regulatory changes, emerging frameworks, and evolving approaches to governance and compliance
Requirements
- A bachelor's degree in a relevant field (such as cybersecurity, information systems, computer science, risk management, or business) — or equivalent practical experience, training, or transferable skills
- A foundational understanding of GRC concepts, including risk management, controls, compliance frameworks, and audit processes
- Basic familiarity with Business Continuity and Disaster Recovery principles, including concepts like Business Impact Analyses, recovery time objectives, and recovery point objectives
- Some familiarity with at least one major security or compliance framework (such as NIST CSF, SOC 2, or PCI DSS)
- Experience in a GRC, cybersecurity, internal audit, IT risk, or business continuity context — paid, academic, capstone, or volunteer experience is all considered
- Clear written and verbal communication skills, including the ability to explain risk and compliance concepts to a range of audiences
- Strong organizational skills and the ability to manage multiple priorities at once
- A curious, analytical mindset and a genuine interest in learning and asking questions
Nice to have
- Exposure to or interest in treating GRC processes as code — for example, automating controls, using APIs, or applying engineering approaches to scale compliance work (no prior coding experience required; we'll support your learning)
- Prior experience with a compliance or business continuity platform such as Drata or RiskConnect
Benefits
- Work from (almost) anywhere for up to 20 days per year
- Focus on mental health and well-being: company-paid therapy sessions through SpringHealth, company-paid subscription to HeadSpace, company-wide week off a year
- No meeting Fridays
- Paid parental leave
- Generous paid vacation + time off for your birthday
- Paid volunteer time
- Development Dollars and leadership development
- Access to thousands of on-demand e-learnings
- Travel discounts
- Employee Resource Groups
- Competitive retirement and health plans
- Free lunch 2 days per week
- Fun quarterly events such as boat trips, arcades, ski trips, Thursday happy hours, and more
Pay
The range for this Massachusetts-based role is $85,000 - $95,000, not inclusive of annual bonus. We offer a competitive base salary and benefits including health benefits, flexible spending account, retirement benefits, life insurance, and paid time off (including PTO, paid sick leave, medical leave, bereavement leave, floating holidays, and paid holidays).
Schedule
This position is required to work from our Cambridge or Concord, MA office 3 days per week.