GRC Analyst

atUpwind SecurityRemoteUS flagUnited StatesFull-timeRiskMid-levelSenior

Posted 16 hours ago

This is a fully remote position, open to applicants in United States.

πŸ“‹ Description

β€’ Manage and enhance Upwind's GRC and security compliance initiatives.

β€’ Assist with compliance efforts across SOC 2, ISO 27001, NIST, and FedRAMP, which includes control implementation, evidence gathering, documentation, remediation tracking, continuous monitoring, and audit preparation.

β€’ Collaborate with Engineering, IT, Security, Legal, and HR to coordinate audit and compliance evidence.

β€’ Convert compliance requirements into actionable items for technical and business teams.

β€’ Conduct control assessments, gap analyses, and risk evaluations, providing remediation recommendations.

β€’ Partner with process owners to develop sustainable, evidence-driven remediation strategies.

β€’ Monitor vulnerabilities, risks, audit findings, and POA&Ms until resolution.

β€’ Address customer security questionnaires, due diligence inquiries, and security documentation requests.

β€’ Assist in third-party risk management and vendor security evaluations.

β€’ Draft and maintain policies, standards, procedures, and control documentation.

β€’ Oversee GRC systems, evidence repositories, and risk registers.

β€’ Investigate new regulatory and customer requirements to assess their relevance.

β€’ Leverage AI and automation to expedite research, documentation, evidence organization, and workflows while ensuring proper validation and data management.

β€’ Identify gaps and issues promptly, proposing solutions.


⛳️ Requirements

β€’ 3 to 5 years of experience in GRC, cybersecurity, risk management, compliance, or auditing.

β€’ Knowledge of NIST 800-53, SOC 2, ISO 27001, NIST CSF, or similar frameworks.

β€’ Experience in supporting audits, assessments, security questionnaires, or evidence collection.

β€’ Excellent written communication and documentation abilities.

β€’ Technical proficiency to collaborate effectively with Engineering, IT, and Security teams.

β€’ Capability to transform audit findings into implementable remediation strategies.

β€’ Comfort in a dynamic environment where priorities may change.

β€’ Proven track record of utilizing technology to enhance GRC operations, including risk analysis, evidence collection, control monitoring, remediation tracking, research, customer trust, or workflow automation.

β€’ Highly organized and detail-oriented.

β€’ Nice-to-have: Familiarity with FedRAMP, NIST 800-53, or other U.S. government compliance experience, including POA&Ms, continuous monitoring, or assessment activities.

β€’ Nice-to-have: Experience collaborating with external assessors on formal readiness or assessment efforts.

β€’ Nice-to-have: Cloud security experience, especially with AWS or AWS GovCloud.

β€’ Nice-to-have: Background in SaaS, cloud security, or a rapidly growing technology firm.

β€’ Nice-to-have: Experience working within a global, distributed workforce across various time zones.

β€’ Nice-to-have: Practical experience with cloud-based GRC, compliance automation, or AI-driven workflow platforms.

β€’ Nice-to-have: Expertise in developing GRC automations, integrations, or dashboards.

β€’ Nice-to-have: Familiarity with Jira, GitHub, or similar tools.

β€’ Certifications such as Security+, CISA, CRISC, CISM, CGRC, or ISO 27001 are also beneficial.


🏝️ Benefits

β€’ Full-time employment.

β€’ Remote work opportunity within the United States.

People also viewed

ExamWorks11 hours ago

InfoSec GRC Analyst

US flagUnited States OnlyFull-timeRisk$60k – $90k/year
ApplyView job
AAA12 hours ago

Model Risk Advisor

US flagAlabama, +41 more statesFull-timeRisk$116.8k – $155.8k/year
ApplyView job
Muon Space12 hours ago

Senior Security Risk Analyst

US flagAlabama, +25 more statesFull-timeRisk$154k – $207k/year
ApplyView job
Nestle12 hours ago

Capital Governance Expert

US flagOhio OnlyFull-timeRisk$119.1k – $160k/year
ApplyView job
New York Blood Center16 hours ago

Insurance & Risk Specialist

US flagNew York OnlyFull-timeRisk$51 – $56/hour
ApplyView job
HealthEdge16 hours ago

VP, Sales – Risk & Quality

US flagUnited States OnlyFull-timeRisk$233k – $254k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers