
GRC Analyst
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in United States.
β’ Manage and enhance Upwind's GRC and security compliance initiatives.
β’ Assist with compliance efforts across SOC 2, ISO 27001, NIST, and FedRAMP, which includes control implementation, evidence gathering, documentation, remediation tracking, continuous monitoring, and audit preparation.
β’ Collaborate with Engineering, IT, Security, Legal, and HR to coordinate audit and compliance evidence.
β’ Convert compliance requirements into actionable items for technical and business teams.
β’ Conduct control assessments, gap analyses, and risk evaluations, providing remediation recommendations.
β’ Partner with process owners to develop sustainable, evidence-driven remediation strategies.
β’ Monitor vulnerabilities, risks, audit findings, and POA&Ms until resolution.
β’ Address customer security questionnaires, due diligence inquiries, and security documentation requests.
β’ Assist in third-party risk management and vendor security evaluations.
β’ Draft and maintain policies, standards, procedures, and control documentation.
β’ Oversee GRC systems, evidence repositories, and risk registers.
β’ Investigate new regulatory and customer requirements to assess their relevance.
β’ Leverage AI and automation to expedite research, documentation, evidence organization, and workflows while ensuring proper validation and data management.
β’ Identify gaps and issues promptly, proposing solutions.
β’ 3 to 5 years of experience in GRC, cybersecurity, risk management, compliance, or auditing.
β’ Knowledge of NIST 800-53, SOC 2, ISO 27001, NIST CSF, or similar frameworks.
β’ Experience in supporting audits, assessments, security questionnaires, or evidence collection.
β’ Excellent written communication and documentation abilities.
β’ Technical proficiency to collaborate effectively with Engineering, IT, and Security teams.
β’ Capability to transform audit findings into implementable remediation strategies.
β’ Comfort in a dynamic environment where priorities may change.
β’ Proven track record of utilizing technology to enhance GRC operations, including risk analysis, evidence collection, control monitoring, remediation tracking, research, customer trust, or workflow automation.
β’ Highly organized and detail-oriented.
β’ Nice-to-have: Familiarity with FedRAMP, NIST 800-53, or other U.S. government compliance experience, including POA&Ms, continuous monitoring, or assessment activities.
β’ Nice-to-have: Experience collaborating with external assessors on formal readiness or assessment efforts.
β’ Nice-to-have: Cloud security experience, especially with AWS or AWS GovCloud.
β’ Nice-to-have: Background in SaaS, cloud security, or a rapidly growing technology firm.
β’ Nice-to-have: Experience working within a global, distributed workforce across various time zones.
β’ Nice-to-have: Practical experience with cloud-based GRC, compliance automation, or AI-driven workflow platforms.
β’ Nice-to-have: Expertise in developing GRC automations, integrations, or dashboards.
β’ Nice-to-have: Familiarity with Jira, GitHub, or similar tools.
β’ Certifications such as Security+, CISA, CRISC, CISM, CGRC, or ISO 27001 are also beneficial.
β’ Full-time employment.
β’ Remote work opportunity within the United States.
ExamWorks
AAA
Muon Space
Nestle
Get handpicked remote jobs straight to your inbox weekly.