
Senior GRC Analyst
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in United States.
β’ Act as a proactive GRC advisor for a diverse portfolio of clients, assisting them in conducting risk assessments, maintaining risk registers, preparing for audits, and implementing controls.
β’ Support clients in their audit preparations and processes (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST, and similar frameworks), converting requirements into actionable next steps.
β’ Provide guidance on the development of policies and the design of controls customized to fit each client's risk profile and maturity level.
β’ Identify GRC complexities early β discerning when a client's inquiry involves risk, compliance, or audit subtleties that require more than a generic playbook response.
β’ Collaborate closely with Support and Customer Success teams to manage escalations that necessitate genuine GRC expertise, beyond mere product knowledge.
β’ Transform frequently asked customer queries into scalable solutions β creating playbooks, internal knowledge base content, and best-practice frameworks for team-wide use.
β’ Represent the client's voice internally, highlighting areas where our platform could enhance support for practical GRC workflows.
β’ Minimum of 5 years' experience as a GRC analyst, consultant, or coordinator β whether in-house, at a consulting firm, or in a related role.
β’ Direct, practical experience with audits, risk assessments, risk registers, and policy implementation β you have been actively involved, rather than just familiar with the concepts.
β’ Knowledge of common frameworks (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST, or similar) is essential.
β’ An innate ability to recognize GRC complexities: you can identify when an issue is more intricate than it seems and know how to clarify it for someone who is struggling.
β’ Excellent consultative communication skills β able to convey compliance concepts to non-technical stakeholders without sacrificing clarity.
β’ A genuine passion for helping clients solve their challenges, rather than simply closing tickets.
β’ Nice to Have: Certifications such as CISA, CRISC, CGRC, or ISO 27001 Lead Implementer/Auditor. Experience with a GRC software platform (as a practitioner, implementer, or vendor-side consultant). Exposure to various industries or company sizes, providing you with a broader understanding of how GRC programs function in practice.
β’ Competitive salary along with significant equity participation during a pivotal Series A phase.
β’ Comprehensive paid benefits package, including health insurance, 401(k), and generous leave policies.
Circana
Zero Hash
World Kinect
The Hartford
Get handpicked remote jobs straight to your inbox weekly.