GRC Analyst II
Payscale · United States · 2 wk ago
RemoteRemoteBusiness Development$81k–$121k/yrFull-time
About the role
Payscale is seeking a GRC Analyst II to join our Information Security Team. Reporting to the Manager of GRC, this role involves broad ownership of core GRC program areas and support for senior-level initiatives in risk, audit, and compliance.
Responsibilities
- Maintain Payscale's data classification program, including classification schema, tagging standards, and coordination with data owners.
- Maintain the system classification and ownership inventory, partnering with teams for proper classification, attribution, and regular reviews.
- Support audit coordination activities for SOC 2 and other compliance frameworks.
- Conduct vendor security assessments and reviews.
- Manage the policy management lifecycle, including drafting new policies, tracking review cycles, coordinating approvals, and maintaining version control.
- Identify control gaps or process improvement opportunities and collaborate with business units to implement and sustain effective controls.
Requirements
- Bachelor's degree in cybersecurity, information systems, or a related field.
- 2-4 years of work experience in GRC, information security, or a related field within a commercial SaaS or software company.
- Working knowledge of information security control frameworks such as SOC 2, ISO 27001, NIST 800-53, or CIS.
- Demonstrated experience with data classification frameworks and data governance concepts.
- Experience conducting vendor security assessments and managing third-party risk workflows.
- Hands-on experience with audit support activities, including evidence collection for SOC 2 or similar frameworks.
- Solid understanding of information security policies, standards, and procedures.
- Hands-on experience with GRC tools or platforms (e.g., Drata, ServiceNow GRC, or similar).
- Strong written and verbal communication skills with the ability to engage both technical and non-technical stakeholders.
- Ability to manage multiple workstreams independently, prioritize effectively, and meet deadlines.
Qualifications
- Location: Remote-first model with flexible work arrangements.
- Benefits: Comprehensive benefits package including medical, dental, life, vision, disability, and life insurance; 16 weeks of paid parental leave; 401(k) retirement plan with a fully vested immediate company match; and more.
- Equal Opportunity Employer: We value diversity and inclusion and are committed to creating an inclusive environment for all employees.
Skills
- Data classification and governance.
- Audit coordination and compliance.
- Vendor security assessment.
- Policy management and implementation.
- Communication and stakeholder engagement.
Benefits
- Flexible paid time off.
- 14 Paid Company Holidays.
- Comprehensive benefits plan including medical, dental, life, vision, disability, and life insurance.
- 16 weeks of paid parental leave.
- 401(k) retirement plan with a fully vested immediate company match.
- Annual remote work stipend.
- Supplemental health benefits.
- Employee Resource Groups.
- Volunteer hours.
- Continued learning and development opportunities.
Pay
$80.8K - $121.2K
Schedule
Remote-first model with flexible work arrangements.