17 часов назад
Senior GRC Analyst (SaaS)
183 000 - 205 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior GRC Analyst (SaaS): Managing security governance, risk, and compliance initiatives for a SaaS platform with an accent on SOC 2 Type 2, data governance, vendor risk, and AI-enabled control automation. Focus on assessing control gaps, coordinating remediation, leading auditor interactions, and building scalable GRC processes across the organization.
Location: San Francisco, CA — hybrid, with approximately 2–3 days per week in the office. San Francisco office expectations cover the San Francisco and San Jose metro areas.
Cash compensation: $183,000–$205,000 annually in the San Francisco Bay Area, plus stock equity.
Company
provides payroll, health insurance, 401(k), and HR solutions for more than 500,000 small businesses.
What you will do
- Develop and maintain security and compliance SOPs, internal documentation, and company-wide policies supporting SOC 2 and future frameworks.
- Manage trust platforms covering controls, risks, vendors, and exceptions, and implement AI agents to automate control execution and evidence collection.
- Establish data governance policies for classification, retention, and handling with Legal, Enterprise Applications, and other stakeholders.
- Conduct internal risk assessments, identify control gaps, and coordinate remediation plans with functional teams.
- Manage third-party vendor risk reviews, including onboarding, monitoring, and renewals.
- Lead external auditor and regulatory interactions, client security assessments, and cross-functional GRC enablement.
Requirements
- 8+ years of governance, risk, and compliance experience within SaaS; HCM, payroll, or fintech experience is preferred.
- Bachelor’s degree in Business, Information Systems, or a related field.
- Experience implementing controls and policies in fast-paced, product-driven SaaS environments.
- Experience leading or supporting a SOC 2 Type 2 compliance initiative and collaborating with auditors and cross-functional teams.
- Familiarity with Optro, Vanta, Drata, Viso Trust, or similar compliance platforms.
- Strong communication, stakeholder influence, process design, and data analysis skills, plus a relevant professional certification.
Nice to have
- CISA, CRISC, or GRCP certification.
- CGEIT, CRMA, or PMI-RMP certification.
Culture & Benefits
- Full-time employees receive competitive base pay, benefits, and RSU equity.
- Employees in Denver, San Francisco, and New York work from the office on designated days approximately 2–3 days per week or more depending on the role.
- Approved non-office work requires a secure, reliable, and consistent internet connection.
- AI tools are an expected part of work, with role-specific AI fluency developed over time.
- Cross-functional work supports security-minded practices and employee GRC enablement.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
GRC Engineer (Cybersecurity)
200 000 - 250 000$
21 час назад
Lead Security Analyst (AI Governance)
90 000 - 132 000$
7 дней назад
GRC Analyst (AI)
160 000 - 170 000$
21 час назад
Security Compliance Analyst (Cybersecurity)
130 000 - 160 000$
48 минут назад
Senior GRC Manager (Cybersecurity)
130 000 - 150 000$
Sardine
2 дня назад
Security Compliance Lead (Fintech)
130 000 - 190 000$