Назад
Company hidden
13 часов назад

Senior Governance, Risk, and Compliance (GRC) Analyst (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Governance, Risk, and Compliance (GRC) Analyst (Cybersecurity) (SOC 2/ISO 27001): Owning and advancing RainFocus's governance, risk, and compliance program through control framework management, formal risk assessments, audit support, and regulatory compliance with an accent on security, privacy, and program maturity. Focus on leading risk assessments, mapping controls to frameworks such as SOC 2, ISO 27001, PCI DSS, NIST, and GDPR, and improving cloud compliance processes.

Location: Remote, United States; listed location: Orem, Utah

Company

hirify.global is hiring for its Research & Development – Technology organization and Security and Privacy team.

What you will do

  • Own and grow the governance, risk, and compliance program.
  • Maintain and improve the control framework.
  • Lead formal risk assessments and drive risk management activities.
  • Support audits and compliance initiatives.
  • Advance the maturity of the security and privacy program.
  • Report directly to the CISO and work with technical and non-technical stakeholders.

Requirements

  • 6+ years of experience in GRC, IT audit, information security compliance, or a related field.
  • Bachelor's degree in Technology, Cybersecurity, or a related field is highly desirable.
  • In-depth knowledge of SOC 2, ISO 27001, PCI DSS, NIST 800-series, GDPR, and related regulations, standards, and frameworks.
  • Experience conducting or substantially contributing to formal risk assessments.
  • Strong analytical, problem-solving, communication, and interpersonal skills.
  • Ability to manage multiple projects, meet deadlines, work independently, and collaborate effectively.

Nice to have

  • Professional certification such as CISA, CRISC, CISSP, CIPP, or CIPM.
  • Familiarity with Drata, OneTrust, Vanta, or related GRC tooling.
  • Experience with cloud security and compliance frameworks.
  • Experience with OneTrust or related GRC technologies.

Culture & Benefits

  • Full-time remote workplace.
  • Significant ownership and responsibility from the start.
  • Fast-paced environment with opportunities to adapt and learn.
  • Focus on security, privacy, quality, and continuous improvement.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →