2 часа назад
GRC Analyst (AI)
135 000 - 165 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
GRC Analyst (AI): Supporting compliance, risk management, and security assurance programs for an AI-powered contract intelligence platform with an accent on SOC 2 Type II, ISO 27001, CSA STAR, and ISO/IEC 42001. Focus on coordinating audits and evidence collection, maintaining Vanta workflows and security policies, conducting third-party risk assessments, and supporting responsible AI governance.
Location: Fully onsite at 's headquarters in San Francisco, United States. Relocation assistance and visa and green card support are available where applicable.
Salary: $135K–$165K annually.
Company
is an AI contract intelligence platform used by companies including Uber, Meta, Canva, IBM, and Shopify.
What you will do
- Support and coordinate compliance programs including SOC 2 Type II, ISO 27001, CSA STAR, and ISO/IEC 42001.
- Assist with annual and surveillance audits, customer security assessments, and evidence collection.
- Maintain audit readiness, Vanta workflows, automated evidence collection, and control monitoring.
- Conduct vendor and third-party risk assessments and maintain the enterprise risk register.
- Maintain security policies, standards, and procedures.
- Support AI governance and responsible AI compliance initiatives in partnership with Security, Engineering, IT, Legal, HR, and Operations.
Requirements
- 3–5 years of experience in GRC, information security, IT audit, or a related field.
- Hands-on experience supporting SOC 2 Type II, ISO 27001, and CSA STAR, with in-depth knowledge of ISO/IEC 42001.
- Experience administering or extensively using Vanta or a similar GRC and compliance automation platform.
- Experience maintaining a customer-facing Trust Center with security documentation, compliance artifacts, sub-processor disclosures, and customer assurance materials.
- Strong understanding of information security principles, security controls, audits, evidence management, and customer security reviews.
- Excellent written and verbal communication skills.
Nice to have
- Experience at a SaaS or AI company or in a startup environment.
- Familiarity with GDPR, CCPA, privacy regulations, and third-party risk management.
- Knowledge of GCP, AWS, or Azure cloud environments.
- Security+, CISA, CRISC, CCSK, or ISO 27001 Lead Implementer/Auditor certification.
Culture & Benefits
- Fast-growing startup environment with significant responsibility and a strong bias toward action.
- Equity in a rapidly scaling company.
- Medical, dental, and vision plans, plus life insurance.
- HSA and FSA accounts, 401(k), commuter benefits, and unlimited PTO.
- Downtown San Francisco office with catered lunch, snacks, coffee, an in-building gym, and a dog-friendly environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →