Jobs · Business Development

GRC Analyst II

Payscale · United States · 2 wk ago
RemoteRemoteBusiness Development$81k–$121k/yrFull-time

About the role

Payscale is seeking a GRC Analyst II to join our Information Security Team. Reporting to the Manager of GRC, this role involves broad ownership of core GRC program areas and support for senior-level initiatives in risk, audit, and compliance.

Responsibilities

  • Maintain Payscale's data classification program, including classification schema, tagging standards, and coordination with data owners.
  • Maintain the system classification and ownership inventory, partnering with teams for proper classification, attribution, and regular reviews.
  • Support audit coordination activities for SOC 2 and other compliance frameworks.
  • Conduct vendor security assessments and reviews.
  • Manage the policy management lifecycle, including drafting new policies, tracking review cycles, coordinating approvals, and maintaining version control.
  • Identify control gaps or process improvement opportunities and collaborate with business units to implement and sustain effective controls.

Requirements

  • Bachelor's degree in cybersecurity, information systems, or a related field.
  • 2-4 years of work experience in GRC, information security, or a related field within a commercial SaaS or software company.
  • Working knowledge of information security control frameworks such as SOC 2, ISO 27001, NIST 800-53, or CIS.
  • Demonstrated experience with data classification frameworks and data governance concepts.
  • Experience conducting vendor security assessments and managing third-party risk workflows.
  • Hands-on experience with audit support activities, including evidence collection for SOC 2 or similar frameworks.
  • Solid understanding of information security policies, standards, and procedures.
  • Hands-on experience with GRC tools or platforms (e.g., Drata, ServiceNow GRC, or similar).
  • Strong written and verbal communication skills with the ability to engage both technical and non-technical stakeholders.
  • Ability to manage multiple workstreams independently, prioritize effectively, and meet deadlines.

Qualifications

  • Location: Remote-first model with flexible work arrangements.
  • Benefits: Comprehensive benefits package including medical, dental, life, vision, disability, and life insurance; 16 weeks of paid parental leave; 401(k) retirement plan with a fully vested immediate company match; and more.
  • Equal Opportunity Employer: We value diversity and inclusion and are committed to creating an inclusive environment for all employees.

Skills

  • Data classification and governance.
  • Audit coordination and compliance.
  • Vendor security assessment.
  • Policy management and implementation.
  • Communication and stakeholder engagement.

Benefits

  • Flexible paid time off.
  • 14 Paid Company Holidays.
  • Comprehensive benefits plan including medical, dental, life, vision, disability, and life insurance.
  • 16 weeks of paid parental leave.
  • 401(k) retirement plan with a fully vested immediate company match.
  • Annual remote work stipend.
  • Supplemental health benefits.
  • Employee Resource Groups.
  • Volunteer hours.
  • Continued learning and development opportunities.

Pay

$80.8K - $121.2K

Schedule

Remote-first model with flexible work arrangements.

Similar jobs

GRC Analyst II

Metropolis TechnologiesLos Angeles, CA· Yesterday
Business Development$100k/yrapply on grnh.se

GRC Analyst II

Frontgrade TechnologiesUnited States· 2 mo ago
RemoteBusiness Developmentapply on exzj.fa.us8.oraclecloud.com

GRC Security Analyst II

AquaBryn Mawr, PA· 1 mo ago
Information Technologyapply on aquaamerica.wd5.myworkdayjobs.com

GRC Analyst

LaddersUnited States· 2 wk ago
RemoteBusiness Development$134k–$202k/yrapply on theladders.com

GRC Analyst

University of OklahomaNorman, OK· 1 wk ago
Business Development$46k–$60k/yrapply on jobs.ou.edu

GRC Analyst

UplightBoulder, CO· 1 mo ago
RemoteBusiness Developmentapply on jobs.jobvite.com