Associate GRC Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Associate GRC Analyst (GRC): Supporting risk assessments, compliance activities, policy management, control monitoring, and BC/DR efforts with an accent on audit readiness and evidence tracking. Focus on modernizing the GRC program by streamlining processes and contributing to automation using scripts, APIs, or compliance platform integrations.
Location: Cambridge or Concord, MA office (required 3 days per week)
Salary: $85,000 - 95,000 (base, not inclusive of annual bonus)
Company
is a travel search engine and part of Booking Holdings, operating a portfolio of global metasearch brands.
What you will do
- Execute risk assessments by identifying, documenting, and tracking risks across business and technology areas.
- Maintain and update security/compliance policies, standards, and procedures aligned with NIST CSF, SOC 2, PCI DSS, and GDPR.
- Coordinate internal and external audits by gathering evidence, tracking findings, and following up on remediation.
- Support control testing and monitoring to verify controls work as intended; maintain the risk register and risk treatment tracking.
- Assist with customer-facing security reviews, including security questionnaires and due diligence documentation.
- Develop, maintain, and test Business Continuity and Disaster Recovery plans, including BIAs and recovery strategies; contribute to GRC process automation.
Requirements
- Work from the Cambridge or Concord, MA office 3 days per week.
- Bachelor’s degree in a relevant field (cybersecurity, information systems, computer science, risk management, or business) or equivalent practical experience.
- Foundational understanding of GRC concepts: risk management, controls, compliance frameworks, and audit processes.
- Basic familiarity with Business Continuity and Disaster Recovery concepts (BIAs, RTO, RPO).
- Familiarity with at least one major security/compliance framework (NIST CSF, SOC 2, or PCI DSS).
- Strong written and verbal communication skills and the ability to manage multiple priorities.
Nice to have
- Interest in treating GRC processes as code (automation, APIs, engineering approaches to scale compliance work).
- Experience with a compliance or business continuity platform such as Drata or RiskConnect.
Culture & Benefits
- Work from (almost) anywhere for up to 20 days per year.
- Company-paid therapy sessions via SpringHealth and a HeadSpace subscription.
- Company-wide week off once a year and no meeting Fridays.
- Paid parental leave, generous paid vacation, and time off for your birthday.
- Development Dollars, leadership development, and access to on-demand e-learning.
- Competitive retirement and health plans, free lunch 2 days per week, and paid volunteer time.
Hiring process
- Interview and application evaluation focused on GRC fundamentals, communication, and organizational skills.
- Role-specific discussions around risk/compliance experience and interest in GRC modernization.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →