Назад
Company hidden
5 дней назад

GRC Analyst (AI)

108 000 - 125 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Analyst (AI): Operating and improving governance, risk, and compliance programs across SOX, SOC 2, PCI DSS, NIST, and privacy frameworks with an accent on audit readiness, control testing, vendor risk, and compliance reporting. Focus on automating GRC workflows, building continuous compliance monitoring, evaluating security controls, and coordinating remediation with technical and business teams.

Location: New York City; hybrid work from the NYC office 3 days per week

Cash compensation: $108,000–$125,000 USD per year

Company

hirify.global is a design-driven platform providing websites, domains, ecommerce, marketing, scheduling, and social media products to millions of customers in more than 200 countries and territories.

What you will do

  • Lead and support SOX, SOC, PCI, and NIST audits from scoping through reporting.
  • Maintain audit-ready documentation, evaluate control design and operating effectiveness, and track findings through closure.
  • Manage security risk assessments, exception records, vendor security reviews, and third-party remediation.
  • Coordinate responses to customer security questionnaires and partner assessments.
  • Support privacy audits covering GDPR, CCPA/CPRA, data retention, deletion, access rights, and third-party processing.
  • Improve GRC operations through automation, integrations, AI-enabled workflows, and continuous compliance monitoring.

Requirements

  • 3+ years of experience in GRC, IT audit, security compliance, or privacy compliance.
  • Experience managing audit activities end to end across SOX, SOC 1/2, PCI, NIST, or ISO frameworks.
  • Experience with IT control evaluation, control testing, issue management, and reporting.
  • Experience supporting vendor risk programs and reviewing independent assurance reports.
  • Working knowledge of SaaS and cloud environments.
  • Experience using GRC or workflow platforms to maintain records and drive repeatable processes.

Nice to have

  • Experience building GRC automation, continuous control monitoring, or compliance dashboards.
  • Familiarity with privacy engineering and privacy-by-design practices.

Culture & Benefits

  • Collaborative, detail-oriented Security organization working with Engineering, Legal, Finance, Product, and external auditors.
  • Medical plan options, including an option for fully covered premiums, plus supplemental insurance.
  • Flexible paid time off, 12 weeks of paid parental leave, and family care leave.
  • Retirement benefits with employer match, education reimbursement, and commuter benefits.
  • Employee assistance, mindfulness subscription, employee resource groups, donation matching, and a dog-friendly workplace.
  • Free lunch and snacks, private rooftop access, and hack week twice per year.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →