
GRC Analyst
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in United States.
• Take charge of GRC workstreams from the initial request stage through to evidence collection, testing, remediation, and final completion.
• Ensure that YipitData remains audit-ready throughout the entire year.
• Assess security controls and confirm that evidence verifies their operational effectiveness.
• Perform risk assessments and assist in formulating remediation strategies.
• Align controls with SOC 2 and other relevant frameworks.
• Oversee access reviews, control testing, policy evaluations, risk updates, and audit evidence requests.
• Evaluate the security practices of vendors.
• Assist with customer security inquiries.
• Convert compliance requirements into actionable steps.
• Create and uphold policies, standards, control narratives, risk records, metrics, and program documentation.
• Monitor findings and commitments for remediation.
• Streamline and automate repetitive GRC tasks.
• Contribute to the governance of AI products, agents, and innovative data-handling techniques.
• Collaborate with Security, IT, Engineering, Legal, Finance, and People teams.
• Proven experience in security, compliance, risk management, auditing, privacy, vendor risk, or a closely related field.
• Practical experience with SOC 2, including support for Type I or Type II audits, testing controls, validating evidence, coordinating with auditors, and tracking remediation to completion.
• Knowledge of SOC 2, NIST CSF, or comparable security and compliance frameworks.
• Exceptional writing abilities to articulate complex requirements clearly.
• Skill in identifying discrepancies, missing information, and unsupported responses.
• Confidence in asking follow-up questions and appropriately challenging responses.
• Capability to manage multiple workstreams, adhere to deadlines, and ensure follow-through.
• Proficiency in communicating with both technical and non-technical teams.
• Ability to work autonomously and discern when to escalate issues.
• Interest in governance concerning AI and emerging technologies.
• Flexible availability, with most employees operating on East Coast hours.
• Flexible work hours.
• Flexible vacation policy.
• Generous 401K matching.
• Parental leave.
• Team-building events.
• Wellness budget.
• Learning reimbursement.
• Equity options.
• Opportunity for remote work.
Astrana Health
Elfonze Technologies
Netflix
Addvisor Group
Get handpicked remote jobs straight to your inbox weekly.