Назад
Company hidden
6 дней назад

Senior GRC Analyst

120 000 - 150 000$
Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior GRC Analyst (AI/SaaS): Developing and maintaining integrated security, privacy, risk, and compliance frameworks for an insurance-focused AI SaaS platform with an accent on audit readiness, third-party assurance, and regulatory alignment. Focus on managing ISO 27001 and SOC 2 Type II audits, conducting risk assessments and DPIAs, and evaluating security controls across engineering and business initiatives.

Location: Remote or hybrid in Canada or the United States; available locations include Canada, Toronto, Boston, and US remote. Central or Eastern time zone.

Salary: $120,000–$150,000 USD base salary per year, plus variable compensation and benefits.

Company

hirify.global provides secure, explainable AI agents and SaaS solutions that transform critical work for insurance companies.

What you will do

  • Develop and maintain security, privacy, governance, and compliance policies, standards, and procedures.
  • Manage security assurance plans, control evaluations, risk assessments, and remediation activities.
  • Coordinate internal and external audits for ISO 27001 and SOC 2 Type II certifications.
  • Lead third-party security assurance activities, including supplier assessments and issue remediation.
  • Review architectural designs and new initiatives to identify and mitigate security and privacy risks.
  • Support DPIAs, DSAR responses, customer security questionnaires, contract reviews, and TrustOps activities.

Requirements

  • 7+ years of experience in GRC, IT audit, security assurance, or information security.
  • Bachelor’s degree in a relevant field or equivalent professional experience.
  • Experience delivering work in highly regulated industries such as financial services or healthcare.
  • Experience managing or supporting formal audits and certification processes from start to finish.
  • Deep knowledge of ISO 27001, ISO 27701, SOC 2 Type II, HITRUST, and NIST CSF.
  • Knowledge of GDPR, HIPAA, AI regulations and standards, business continuity, disaster recovery, and incident response planning.

Nice to have

  • Certifications such as CIPP/E, CIPP/US, CIPT, CISA, CISM, CRISC, or CISSP.
  • Hands-on experience with Drata, including integrations, automated evidence collection, monitoring tests, custom controls, and frameworks.

Culture & Benefits

  • Flexible remote and hybrid working options.
  • Competitive base salary, variable compensation tied to individual and company performance, and country-specific benefits.
  • Learning and development opportunities, including a monthly half-day Focus Friday.
  • Generous paid time off and paid holidays.
  • Mental health benefits and two paid volunteering days per year.

Hiring process

  • Initial fit call with a Talent Acquisition Manager.
  • Team fit call with the Hiring Manager followed by a technical interview with the team.
  • Final interview with the CISO.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →