
Senior GRC Analyst
Posted Aug 8

Posted Aug 8
This is a fully remote position, open to applicants in United States.
• Direct the continuous evaluation and upkeep of organizational security policies, standards, and procedures; identify policy deficiencies based on regulatory obligations, business demands, and industry best practices.
• Collaborate with Legal, Regulatory Affairs, Internal Audit, and other compliance teams to ensure a cohesive governance roadmap.
• Spearhead security risk assessments for new and renewing third-party vendors, monitor remediation tasks, and tackle identified risks.
• Organize annual security audits and certifications such as SOC 2, PCI, and CIS.
• Oversee evidence collection, action item tracking, stakeholder communication, audit preparedness, and liaison activities with external auditors.
• Align security controls with operational processes and the necessary supporting evidence.
• Manage and enhance the security awareness and training program, including tracking completion metrics and developing training content.
• Collaborate with Legal and Regulatory teams to interpret evolving compliance requirements and synchronize corporate practices with technology.
• Enhance the efficiency, consistency, and scalability of GRC processes, documentation, tools, and workflows.
• Maintain and refine risk and issue registries, encompassing exceptions, risk owners, and update timelines.
• A minimum of 5 years of experience in Governance, Risk, and Compliance (GRC), Information Security, IT Audit, or related areas.
• Proven ability to independently manage audits, compliance initiatives, or governance programs with minimal supervision.
• Familiarity with SOC 2, ISO 27001, SOX 404, PCI-DSS, NIST, GDPR, CIS, or comparable frameworks.
• Experience in audit evidence gathering and review, remediation tracking, and auditor coordination.
• Background in maintaining or developing security policies, standards, and procedures.
• Practical experience in conducting Third-Party Risk Management assessments, including vendor security reviews, questionnaire evaluations, risk analysis, remediation tracking, and ongoing monitoring.
• Skill in identifying, documenting, tracking, and communicating security and compliance risks to both technical and non-technical stakeholders.
• Familiarity with GRC platforms and tools for compliance activities, risk registers, policy lifecycle management, audit evidence collection, and workflow automation.
• Experience in mapping security and compliance controls to operational processes and evidence requirements.
• Understanding of GRC's impact on the Secure Software Development Life Cycle and IT operations.
• Involvement in supporting privacy and data protection compliance initiatives, including CCPA, consumer privacy regulations, and PII/data handling protection.
• Excellent written and verbal communication skills.
• Strong organizational and project management capabilities.
• Must be authorized to work for any employer in the U.S.; employment visa sponsorship is not available.
• Preferred: CISSP, CISM, CISA, CRISC, Security+, or similar certifications.
• Preferred: experience in rapidly growing technology or regulated environments.
• Preferred: familiarity with Vanta, Drata, Archer, OneTrust, or ServiceNow GRC.
• Company-subsidized medical, dental, & vision plans.
• 401(k) plan with company match.
• Annual bonus.
• Flexible PTO to promote a healthy work/life balance (2 weeks STRONGLY encouraged!).
• Generous paid leave programs, including 16-week paid parental leave and disability benefits.
• Workplace flexibility and modern work schedules focused on achieving results rather than clocking hours.
• Company-wide in-person events and team outings.
• Lifestyle enhancement program.
• Company-provided equipment (Windows & Mac options).
• Annual performance reviews with opportunities for growth and career development.
Circana
Zero Hash
The Hartford
Get handpicked remote jobs straight to your inbox weekly.