Senior GRC Analyst
Core
Senior GRC Analyst leading enterprise risk management, compliance (SOC 2, ISO 27001), and third-party risk programs for a global EdTech platform.
Role type
Senior IC GRC Analyst (Cybersecurity)
Builds
Scalable governance processes, risk frameworks, and compliance controls for a SaaS platform serving 180 countries.
Domain
EdTech / SaaS / Cybersecurity
Required skills
GRC program management, enterprise risk assessment, third-party risk management, SOC 2 Type 2 implementation, regulatory compliance (GDPR, CCPA, EU AI Act), policy development, cross-functional stakeholder management, GRC automation.
Preferred skills
Cloud security knowledge, AI tool application for GRC workflows, experience with ISO 27001/27701/PCI DSS, hybrid engineering/legal background.
Technologies
SOC 2, ISO 27001, ISO 27701, PCI DSS, GDPR, CCPA, COPPA, EU AI Act, AI automation tools.
Responsibilities
Maintain and improve the risk management framework; lead enterprise risk assessments and track KRIs; manage third-party risk and vendor reviews; develop security, AI, and compliance policies; support SOC 2 and ISO 27001 compliance initiatives; contribute to data privacy and retention policies; coordinate between Cybersecurity, Legal, and Engineering; champion security culture; automate GRC operations using AI tools.
Seniority
Senior, hands-on IC
