Senior GRC Analyst

Posted 6 hours ago

This is a fully remote position, open to applicants in United States, +2 more locations.

📋 Description

• Design, uphold, and evaluate Shift’s comprehensive security and privacy management framework.

• Ensure adherence to critical industry standards.

• Conduct risk assessments.

• Manage the third-party security assurance program.

• Assist TrustOps initiatives related to customer materials, inquiries, contract evaluations, and due diligence.

• Convert global information security requirements into implementable policies, standards, and procedures.

• Advocate for security and compliance throughout the organization and serve as a subject matter expert.

• Contribute to the security awareness initiative.

• Formulate and update privacy policies, data handling protocols, and publicly available privacy notices.

• Create and maintain the security assurance plan while assessing security controls.

• Enhance third-party information security assurance and ongoing assessment procedures.

• Identify risk areas and facilitate evaluations and testing of security controls.

• Review architectural designs and new projects for security alignment and risk mitigation.

• Support and manage Data Protection Impact Assessments.

• Oversee and coordinate ISO 27001 and SOC 2 Type II internal and external audits.

• Analyze and compile compliance documentation and supporting evidence.

• Coordinate the resolution of audit findings and ensure they are tracked to completion.

• Aid in responding to Data Subject Access Requests.

• Communicate with third parties and suppliers to perform risk assessments, review security postures, and manage issue resolution.

• Report to the GRC Lead within the Information Security department.


⛳️ Requirements

• Over 7 years of demonstrated experience in a GRC, IT Audit, Security Assurance, or Information Security role.

• Bachelor’s Degree in a relevant discipline or equivalent professional experience.

• Professional certifications such as CIPP/E, CIPP/US, CIPT, CISA, CISM, CRISC, or CISSP are strongly preferred.

• Direct experience in highly regulated sectors, such as financial services or healthcare.

• Proven experience managing or supporting formal audit and certification processes from inception to conclusion.

• Extensive knowledge of security and privacy frameworks, including ISO 27001, ISO 27701, SOC 2 Type II, HITRUST, and NIST CSF.

• Strong understanding of global privacy and healthcare regulations, including GDPR and HIPAA.

• Familiarity with AI regulations, frameworks, and standards, such as the EU AI Act and ISO 42001.

• Working knowledge of business continuity, disaster recovery, and incident response planning.

• Practical experience with contemporary GRC management tools, preferably Drata.

• Excellent communication and presentation abilities.

• Strong stakeholder management capabilities.

• Proficient project management skills with the capacity to manage multiple audits and assessments concurrently.

• Analytical mindset with the ability to balance regulatory demands with business goals.


🏝️ Benefits

• Flexible remote and hybrid work arrangements.

• Competitive salary with a variable component linked to personal and company performance.

• Numerous Learning and Development opportunities, including Focus Fridays, a half-day each month dedicated to learning and personal growth.

• Generous paid time off (PTO) and holidays.

• Mental health benefits.

• Two MAD Days per year (Make A Difference Days for paid volunteering).

• Additional benefits may be available by country, depending on your eligibility.

People also viewed

The Baldwin Group6 hours ago

Risk Engineer

US flagUnited States OnlyFull-timeRisk
ApplyView job
Aegea Saneamento7 hours ago

Junior Risk and Internal Controls Analyst – Focus on Data Privacy and LGPD

BR flagBrazil OnlyFull-timeRisk
ApplyView job
Flex8 hours ago

Risk Analyst

US flagCalifornia, +2 more statesFull-timeRisk$120k – $145k/year
ApplyView job
Allstate9 hours ago

Large Loss Risk Adjuster

US flagAlabama, +41 more statesFull-timeRisk$85k – $145.1k/year
ApplyView job
Shelter Insurance Companies9 hours ago

Catastrophe Risk Modeler

US flagMissouri OnlyFull-timeRisk$69.3k – $88.6k/year
ApplyView job
Relation Insurance Services12 hours ago

Sales Coordinator, Risk Strategy

US flagOklahoma OnlyFull-timeRisk$25 – $34/hour
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers