Remotery

Senior GRC Analyst

atPrizePicksRemoteUS flagUnited StatesFull-timeRiskSenior$110k – $120k/year

Posted Aug 8

This is a fully remote position, open to applicants in United States.

📋 Description

• Direct the continuous evaluation and upkeep of organizational security policies, standards, and procedures; identify policy deficiencies based on regulatory obligations, business demands, and industry best practices.

• Collaborate with Legal, Regulatory Affairs, Internal Audit, and other compliance teams to ensure a cohesive governance roadmap.

• Spearhead security risk assessments for new and renewing third-party vendors, monitor remediation tasks, and tackle identified risks.

• Organize annual security audits and certifications such as SOC 2, PCI, and CIS.

• Oversee evidence collection, action item tracking, stakeholder communication, audit preparedness, and liaison activities with external auditors.

• Align security controls with operational processes and the necessary supporting evidence.

• Manage and enhance the security awareness and training program, including tracking completion metrics and developing training content.

• Collaborate with Legal and Regulatory teams to interpret evolving compliance requirements and synchronize corporate practices with technology.

• Enhance the efficiency, consistency, and scalability of GRC processes, documentation, tools, and workflows.

• Maintain and refine risk and issue registries, encompassing exceptions, risk owners, and update timelines.


⛳️ Requirements

• A minimum of 5 years of experience in Governance, Risk, and Compliance (GRC), Information Security, IT Audit, or related areas.

• Proven ability to independently manage audits, compliance initiatives, or governance programs with minimal supervision.

• Familiarity with SOC 2, ISO 27001, SOX 404, PCI-DSS, NIST, GDPR, CIS, or comparable frameworks.

• Experience in audit evidence gathering and review, remediation tracking, and auditor coordination.

• Background in maintaining or developing security policies, standards, and procedures.

• Practical experience in conducting Third-Party Risk Management assessments, including vendor security reviews, questionnaire evaluations, risk analysis, remediation tracking, and ongoing monitoring.

• Skill in identifying, documenting, tracking, and communicating security and compliance risks to both technical and non-technical stakeholders.

• Familiarity with GRC platforms and tools for compliance activities, risk registers, policy lifecycle management, audit evidence collection, and workflow automation.

• Experience in mapping security and compliance controls to operational processes and evidence requirements.

• Understanding of GRC's impact on the Secure Software Development Life Cycle and IT operations.

• Involvement in supporting privacy and data protection compliance initiatives, including CCPA, consumer privacy regulations, and PII/data handling protection.

• Excellent written and verbal communication skills.

• Strong organizational and project management capabilities.

• Must be authorized to work for any employer in the U.S.; employment visa sponsorship is not available.

• Preferred: CISSP, CISM, CISA, CRISC, Security+, or similar certifications.

• Preferred: experience in rapidly growing technology or regulated environments.

• Preferred: familiarity with Vanta, Drata, Archer, OneTrust, or ServiceNow GRC.


🏝️ Benefits

• Company-subsidized medical, dental, & vision plans.

• 401(k) plan with company match.

• Annual bonus.

• Flexible PTO to promote a healthy work/life balance (2 weeks STRONGLY encouraged!).

• Generous paid leave programs, including 16-week paid parental leave and disability benefits.

• Workplace flexibility and modern work schedules focused on achieving results rather than clocking hours.

• Company-wide in-person events and team outings.

• Lifestyle enhancement program.

• Company-provided equipment (Windows & Mac options).

• Annual performance reviews with opportunities for growth and career development.

People also viewed

Circana1 day ago

VP, Global Compensation Administration – Governance

US flagUnited States OnlyFull-timeRisk$180k – $200k/year
ApplyView job
Zero Hash1 day ago

Operational Risk Manager

US flagUnited States, +1 more countryFull-timeRisk
ApplyView job
World Kinect1 day ago

Senior Analyst, Credit & Risk

US flagFlorida OnlyFull-timeRisk
ApplyView job
The Hartford1 day ago

Risk Manager – CAT Modeling

US flagConnecticut OnlyFull-timeRisk$112.4k – $168.6k/year
ApplyView job
NatWest Group1 day ago

Empirical Behavioural Scientist, Behavioural Risk

GB flagUnited Kingdom OnlyFull-timeRisk
ApplyView job
Vontier1 day ago

Global Privacy & Information Governance Manager

GB flagUnited Kingdom OnlyFull-timeRisk£65k – £80k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers