GRC (Governance, Risk, and Compliance) Analyst
About the role
The GRC Analyst will play a crucial part in ensuring YipitData's security controls are robust and effective. They will be responsible for conducting audits, risk assessments, control testing, vendor reviews, and customer questionnaires. The role involves partnering with various departments to understand operations, identify gaps, and develop remediation plans.
Responsibilities
- Drive GRC workstreams from initial request through evidence collection, testing, remediation, and completion
- Test security controls to ensure they are working as intended
- Conduct risk assessments and develop remediation plans
- Map controls across SOC 2 and other frameworks
- Support customer security questionnaires and review vendors
- Translate compliance requirements into clear actions
- Organize and track findings and remediation commitments
- Communicate with both technical and non-technical teams
- Identify areas for simplification and automation
- Think through governance for emerging technologies
Requirements
No specific requirements are listed in the job posting.
Qualifications
No specific qualifications are listed in the job posting.
Skills
No specific skills are listed in the job posting.
Benefits
No specific benefits are listed in the job posting.
Pay
The annual base salary range for this position is anticipated to be $102,500 / year. Final compensation may be determined by a number of factors, including, but not limited to, the applicant’s experience, knowledge, skills, abilities, and internal team benchmarks.
Schedule
The work hours are flexible on this team, but most employees work East Coast hours.