Назад
Company hidden
3 дня назад

IT Risk and Compliance Analyst

80 000 - 90 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
IT Risk and Compliance Analyst (GRC/Privacy): Executing and rebuilding an IT risk and compliance program covering contracts, security questionnaires, control evidence, vendor risk, data retention, privacy, and incident readiness with an accent on SOC 2, ISO 27001, NIST CSF, GDPR, and CCPA obligations. Focus on translating contractual requirements into tracked controls, coordinating remediation, reviewing SaaS and AI vendors, and maintaining evidence, policies, and risk reporting.

Location: Remote within the United States; not available for hire or work in New Mexico, Montana, Alaska, or Hawaii.

Salary: $80,000–$90,000 USD per year.

Company

hirify.global is an independent, human-first AI-native design and technology company that combines AI, people, design, and technology to deliver work for major brands.

What you will do

  • Review MSAs, SOWs, DPAs, security addenda, and contractual security and privacy obligations, coordinating issues and redlines with Legal, IT, and Delivery.
  • Respond to client security questionnaires, due diligence requests, and audit inquiries while maintaining a reusable answer library.
  • Collect control evidence in the GRC platform and track gap remediation against SOC 2, ISO 27001, NIST CSF, and other frameworks.
  • Support SaaS and AI vendor risk assessments, data retention and disposal operations, data mapping, data subject requests, and GDPR and CCPA tracking.
  • Draft and maintain compliance policies, SOPs, process documentation, risk reporting, and the risk register.
  • Support business continuity, disaster recovery, security incident response, security awareness training, internal audits, access reviews, and control testing.

Requirements

  • Bachelor’s degree or equivalent practical experience.
  • 3–5 years of experience in compliance, GRC, contract management, privacy, or a related field.
  • Hands-on experience reviewing commercial contracts, including MSAs, DPAs, or security addenda, and coordinating legal redlines.
  • Experience responding to client security questionnaires or vendor due diligence requests.
  • Working knowledge of at least one major compliance framework: SOC 2, ISO 27001, or NIST CSF.
  • Foundational understanding of GDPR and CCPA, strong organization, concise written communication, and the ability to work independently across parallel initiatives.

Culture & Benefits

  • Remote work within the United States, subject to state availability restrictions.
  • Work in a small team with end-to-end ownership of outcomes.
  • Inclusive, human-first employee experience and equal opportunity workplace.
  • Collaboration with a global network of design and technology experts.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →