Назад
Company hidden
6 часов назад

Security Governance Risk & Compliance Analyst I (Cybersecurity)

49 729 - 73 130$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Governance Risk & Compliance Analyst I (Cybersecurity): Supporting third-party risk assessments, control testing, audit coordination, policy documentation, and risk tracking for enterprise compliance programs with an accent on vendor due diligence, evidence collection, and frameworks such as SOC 2, ISO 27001, and PCI-DSS. Focus on applying AI coding tools like Claude Code to cybersecurity and GRC work, maintaining accurate risk records, and preparing compliance reporting.

Location: US - Remote

Salary: $49,729.00–$73,130.00 per year

Company

hirify.global is part of Commerce, an AI-driven commerce ecosystem that connects tools and systems supporting business growth and data-driven customer experiences.

What you will do

  • Review vendor security questionnaires, documentation, and due diligence materials for third-party risk assessments.
  • Maintain the vendor risk register and track remediation activities through closure.
  • Assist with internal control testing and collect evidence for SOC 2, ISO 27001, PCI-DSS, and related compliance frameworks.
  • Coordinate audit requests and work with internal stakeholders and external vendors to gather documentation.
  • Monitor policy and procedure reviews, track risk exceptions, and escalate items requiring senior review.
  • Prepare risk reporting and metrics for leadership and committee-level reviews while contributing to process improvements.

Requirements

  • 0–2 years of experience in GRC, risk operations, compliance, or a related function; internships count.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Business, or a related field, or equivalent work experience.
  • Genuine interest in GRC engineering and willingness to learn quickly.
  • Hands-on familiarity with Claude Code or similar AI coding tools and the ability to consider their use in cybersecurity or GRC work.
  • Strong written and verbal communication skills, attention to detail, and comfort with documentation, spreadsheets, and tracking tools.
  • Proficiency in Microsoft Office or Google Workspace.

Nice to have

  • Cybersecurity or risk management coursework or certifications such as Security+ or CISA.
  • Exposure to NIST or compliance frameworks such as SOC 2, ISO 27001, or PCI-DSS.
  • Experience in an operations or process-driven role.

Culture & Benefits

  • Work with a senior, globally distributed Governance, Risk & Compliance team.
  • Growth and learning support from the beginning of the role.
  • Inclusive and accessible hiring experience with accommodations available during recruitment.
  • Potential eligibility for variable compensation, equity, and benefits according to local policies.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →