All roles

Security Compliance Analyst, GRC

Remote · USA Full-time New today

Job Description:

  • Support and maintain security and compliance programs aligned with frameworks such as NIST, ISO, PCI DSS, and HIPAA
  • Assist in maintaining alignment with global privacy regulations (GDPR, CCPA, and similar frameworks)
  • Assist in the development, implementation, and maintenance of security, privacy, and AI governance policies, standards, and procedures
  • Coordinate and support internal and external audits (e.g., SOX, PCI DSS, SOC 2, ISO, HIPAA)
  • Track and manage remediation efforts for identified risks, control gaps, and audit findings
  • Support third-party risk management processes, including vendor assessments for AI/ML and data processing providers
  • Partner with engineering, data, and AI/ML teams to ensure secure and compliant system and model lifecycle practices
  • Maintain and improve GRC tooling (e.g., AuditBoard, Vanta, or similar platforms)
  • Monitor regulatory and framework changes (U.S. and international), including emerging AI governance requirements
  • Develop and maintain risk registers, control matrices, and compliance documentation
  • Conduct risk assessments, including technology, security, privacy, and AI/ML model risk evaluations
  • Assist with security, privacy, and responsible AI awareness and training initiatives
  • Provide reporting and metrics on risk posture, compliance status, and AI governance maturity

Requirements:

  • Bachelor’s degree in Cybersecurity, Information Security, Information Technology/Systems, or related field
  • 3–5 years of experience in GRC, security compliance, risk management, audit, or related field
  • Experience supporting audits and compliance assessments
  • Experience with third-party/vendor risk management
  • Familiarity with data governance principles (classification, retention, lineage)
  • Thorough understanding of risk management methodologies and control frameworks
  • Strong communication, documentation, organizational, and analytical skills
  • Ability to communicate security, privacy, and AI risk concepts to technical and non-technical stakeholders
  • Working knowledge of core frameworks: NIST CSF, PCI DSS, HIPAA, ISO 27001/27002, and global privacy regulations (GDPR, CCPA)
  • Foundational understanding of AI/ML systems and associated governance, risk, and compliance considerations (NIST AI RMF, ISO 42001)
  • Familiarity with cloud environments (AWS primary, Google Workspace/MS Azure preferred) and modern SaaS architectures
  • Experience with GRC tools (AuditBoard, Vanta, Drata, Archer, ServiceNow GRC, or similar) and ticketing/workflow/documentation tools (Jira, Freshservice, Confluence, GitHub, etc.)

Benefits:

  • Competitive salary & equity compensation for full-time roles
  • Unlimited PTO, company holidays, and quarterly mental health days
  • Comprehensive health benefits including medical, dental & vision, and parental leave
  • Employee Stock Purchase Program (ESPP)
  • 401k benefits with employer matching contribution
  • Offsite team retreats

Apply tot his job Apply To this Job

Related roles

GRC Technology Financial Services Senior Consultant

Remote · USA Full-time

Senior GRC Specialist

Remote · USA Full-time

Sr GRC Consultant I

Remote · USA Full-time

Principal Consultant, GRC, Proactive Services (Unit 42) – Remote

Remote · USA Full-time

Cyber Security Technical Advisor (GRC), AVP

Remote · USA Full-time

Risk Manager

Remote · USA Full-time

Security GRC Program Manager, Third Party

Remote · USA Full-time

AMER - Future Opportunities at SAI360

Remote · USA Full-time

Compliance Automation Engineer, GRC

Remote · USA Full-time

Security GRC Engineer-CA/NC-Mandarin preferred(full-time, exempt)

Remote · USA Full-time

Virtual Customer Support Representative – Entry Level

Remote · USA Full-time

Seasonal Healthcare Team Lead - Remote

Remote · USA Full-time

Experienced Weekend Part-Time Customer Service Representative – Remote Opportunity with arenaflex

Remote · USA Full-time

Experienced Part-Time Remote Data Entry Specialist – E-commerce Operations and Customer Experience

Remote · USA Full-time

IT Application Owner

Remote · USA Full-time

Research Audiologist

Remote · USA Full-time

Implementation Manager

Remote · USA Full-time

Remote Customer Benefits Representative – Full‑Time, Flexible Schedule, Home‑Based Client Support & Service Excellence

Remote · USA Full-time

Experienced Data Analyst – High-Level Examination, Content Group at arenaflex

Remote · USA Full-time

Customer Sales and Service Representative – Client Experience & Communications Specialist

Remote · USA Full-time