Governance, Risk & Compliance (GRC) Analyst
IVO Inc
Why Join Ivo?
Every civilization runs on the same infrastructure: agreements between people who don't fully trust each other. Sumerians pressed them into clay. Romans carved them into stone. We bury them in 80-page PDFs.
The way those agreements are reviewed hasn't changed in four thousand years - a human reads the whole thing and tries not to miss anything. We're building the AI that finally changes that. Ivo is the contract intelligence platform of choice for companies like Uber, Meta, Canva, IBM, and Shopify. We recently raised our Series B and have grown 800% over the last 12 months.
The Opportunity
Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives. This role will play a key part in maintaining and enhancing Ivo's compliance programs, including SOC 2 Type II, ISO 27001, CSA STAR, and ISO/IEC 42001.
The ideal candidate has experience supporting security audits, managing evidence collection, conducting risk assessments, maintaining policies and procedures, and partnering cross-functionally with engineering, IT, legal, HR, and business stakeholders.
This is a fully onsite role based out of Ivo's San Francisco headquarters to support close cross-functional collaboration with Security, Engineering, IT, and Operations teams.
What You'll Do
- Support and coordinate Ivo's compliance programs including SOC 2 Type II, ISO 27001, CSA STAR, and ISO/IEC 42001.
- Assist with annual audits, surveillance audits, and customer security assessments.
- Coordinate evidence collection and maintain audit readiness across teams.
- Support and maintain Ivo's Vanta GRC platform and associated compliance workflows.
- Monitor automated compliance evidence collection and control monitoring within Vanta.
- Perform vendor and third-party risk assessments.
- Support enterprise risk management and risk register maintenance.
- Maintain and update security policies, standards, and procedures.
- Support AI governance and responsible AI compliance initiatives.
What We're Looking
- 3–5 years of experience in Governance, Risk & Compliance (GRC), Information Security, IT Audit, or related field.
- Hands-on experience supporting SOC 2 Type II, ISO 27001, CSA STAR, and in-depth knowledge of ISO/IEC 42001.
- Experience administering or working extensively with Vanta or similar GRC/compliance automation platforms.
- Experience managing and maintaining a customer-facing Trust Center, including security documentation, compliance artifacts, sub-processor disclosures, and customer assurance materials.
- Strong understanding of information security principles and common security controls.
- Experience with audits, evidence management, and customer security reviews.
- Excellent written and verbal communication skills.
Nice to Haves
- Experience working at a SaaS or AI company.
- Familiarity with GDPR, CCPA, privacy regulations, and third-party risk management.
- Knowledge of cloud environments such as GCP, AWS, or Azure.
- Relevant certifications such as Security+, CISA, CRISC, CCSK, or ISO 27001 Lead Implementer/Auditor.
Ivo Might Be a Good Fit for You If You:
- Would describe yourself as being relentlessly resourceful.
- You have a strong internal sense of urgency. You have a bias towards doing things today, rather than tomorrow.
- Experience working in a startup environment is preferred but not required.
- Are excited about the adventure of building a company!
What We Offer
- Competitive Compensation: Final offer details are determined based on experience, expertise, and overall fit.
- Equity: Meaningful ownership in a company that's scaling fast
- Relocation and Visa Support: We also offer relocation assistance for successful applicants moving to SF, as well as support for visa and green card applications where applicable.
- Health & Wellness: Comprehensive medical, dental, and vision plans to suit the needs of you and your family.
- Flexible Spending & Insurance: Access to HSA and FSA accounts, plus life insurance coverage.
- 401(k) Program: Save for the future with our 401(k) program.
- Commuter Benefits: We help make getting to and from the office easier and more convenient.
- Unlimited PTO: So you can take the time you need to recharge, stay healthy, and bring your best self to work.
- Office Perks: Enjoy a vibrant Downtown San Francisco office with catered lunch five days a week, premium snacks and coffee, an in-building gym, and a dog-friendly environment.
FAQ
- What stage of growth is Ivo at?: We launched in early access in 2023. Since then, we've had an incredible response from the market and are growing rapidly. We 6x'd in ARR in the last 12 months. Our clients include companies like Uber, Reddit, IBM, Canva, Pinterest, WordPress, and more. We're happy to share more details with candidates who go through our interview process.
- Is this a chill gig?: Startups are very hard, especially if they're growing fast. You'll have a ton of responsibility, and there's always an enormous amount of stuff to do. It's hard work but the payoff is uncapped.
- Can I work remotely?: We require candidates to work with us in-person 5 days a week in our San Francisco office.
Ivo is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
$135k - $165k
...foundational to our platform and customer relationships. As we continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk management programs. Role Overview Ivo is seeking a...SuggestedContract workFlexible hours- United States Digital Space LLC in San Francisco seeks a Governance, Risk & Compliance Analyst to mature our security program and manage regulatory obligations, shaping compliance and risk practices to build customer trust in a fast-growing startup transforming search and...Suggested
- Perplexity is seeking a Governance, Risk & Compliance Analyst to shape and run our compliance and risk management program. You will lead the implementation of frameworks, oversee data privacy regulations, and build scalable audit systems in a fast‑growing startup environment...Suggested
$150k - $180k
...knowledge. The Role We’re looking for a GRC Analyst to join our growing Security, IT, and Privacy... .... You’ll be the backbone of all the compliance work at the intersection of Engineering,... ...right person translates security and risk into terms that the business and product...SuggestedFull timeImmediate startRemote workWork from homeFlexible hours- the company is seeking a highly experienced Governance, Risk & Compliance Analyst to join our world-class team. You will help shape our compliance and risk... ...to additional compliance frameworks Build internal GRC platform and tooling Conduct risk assessments and mitigate...Suggested
$140k - $178k
...truth-finding goals. As a GRCT Analyst, you will independently drive moderately complex trust, compliance, and risk workstreams that help... ...Support internal risk and governance processes such as security impact... ...experience with trust portals or GRC tooling. Experience using...Local areaFlexible hoursShift work$153.4k - $191.8k
...often, they stem from gaps in governance, risk management, operational discipline... ..., and accountability. Strong GRC programs help prevent those... ...for an Information Security GRC Analyst to help mature Mercury’s security, risk, and compliance programs. This is not a...- Mercury is seeking an Information Security GRC Analyst to mature security, risk, and compliance programs and build guardrails for business continuity and resilience... ..., CIS, and ISO 27001. The role emphasizes scalable governance and practical controls to enable fast, secure...
$132.6k - $195k
...marketplace of consumers, merchants, and drivers.About the RoleThe Global Governance, Risk, and Compliance (GRC) team is looking for a technical, security-focused Third-Party Risk Management (TPRM) Sr. Analyst. If you are comfortable and have experience working in a fast-paced...Hourly payContract workWork at officeLocal areaRemote workFlexible hours- ...and people to realize their full potential. The Technology Compliance & Emerging Risk Senior Associate will help plan engagements, perform... ...This role strengthens technology compliance, cybersecurity governance, and risk management, including AI and digital transformation...
- ...everything else feel small. Role Scope Run the day-to-day compliance program end to end across SOC 2 Type II, ISO 27001, NIST 800-53... ...collection, control monitoring, and audit readiness held on GRC platforms (Vanta) and the tooling we build in-house. Own the...Local area
$134k - $202k
...our community, or shaping our story, you’ll help define what comes next. About the role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and...Work at officeRemote workWorldwideMonday to Friday$95k - $150k
...Startups. Your Role The Security & Compliance team at Zip is committed to... ...customer requirements. As a GRC Analyst at Zip, you’ll be a key... ...internal audits, and vendor risk assessments Lead... ...’ security, compliance, and governance teams in due diligence and security...Home officeFlexible hours$183k - $205k
...Senior GRC Analyst San Francisco, CA - Hybrid At Gusto, we're on a mission to grow the small business economy. We handle... ...during the interview process. Gusto is seeking a Security, Governance, Risk & Compliance professional to join our team managing our security...Full timeWork at officeLocal area2 days per week3 days per week- Zip is hiring a GRC Analyst to drive compliance programs across SOC 1, SOC 2, ISO 27001, and expanding into the EU and regulated industries. You’ll... ...development. In this fast-growing environment, you’ll lead risk assessments, support due diligence questionnaires, and translate...
$135k - $165k
Icehouseventures is seeking a proactive GRC Analyst to join our team in San Francisco. This role will support compliance and risk management initiatives essential for maintaining high security standards. The ideal candidate will have 3-5 years of experience in GRC and relevant...Contract work- Fluidstack is seeking a Security Compliance Lead in San Francisco to own end-to-end controls across SOC 2 Type II, ISO 27001, NIST 800-53, and FedRAMP, building a scalable program for global sites. You will collaborate with engineering and operations to gather evidence...
- Salesforce.com, inc. is seeking a detail-oriented Security GRC Analyst to join their Security and Compliance team. In this role, you will lead the Unified Audit program ensuring compliance across various frameworks like SOC 2 and HIPAA, while managing evidence collection...
- Anthropic is seeking a Senior Third Party Risk Manager to lead the top tier of vendor risk, including mission-critical compute, data center, and data-pipeline partners. You will shape risk assessments, escalation, and remediation across security, privacy, and operations...Work at officeVisa sponsorship
- Ivo is looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst in San Francisco. The ideal candidate will support compliance programs such as SOC 2 Type II and ISO 27001 while managing audits and risk assessments. This onsite role offers a competitive...
- Vercel in San Francisco is seeking a GRC Analyst to join our Governance, Risk & Compliance team. You will manage and maintain ongoing compliance with security and privacy frameworks, policies, and audits including ISO 27001, SOC 2, HIPAA, and PCI DSS. You will collaborate...Remote jobWork at office
- Early Warning is seeking a Sr. Risk Analyst to support the Enterprise Risk Management program. You... ...senior management in Product Development, Legal/Compliance, IT, and Finance. A strong background in risk, analytics, and governance is essential. You will contribute to risk...
- Baker Tilly Public Sector Internal Audit & Risk Senior Consultant in the San Francisco region offers a dynamic, client‑facing role... ...advisory firm. You will assess risks, strengthen controls and support governance improvements for government and public sector clients. The role...Remote job
- Runway is seeking a senior GRC professional to design and manage governance, risk, and compliance programs across our US operations, with remote flexibility. You will lead external audits, maintain certifications (SOC 2, ISO 27001/27701/42001, FedRAMP), oversee GDPR/CCPA...Remote work
$117.2k - $176.7k
...Francisco, CAThe Senior Security GRC Analyst role is part of our... ...alike, you will help ensure compliance programs run smoothly and certifications... ...program status and risk areas to leadership.Manage internal... ...years of experience in GRC (Governance, Risk, and Compliance),...Full timeWork at office$118.68k - $175.8k
...is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.Team:The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information...Work experience placementWork at officeLocal area- SmithRx is seeking a Compliance Analyst to help implement a robust compliance program in a dynamic PBM regulatory landscape. You will remediate non-compliance and support policy and procedure adherence across the organization. You will work with the Corporate Compliance...Remote jobFull timeHome office
- The California Public Utilities Commission is seeking an Analyst I to support enterprise risk management, risk and compliance, and division operations under the Program and Project Supervisor. The role involves research, analysis, report preparation, and workflow development...
- You.com is looking for a GRC Analyst to join our Security, IT, and Privacy function in San Francisco... ...be crucial in building and maintaining compliance programs and ensuring trust with our... ...frameworks and conducting vendor risk assessments. The ideal candidate has 3-5...
- We are looking for a Sr. Compliance Analyst to support marketing and customer communication review activities for financial products in San Francisco... ...on evaluating promotional content, identifying regulatory risk, and advising cross-functional teams on compliant campaign...Long term contract
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance, Risk & Compliance (GRC) Analyst. Be the first to apply!
- risk consultant San Francisco, CA
- risk compliance officer San Francisco, CA
- risk analyst San Francisco, CA
- governance risk & compliance analyst San Francisco, CA
- senior quantitative risk analyst San Francisco, CA
- operational risk consultant San Francisco, CA
- it risk analyst San Francisco, CA
- risk officer San Francisco, CA
- third party risk analyst San Francisco, CA
- transaction risk analyst San Francisco, CA

