
Senior Governance, Risk, and Compliance Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Utah.
• Take charge of and enhance RainFocus's governance, risk, and compliance (GRC) program
• Direct the GRC program encompassing SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, which includes audit preparation, evidence collection, and managing auditor relationships
• Oversee and advance the control framework, map new regulations, and perform gap assessments
• Manage the annual security risk assessment process utilizing NIST SP 800-30, which includes stakeholder interviews, risk scoring, and tracking residual risk
• Keep security policies, standards, and documentation current and updated
• Collaborate with Engineering and Security teams to enhance vulnerability management and secrets-scanning practices
• Develop and implement a Data Loss Prevention program spanning email, endpoints, and cloud storage
• Expand the security awareness training initiative
• Lead AI governance policy, tools, and monitoring efforts
• Recognize and assist in mitigating Shadow IT and unmanaged SaaS visibility gaps with IT
• Work collaboratively across functions to establish risk management practices and ensure compliance throughout the organization
• Address security and privacy inquiries from clients, partners, and employees
• Compile and deliver security and privacy compliance reports, detailing program maturity and remediation progress
• Monitor emerging security threats, vulnerabilities, and compliance requirements
• Report directly to the Chief Information Security Officer (CISO)
• A Bachelor’s degree in Technology, Cybersecurity, or a related discipline is highly preferred
• Over 6 years of experience in GRC, IT audit, information security compliance, or a similar field
• Comprehensive understanding of SOC 2, ISO 27001, PCI DSS, NIST 800-series, GDPR, and associated frameworks
• Proven experience in conducting or significantly contributing to formal risk assessments
• Professional certifications such as CISA, CRISC, CISSP, CIPP, or CIPM are strongly preferred
• Familiarity with security tools like Drata, OneTrust, Vanta, or similar platforms
• Excellent analytical and problem-solving abilities
• Outstanding communication and interpersonal skills
• Capability to handle multiple projects and meet deadlines in a dynamic environment
• Experience with cloud security and compliance frameworks is advantageous
• Familiarity with OneTrust or similar GRC technologies is a plus
• Strong work ethic and dedication to excellence
• Ability to work independently as well as collaboratively within a team
• Adaptability to change and eagerness to learn quickly
• A genuine passion for security and privacy
• Competitive salaries
• Comprehensive benefits package
• 401k plan
• Generous Paid Time Off (PTO)
• Team-building activities
ICON plc
US Anesthesia Partners
MultiplyMii
Paychex
Get handpicked remote jobs straight to your inbox weekly.