Назад
Company hidden
4 дня назад

GRC Analyst (Cloud Security)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Analyst (Cloud Security): Operating and improving security compliance programs across SOC 2, ISO 27001, NIST, and FedRAMP with an accent on risk assessments, audit readiness, evidence management, and remediation. Focus on translating requirements into sustainable controls, coordinating cross-functional compliance work, and using AI and automation to scale GRC workflows.

Location: US (Remote)

Company

hirify.global provides a cloud security platform that uses runtime context and eBPF-powered sensors for cloud posture discovery, threat protection, and API security.

What you will do

  • Operate and improve GRC and security compliance programs.
  • Support SOC 2, ISO 27001, NIST, and FedRAMP activities, including control implementation, evidence collection, remediation tracking, continuous monitoring, and audit readiness.
  • Coordinate audit evidence across Engineering, IT, Security, Legal, and HR.
  • Perform control, gap, and risk assessments and translate findings into practical remediation plans.
  • Manage customer security questionnaires, third-party risk assessments, policies, standards, risk registers, and GRC repositories.
  • Use AI and automation to improve research, documentation, evidence organization, and compliance workflows with appropriate validation.

Requirements

  • 3–5 years of experience in GRC, cybersecurity, risk management, compliance, or audit.
  • Familiarity with NIST 800-53, SOC 2, ISO 27001, NIST CSF, or similar frameworks.
  • Experience supporting audits, assessments, security questionnaires, or evidence collection.
  • Strong written communication and documentation skills, with enough technical fluency to work with Engineering, IT, and Security.
  • Ability to turn audit findings into remediation plans and drive assigned work to completion.
  • Experience using technology to improve GRC work, including risk analysis, control monitoring, remediation tracking, or workflow automation.

Nice to have

  • FedRAMP, NIST 800-53, or U.S. government compliance experience.
  • Cloud security experience, particularly with AWS or AWS GovCloud.
  • Experience with SaaS, cloud security, high-growth technology companies, or distributed workforces.
  • Experience with GRC automation platforms, AI-enabled workflows, integrations, or dashboards.
  • Security+, CISA, CRISC, CISM, CGRC, or ISO 27001 certification.

Culture & Benefits

  • Hands-on work in a fast-paced environment with continuously evolving processes.
  • Cross-functional collaboration with Engineering, IT, Security, Legal, and HR.
  • Emphasis on ownership, curiosity, practical problem-solving, and sustainable remediation.
  • Use of modern cloud-based security, compliance, automation, and AI-enabled tools.

Hiring process

  • Apply by email at people@hirify.global.io.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →