GRC (Governance, Risk, and Compliance) Analyst
About the role
Take ownership of GRC workstreams and drive them from the initial request through evidence collection, testing, remediation, and completion
Help keep YipitData audit-ready throughout the year
Test security controls and determine whether they are actually working, rather than simply confirming that a document exists
Conduct risk assessments, identify meaningful gaps, and help teams develop remediation plans that are realistic and effective
Map controls across SOC 2 and other frameworks so one strong control can satisfy multiple requirements
Coordinate recurring work such as access reviews, control testing, policy reviews, risk updates, and audit evidence requests
Review vendors and help determine whether their security practices meet YipitData's expectations
Support customer security questionnaires by finding the right information, validating it, and making sure our answers are accurate and consistent
Translate compliance requirements into clear actions for teams that do not live and breathe GRC
Draft and maintain policies, standards, control narratives, risk records, metrics, and other program documentation
Track findings and remediation commitments, follow up with owners, and keep issues from quietly sitting open forever
Look for ways to simplify and automate repetitive GRC work so the program can scale with the business
Help us think through governance for emerging technologies, including AI products, agents, and new ways of handling data
Responsibilities
Take ownership of GRC workstreams and drive them from the initial request through evidence collection, testing, remediation, and completion
Help keep YipitData audit-ready throughout the year
Test security controls and determine whether they are actually working, rather than simply confirming that a document exists
Conduct risk assessments, identify meaningful gaps, and help teams develop remediation plans that are realistic and effective
Map controls across SOC 2 and other frameworks so one strong control can satisfy multiple requirements
Coordinate recurring work such as access reviews, control testing, policy reviews, risk updates, and audit evidence requests
Review vendors and help determine whether their security practices meet YipitData's expectations
Support customer security questionnaires by finding the right information, validating it, and making sure our answers are accurate and consistent
Translate compliance requirements into clear actions for teams that do not live and breathe GRC
Draft and maintain policies, standards, control narratives, risk records, metrics, and other program documentation
Track findings and remediation commitments, follow up with owners, and keep issues from quietly sitting open forever
Look for ways to simplify and automate repetitive GRC work so the program can scale with the business
Help us think through governance for emerging technologies, including AI products, agents, and new ways of handling data
Requirements
You can operate in an environment that is constantly changing: where not every process is perfect or every answer is immediately available
You have experience in security, compliance, risk, audit, privacy, vendor risk, or another field that taught you how to evaluate whether expectations are being met
You understand that evidence is only useful if it actually proves the control
You can connect a policy or framework requirement to what people and systems are doing in the real world
You are familiar with SOC 2, NIST CSF, or similar security and compliance frameworks
You are a strong writer who can make complicated requirements clear for those not familiar with security frameworks
You notice inconsistencies, missing information, and answers that do not quite add up
You are comfortable asking follow-up questions and respectfully pushing back when something needs a closer look
You can keep multiple workstreams organized, meet deadlines, and follow through
You communicate well with both technical and non-technical teams and can explain why a requirement matters
You take ownership, use good judgment, and know when to work independently versus when to escalate
You are interested in figuring out how traditional governance needs to evolve for AI and other emerging technologies
Qualifications
Experience in security, compliance, risk, audit, privacy, vendor risk, or another field that taught you how to evaluate whether expectations are being met
Familiarity with SOC 2, NIST CSF, or similar security and compliance frameworks
Strong writing skills to translate compliance requirements into clear actions for teams that do not live and breathe GRC
Ability to connect policy or framework requirements to real-world operations
Comfortable operating in a constantly changing environment
Experience conducting risk assessments and developing remediation plans
Experience mapping controls across different frameworks
Skills
Experience in security, compliance, risk, audit, privacy, vendor risk, or another field
Familiarity with SOC 2, NIST CSF, or similar frameworks
Strong writing and communication skills
Ability to connect policy or framework requirements to real-world operations
Experience conducting risk assessments and developing remediation plans
Experience mapping controls across different frameworks
Benefits
Comprehensive benefits including flexible work hours, flexible vacation, a generous 401K match, parental leave, team events, wellness budget, learning reimbursement, and more!
Pay
The annual base salary range for this position is anticipated to be $102,500 / year. Final compensation may be determined by a number of factors, including, but not limited to, the applicant's experience, knowledge, skills, abilities, and internal team benchmarks.
Schedule
This role may be performed fully remotely within the United States. Please note that our US headquarters are located in NYC. If the remote work is performed outside of these offices, income may be subject to New York State tax withholding.