Назад
Company hidden
17 часов назад

Senior GRC Analyst (SaaS)

183 000 - 205 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior GRC Analyst (SaaS): Managing security governance, risk, and compliance initiatives for a SaaS platform with an accent on SOC 2 Type 2, data governance, vendor risk, and AI-enabled control automation. Focus on assessing control gaps, coordinating remediation, leading auditor interactions, and building scalable GRC processes across the organization.

Location: San Francisco, CA — hybrid, with approximately 2–3 days per week in the office. San Francisco office expectations cover the San Francisco and San Jose metro areas.

Cash compensation: $183,000–$205,000 annually in the San Francisco Bay Area, plus stock equity.

Company

hirify.global provides payroll, health insurance, 401(k), and HR solutions for more than 500,000 small businesses.

What you will do

  • Develop and maintain security and compliance SOPs, internal documentation, and company-wide policies supporting SOC 2 and future frameworks.
  • Manage trust platforms covering controls, risks, vendors, and exceptions, and implement AI agents to automate control execution and evidence collection.
  • Establish data governance policies for classification, retention, and handling with Legal, Enterprise Applications, and other stakeholders.
  • Conduct internal risk assessments, identify control gaps, and coordinate remediation plans with functional teams.
  • Manage third-party vendor risk reviews, including onboarding, monitoring, and renewals.
  • Lead external auditor and regulatory interactions, client security assessments, and cross-functional GRC enablement.

Requirements

  • 8+ years of governance, risk, and compliance experience within SaaS; HCM, payroll, or fintech experience is preferred.
  • Bachelor’s degree in Business, Information Systems, or a related field.
  • Experience implementing controls and policies in fast-paced, product-driven SaaS environments.
  • Experience leading or supporting a SOC 2 Type 2 compliance initiative and collaborating with auditors and cross-functional teams.
  • Familiarity with Optro, Vanta, Drata, Viso Trust, or similar compliance platforms.
  • Strong communication, stakeholder influence, process design, and data analysis skills, plus a relevant professional certification.

Nice to have

  • CISA, CRISC, or GRCP certification.
  • CGEIT, CRMA, or PMI-RMP certification.

Culture & Benefits

  • Full-time employees receive competitive base pay, benefits, and RSU equity.
  • Employees in Denver, San Francisco, and New York work from the office on designated days approximately 2–3 days per week or more depending on the role.
  • Approved non-office work requires a secure, reliable, and consistent internet connection.
  • AI tools are an expected part of work, with role-specific AI fluency developed over time.
  • Cross-functional work supports security-minded practices and employee GRC enablement.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →