13 часов назад
Senior Governance, Risk, and Compliance (GRC) Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Governance, Risk, and Compliance (GRC) Analyst (Cybersecurity) (SOC 2/ISO 27001): Owning and advancing RainFocus's governance, risk, and compliance program through control framework management, formal risk assessments, audit support, and regulatory compliance with an accent on security, privacy, and program maturity. Focus on leading risk assessments, mapping controls to frameworks such as SOC 2, ISO 27001, PCI DSS, NIST, and GDPR, and improving cloud compliance processes.
Location: Remote, United States; listed location: Orem, Utah
Company
is hiring for its Research & Development – Technology organization and Security and Privacy team.
What you will do
- Own and grow the governance, risk, and compliance program.
- Maintain and improve the control framework.
- Lead formal risk assessments and drive risk management activities.
- Support audits and compliance initiatives.
- Advance the maturity of the security and privacy program.
- Report directly to the CISO and work with technical and non-technical stakeholders.
Requirements
- 6+ years of experience in GRC, IT audit, information security compliance, or a related field.
- Bachelor's degree in Technology, Cybersecurity, or a related field is highly desirable.
- In-depth knowledge of SOC 2, ISO 27001, PCI DSS, NIST 800-series, GDPR, and related regulations, standards, and frameworks.
- Experience conducting or substantially contributing to formal risk assessments.
- Strong analytical, problem-solving, communication, and interpersonal skills.
- Ability to manage multiple projects, meet deadlines, work independently, and collaborate effectively.
Nice to have
- Professional certification such as CISA, CRISC, CISSP, CIPP, or CIPM.
- Familiarity with Drata, OneTrust, Vanta, or related GRC tooling.
- Experience with cloud security and compliance frameworks.
- Experience with OneTrust or related GRC technologies.
Culture & Benefits
- Full-time remote workplace.
- Significant ownership and responsibility from the start.
- Fast-paced environment with opportunities to adapt and learn.
- Focus on security, privacy, quality, and continuous improvement.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
Senior Risk Management / GRC Manager (Fintech)
3 дня назад
Senior GRC Manager (Cybersecurity)
2 дня назад
Senior Analyst, Third-Party Risk Management (TPRM) (AI)
132 600 - 195 000$
CrowdStrike
7 дней назад
Manager, Third Party Risk Management (Cybersecurity)
125 000 - 180 000$
CrowdStrike
7 дней назад
Third Party Risk Management (TPRM) Analyst (Cybersecurity)
85 000 - 120 000$
6 дней назад