CareerPlanSign in

Senior Governance Risk and Compliance Analyst

Orem, UT💼 Full-time🗓 2026-08-22 → 2026-09-26

Core

Own and grow the company's governance, risk, and compliance program, leading risk assessments, supporting audits, and driving program maturity for a security and privacy team.

Role type

Senior GRC Analyst (Security & Privacy)

Builds

Control frameworks, risk assessment processes, compliance documentation, and security awareness training.

Domain

Cybersecurity, Compliance, Risk Management

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

GRC program ownership, risk assessment (NIST SP 800-30), audit preparation, regulatory mapping, policy management, DLP program design, AI governance, Shadow IT identification, cross-functional collaboration, compliance reporting

Preferred skills

Cloud security compliance, GRC tooling (Drata, OneTrust, Vanta)

Technologies

SOC 2, ISO 27001, PCI DSS, NIST 800-series, GDPR, Drata, OneTrust, Vanta

Responsibilities

Lead GRC program across SOC 2, ISO 27001, PCI DSS, and other frameworks; Manage and mature control framework; Own annual security risk assessment; Maintain security policies and standards; Partner with Engineering to mature vulnerability management; Build and operationalize DLP program; Grow security awareness training; Drive AI governance efforts; Identify and close Shadow IT gaps; Collaborate on risk management practices; Respond to security inquiries; Prepare compliance status reports

Seniority

Senior, hands-on IC

Sourced via remoteok · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.