GRC Analyst
$95,000–$150,000 year
RemoteUnited States or San Francisco, California, United States
Job Summary
Drive and perform periodic compliance-related activities, including user access reviews, internal audits, and vendor risk assessments. Lead conversations with customers' security, compliance, and governance teams for due diligence and security questionnaires. Guide internal control owners to operationalize controls and collaborate with auditors to support third-party audits for SOC 1, SOC 2, and ISO 27001 certifications. Develop and maintain security policies, standards, and guidelines to ensure adherence to regulatory requirements while supporting new certifications for AI products and EU market entry.
Required Qualifications
- Bachelor's degree in a related field
- 2+ years of experience in GRC, information security consulting, cybersecurity risk, audits, or similar roles
- Strong written and verbal communication skills with both technical and non-technical stakeholders
- Familiarity with and participation in one or more of the following frameworks: SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
- Familiarity with information security fundamentals for cloud software systems
Desired Qualifications
- Professional certifications in information security
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.