
GRC Analyst – Governance, Risk, Compliance
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in United States.
• Take ownership of GRC workstreams from the initial request stage through to evidence collection, testing, remediation, and project completion.
• Ensure YipitData remains audit-ready throughout the entire year.
• Assess the effectiveness of security controls through rigorous testing.
• Perform risk assessments, pinpoint gaps, and assist in creating remediation strategies.
• Align controls with SOC 2 and other relevant frameworks.
• Oversee access reviews, control testing, policy evaluations, risk updates, and audit evidence requests.
• Evaluate vendors and their security practices.
• Aid in responding to customer security questionnaires by ensuring accurate and consistent responses.
• Convert compliance requirements into actionable steps.
• Draft and sustain policies, standards, control narratives, risk records, metrics, and program documentation.
• Monitor findings and remediation commitments, following up with responsible parties.
• Streamline and automate repetitive GRC tasks.
• Contribute to the development of governance for AI products, agents, and new data-handling practices.
• Collaborate with Security, IT, Engineering, Legal, Finance, and People teams.
• Background in security, compliance, risk, audit, privacy, vendor risk, or a related discipline.
• Knowledge of SOC 2, NIST CSF, or comparable security and compliance frameworks.
• Excellent writing skills.
• Capacity to assess whether security and compliance standards are being fulfilled.
• Ability to link policy or framework requirements to real-world personnel and systems.
• Skill in identifying inconsistencies, missing information, and gaps.
• Comfort in asking follow-up questions and respectfully addressing issues.
• Proficiency in managing multiple workstreams, adhering to deadlines, and ensuring follow-through.
• Competence in communicating with both technical and non-technical teams.
• Ability to work autonomously while recognizing when to escalate issues.
• Interest in governance related to AI and emerging technologies.
• Flexible work hours.
• Flexible vacation policy.
• Generous 401K matching.
• Parental leave.
• Team events.
• Wellness budget.
• Learning reimbursement.
• Equity participation.
• Remote work options.
• Commitment to equal employment opportunity.
Pfizer
Sezzle
Amplity Health
Get handpicked remote jobs straight to your inbox weekly.