GRC Analyst
Zip · San Francisco, CA · 1 mo ago
HybridBusiness Development$95k–$150k/yrFull-time
Responsibilities
- Drive and perform periodic compliance-related activities, such as user access reviews, internal audits, and vendor risk assessments
- Lead conversations and curate responses for customers’ security, compliance, and governance teams in due diligence and security questionnaires
- Guide internal control owners and stakeholders to understand requirements, take accountability, and operationalize their controls
- Collaborate with internal stakeholders and external auditors to support third party audits including SOC 1, SOC 2, and ISO 27001
- Develop, maintain, and lead the adoption of security policies, standards, and guidelines to ensure compliance with applicable regulatory requirements
Requirements
- Bachelor’s degree in a related field
- 2+ years of experience in GRC, information security consulting, cybersecurity risk, audits, or similar roles
- Strong written and verbal communication skills with both technical and non-technical stakeholders
- Familiarity with and participation in one or more of the following frameworks: SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
- Familiarity with information security fundamentals for cloud software systems
Preferred Qualifications
- Professional certifications in information security are a plus but not required
Pay
The salary range for this role is $95,000 - $150,000. The salary for this position is determined based on a variety of job-related factors that may include location, relevant experience, education, or particular skills and expertise.
Schedule
Not specified
Benefits & Perks
- Start-up equity
- 100% health, vision & dental coverage options
- Catered breakfast, lunch, & dinner
- TClassPass membership
- Flexible PTO
- Classroom & wellness benefits
- Monthly commuter benefit
- Team building events & happy hours
- Home office stipend
- Phone/internet reimbursement
- Paid parental leave
- Fertility stipend
- Unlimited AI token usage