
Senior GRC Analyst
Posted 6 hours ago

Posted 6 hours ago
This is a fully remote position, open to applicants in United States, +2 more locations.
• Design, uphold, and evaluate Shift’s comprehensive security and privacy management framework.
• Ensure adherence to critical industry standards.
• Conduct risk assessments.
• Manage the third-party security assurance program.
• Assist TrustOps initiatives related to customer materials, inquiries, contract evaluations, and due diligence.
• Convert global information security requirements into implementable policies, standards, and procedures.
• Advocate for security and compliance throughout the organization and serve as a subject matter expert.
• Contribute to the security awareness initiative.
• Formulate and update privacy policies, data handling protocols, and publicly available privacy notices.
• Create and maintain the security assurance plan while assessing security controls.
• Enhance third-party information security assurance and ongoing assessment procedures.
• Identify risk areas and facilitate evaluations and testing of security controls.
• Review architectural designs and new projects for security alignment and risk mitigation.
• Support and manage Data Protection Impact Assessments.
• Oversee and coordinate ISO 27001 and SOC 2 Type II internal and external audits.
• Analyze and compile compliance documentation and supporting evidence.
• Coordinate the resolution of audit findings and ensure they are tracked to completion.
• Aid in responding to Data Subject Access Requests.
• Communicate with third parties and suppliers to perform risk assessments, review security postures, and manage issue resolution.
• Report to the GRC Lead within the Information Security department.
• Over 7 years of demonstrated experience in a GRC, IT Audit, Security Assurance, or Information Security role.
• Bachelor’s Degree in a relevant discipline or equivalent professional experience.
• Professional certifications such as CIPP/E, CIPP/US, CIPT, CISA, CISM, CRISC, or CISSP are strongly preferred.
• Direct experience in highly regulated sectors, such as financial services or healthcare.
• Proven experience managing or supporting formal audit and certification processes from inception to conclusion.
• Extensive knowledge of security and privacy frameworks, including ISO 27001, ISO 27701, SOC 2 Type II, HITRUST, and NIST CSF.
• Strong understanding of global privacy and healthcare regulations, including GDPR and HIPAA.
• Familiarity with AI regulations, frameworks, and standards, such as the EU AI Act and ISO 42001.
• Working knowledge of business continuity, disaster recovery, and incident response planning.
• Practical experience with contemporary GRC management tools, preferably Drata.
• Excellent communication and presentation abilities.
• Strong stakeholder management capabilities.
• Proficient project management skills with the capacity to manage multiple audits and assessments concurrently.
• Analytical mindset with the ability to balance regulatory demands with business goals.
• Flexible remote and hybrid work arrangements.
• Competitive salary with a variable component linked to personal and company performance.
• Numerous Learning and Development opportunities, including Focus Fridays, a half-day each month dedicated to learning and personal growth.
• Generous paid time off (PTO) and holidays.
• Mental health benefits.
• Two MAD Days per year (Make A Difference Days for paid volunteering).
• Additional benefits may be available by country, depending on your eligibility.
The Baldwin Group
Aegea Saneamento
Allstate
Get handpicked remote jobs straight to your inbox weekly.