
Senior GRC Analyst
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in United States.
• Take ownership of designated GRC projects, compliance deliverables, and process enhancements from initial planning to final execution
• Facilitate the daily operations and ongoing enhancement of Aya’s enterprise GRC initiative
• Develop and refine scalable workflows that convert regulatory and framework requirements into control activities and operational duties
• Assist with ensuring compliance with SOC 2 and ISO/IEC 27001:2022, including readiness assessments, audit preparation, evidence coordination, control testing, auditor support, and remediation tracking
• Establish control ownership, traceability, documentation, and evidence requirements
• Transition manual or spreadsheet-based compliance activities to automated, system-driven processes
• Enhance automated evidence collection, control testing, issue and remediation tracking, dashboards, and reporting
• Conduct reviews of controls, risk assessments, evidence evaluations, and compliance gap analyses
• Oversee remediation efforts, follow up with control owners, identify delivery risks, and escalate issues as necessary
• Create and maintain dashboards, metrics, and reports that communicate compliance status, trends, exceptions, risks, and remediation progress
• Collaborate with ServiceNow platform and engineering teams to develop scalable and maintainable GRC solutions
• Address customer inquiries regarding compliance, security, privacy, and risk in RFPs, due diligence requests, contracts, and meetings
• Work together with Security, IT, Engineering, Finance, Legal, Privacy, Internal Audit, and business stakeholders
• Convert risk and compliance requirements into actionable business guidance
• Lead working sessions, walkthroughs, and discussions with control owners and subject-matter experts
• Identify emerging risks, process dependencies, and long-term improvements in GRC
• Mentor junior analysts and team members through collaboration, knowledge sharing, and examples
• Review work outputs for accuracy, completeness, and adherence to quality standards
• Document process enhancements, design choices, procedures, and lessons learned
• Minimum of 4 years of experience in Governance, Risk, and Compliance, Information Security, IT Audit, or a related field
• Practical experience in operating or configuring GRC tools such as ServiceNow GRC / IRM, Drata, Vanta, or Hyperproof
• Proven track record of managing GRC projects, compliance deliverables, or process improvement initiatives from planning through execution
• Strong familiarity with SOC 2 or ISO/IEC 27001:2022 standards
• Experience with control design, evidence evaluation, risk assessments, audit support, remediation tracking, or compliance testing
• Background in enhancing manual compliance processes through automation, workflow design, or system-based reporting
• Excellent written and verbal communication skills, with the ability to convey risk and compliance concepts to both technical and non-technical audiences
• Capability to work independently, manage competing priorities, anticipate next steps, and escalate risks proactively
• Experience collaborating across Information Security, IT, Engineering, Legal, Privacy, Finance, Audit, and business teams
• Bachelor’s degree in IT / CS is preferred
• CISA, CISSP (or CISSP Associate), CCSP, ISO 27001 certification, or another relevant security or compliance credential is preferred
• Familiarity with additional security, compliance, AI governance, and privacy frameworks or regulatory requirements, including ISO/IEC 42001, NIST AI RMF, NIST CSF, GDPR/UK GDPR, and CCPA/CPRA, is a plus
• Experience in ServiceNow GRC / IRM implementation, administration, configuration, or integration is preferred
• Proven experience in developing GRC metrics, dashboards, KPIs, or leadership reporting is preferred
• Experience in supporting internal or external audits within a regulated or healthcare-related environment is preferred
• Availability during PST business hours
• Comprehensive premium medical, dental, life, and vision insurance
• Generous 401(k) matching contributions
• Reimbursement programs
• Discretionary bonuses
• Paid sick leave in compliance with applicable state, federal, and local legislation
• Celebrations and rewards for achieving objectives
• Company-sponsored virtual events, happy hours, and team-building activities
• Birthday treats
• Unlimited DTO (time off)
• Daily virtual yoga, meditation, or boot camp classes
XBOX
Monarch Money
XBOX
Get handpicked remote jobs straight to your inbox weekly.