Staff GRC Analyst

1 month ago
Full-time
Senior
Cybersecurity
Engine.com

Engine.com

Engine.com offers top-notch engine maintenance services for various industries, ensuring peak performance and client satisfaction.

Machinery
1-10

Description

  • Lead configuration and management of GRC tools (Trust Centers, Learning Management Systems, Compliance Tracking, etc.) and ensure integration with security systems.
  • Manage the main dashboard for SOC 2 reporting, ensuring accuracy and compliance.
  • Develop and maintain a comprehensive risk management program and conduct regular risk assessments.
  • Plan, manage, and conduct recurring audits (weekly, monthly, quarterly, and bi-annual) across business, IT, and security processes.
  • Oversee development and execution of security procedures across multiple domains.
  • Develop, update, and maintain contingency planning strategies and procedures, including coordinating annual tabletop drills.
  • Execute routine operational tasks related to security awareness training.
  • Audit third-party vendor and contractor access and compliance.
  • Review procurement requests for security standards and ensure engagements meet company and regulatory requirements.
  • Collaborate cross-functionally to identify and monitor security controls, map controls to issues and risks, and mature audit processes across multiple security frameworks.

Requirements

  • Proven experience managing GRC functions, ideally within a fast-paced, high-growth company.
  • Strong understanding of ISO 27001, SOC 2, GDPR, CCPA, PCI-DSS, and SOX compliance standards.
  • Skilled in using GRC platforms and tools to manage compliance and risk activities.
  • Experience developing and building security/GRC programs across multiple domains.
  • Strong knowledge of security concepts including risk management, identity and access management (IAM), key management, data protection, and network security.
  • Experience with data protection and privacy law compliance.
  • Familiarity with cloud security components of AWS, GCP, or Azure.
  • Ability to manage complex GRC initiatives, work across multiple teams, and handle high-stress IT emergency situations.
  • Excellent organizational, communication, leadership, analytical, and problem-solving skills.
  • Certifications such as CISA, CISM, CISSP, CRISC, or CCEP (preferred).

Benefits

  • Base pay range: $126,480 — $175,000 USD (total compensation may include equity and/or variable pay/OTE).
  • Opportunities for bonuses, commissions, and equity as part of total compensation.
  • Hybrid-hub work model with options for in-office or fully remote work and support to ensure you have what you need to succeed.
  • Perks and benefits vary by employment type and location; full benefits list available on the company's culture page.
  • Competitive benefits package tied to role and experience (details shared by recruiter during process).

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Compliance Analyst - KYB

Binance 5K-10K Capital Markets

Compliance Analyst at Binance in the KYB South East Asia / Asia Legal & Compliance team, working remotely to support corporate onboarding and KYB operations by acting as an escalation point and ensuring compliance through reviews, QA, and process improvements.

Blockchain
1 month ago

BG Risk & Fraud Specialist

Sporty Group 51-250 Media

Risk & Fraud Specialist at Sporty Group responsible for protecting the company and its customers from fraud and financial crime by investigating suspicious activity, analyzing risk patterns, and ensuring KYC and regulatory compliance.

1 month ago

Delegation Oversight Associate

Oscar 1K-5K Insurance

Associate, Delegate Oversight at Oscar joining the Delegation Oversight team to support the enterprise compliance program by executing audit and monitoring activities that ensure adherence to healthcare regulations and internal standards.

HIPAA
1 month ago

Regulatory Associate, Member Documents

Oscar 1K-5K Insurance

Regulatory Associate, Member Documents (EOC) at Oscar, working on the Regulatory Operations team to develop, draft, and format core insurance policy documents for the Individual Plan portfolio to ensure regulatory compliance and operational success.

1 month ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers