TL;DR
Governance & Compliance Analyst (GRC): Manage and enhance third-party risk management and security compliance programs with an accent on vendor risk assessments, audit delivery, and cross-functional collaboration. Focus on executing risk assessments, improving control design, and maintaining compliance with frameworks such as SOC 2, ISO, and NIST.
Location: Remote - USA only, must have legal right to work in the US without visa sponsorship
Salary: $98,000–$135,000 USD annually
Company
hirify.global is a fast-growing cloud security startup trusted by over 50% of the Fortune 100, focused on securing cloud environments globally.
What you will do
- Manage and execute third-party risk assessments to evaluate vendor security maturity and risk.
- Collaborate cross-functionally with Procurement, Security, Legal, and other teams to deliver security compliance programs.
- Document and track third-party risk findings and perform ongoing monitoring.
- Stay updated on security and regulatory trends to identify new risk areas.
- Continuously improve audit and compliance management processes and tools.
- Deliver timely audits such as SOC 2, ISO, and PCI by working with internal and external auditors.
Requirements
- Must have legal right to work in the US without visa sponsorship.
- 3+ years experience in Governance, Risk, and Compliance.
- Knowledge of security and compliance frameworks like NIST, ISO 27001, SOC2, GDPR.
- Ability to collaborate with technical and non-technical teams.
- Passion for security and maintaining organizational safety.
Nice to have
- Experience in SaaS or tech environments.
- Experience working in global teams.
Culture & Benefits
- Medical, dental, and vision insurance.
- Home office setup and monthly connectivity reimbursements.
- Flexible spending accounts and employee assistance programs.
- 401(k) retirement plan with employer match.
- Flexible paid time off plus 11 paid holidays and various paid leave programs.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →