About this role
The team is seeking a highly skilled and motivated Senior Governance, Risk, and Compliance (GRC) Analyst to join their Security and Privacy team. In this role, you will own and grow the GRC program, maintaining the control framework, leading risk assessments, supporting audits, and driving the program's maturity forward. You will report directly to the CISO and have significant ownership from day one.
Key Responsibilities:
- Lead the GRC program across SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, including audit preparation and evidence collection.
- Manage and mature the control framework, mapping new regulations and conducting gap assessments.
- Own the annual security risk assessment process, including stakeholder interviews, risk scoring, and residual risk tracking.
- Maintain and update security policies, standards, and documentation to ensure compliance with industry best practices.
- Partner with Engineering and Security to enhance vulnerability management and secrets-scanning practices.
- Help build and operationalize a Data Loss Prevention (DLP) program across email, endpoint, and cloud storage.
- Grow and mature the security awareness training program.
- Drive AI governance efforts, including policy, tooling, and monitoring for AI tool usage.
- Identify and close Shadow IT visibility gaps in partnership with IT.
- Collaborate with cross-functional teams to implement risk management practices and ensure compliance.
- Respond to security and privacy inquiries from clients, partners, and employees.
- Prepare and present reports on the organization's security and privacy compliance status.
- Stay updated on emerging security threats, vulnerabilities, and compliance requirements.
Qualifications:
- Bachelor's degree in Technology, Cybersecurity, or a related field is highly desirable.
- 6+ years of proven experience in GRC, IT audit, information security compliance, or a related field.
- In-depth knowledge of relevant regulations, standards, and frameworks (e.g., SOC 2, ISO 27001, PCI DSS, NIST 800-series, GDPR).
- Experience running or contributing to formal risk assessments.
- Professional certifications such as CISA, CRISC, CISSP, CIPP, or CIPM are highly desirable.
- Familiarity with modern security tooling such as Drata, OneTrust, Vanta, etc.
- Strong analytical and problem-solving skills, with keen attention to detail.
- Excellent communication and interpersonal skills to work effectively with technical and non-technical stakeholders.
- Ability to manage multiple projects and meet deadlines in a fast-paced environment.
- Experience with cloud security and compliance frameworks is a plus.
- Experience with OneTrust or related GRC technologies is a plus.
Personal Characteristics:
- Strong work ethic and commitment to excellence.
- Ability to work independently and as part of a team.
- Excellent problem-solving and analytical skills.
- Strong communication and interpersonal skills.
- Ability to adapt to change and learn quickly.
- Passion for security and privacy.
What we offer:
The team provides a dynamic work environment with opportunities to impact large-scale events globally. They offer competitive benefits, generous PTO, and a culture focused on teamwork and innovation. Join a team that is dedicated to excellence and making a difference in the industry.