Senior GRC Analyst
Core
Guide GRC maturity from foundational to steady-state, leveraging AI to automate controls and evidence collection while ensuring SOC 2 Type 2 and IT General Controls compliance.
Role type
Senior GRC Analyst (SaaS/HCM)
Builds
Automated GRC processes, control frameworks, and compliance evidence for SOC 2 and related standards
Domain
SaaS, HCM, Payroll, Fintech
Deliverable
production ML models | dashboards & analysis | client delivery
Required skills
GRC framework expertise, SOC 2 Type 2 implementation, vendor risk management, internal risk assessment, data governance policy creation, cross-functional collaboration, regulatory adaptability, process automation, stakeholder enablement
Preferred skills
CISA, CRISC, GRCP, CGEIT, CRMA, PMI-RMP
Technologies
Optro, Vanta, Drata, Viso Trust
Responsibilities
Develop and maintain security/compliance SOPs and policies; manage trust platforms and lead AI agent implementation for automation; collaborate on data governance policies; conduct internal risk assessments and coordinate remediation; manage third-party vendor risk program; lead interactions with external auditors and regulatory bodies; stay current on compliance frameworks; partner cross-functionally to implement scalable GRC processes
Seniority
Senior, hands-on IC