Senior GRC Analyst
$130k - $160kBenepass
Location
U.S Remote
Full time Department
Engineering Team & Role
As a Senior GRC Analyst at Benepass, you will help operate and mature the governance, risk, compliance, audit readiness, and customer assurance programs that support our business, customers, and employees. You will work across security policies, internal controls, audit evidence, risk tracking, security questionnaires, and compliance operations. Reporting to the Head of Infosec & GRC, you will be a key individual contributor on a lean security team. You will partner closely with Security, Engineering, IT, People, Legal, Finance, Sales, Customer Success, and Product to make our security and compliance programs clear, practical, and reliable. You are detail-oriented, organized, and pragmatic. You know how to bring structure to ambiguity, communicate clearly with technical and non-technical stakeholders, and balance compliance rigor with the speed of a growing startup. Role Location & Travel
This remote role is based in the United States or Canada. You will be expected to attend company-wide on-site events three to four times per year, as well as occasional on-site office travel as necessary. What Youll Do Governance & Policy: Maintain and improve information security policies, standards, procedures, control documentation, and related governance materials. Control Mapping: Help map policies and controls to frameworks such as SOC 2, ISO 27001/27002, HITRUST, NIST CSF 2.0, and other customer, regulatory, or security requirements. Policy Operations: Support policy exceptions, risk acceptances, remediation tracking, control owner follow-ups, and recurring governance workflows. Compliance & Audit Readiness: Support SOC 2, ISO 27001, and HITRUST readiness, audit preparation, evidence collection, auditor coordination, and audit response management. Control Testing: Maintain recurring evidence-gathering and control testing workflows, helping ensure controls operate consistently across the business. Findings & Remediation: Track audit findings, control gaps, remediation plans, owners, due dates, and closure evidence. Risk Management: Support risk assessments, control gap assessments, internal reviews, and maintenance of the risk register. Business Communication: Translate technical and security risks into clear business language, including mitigations, ownership, timelines, and residual risk. Customer Assurance: Own or support customer security questionnaires, RFP security sections, due diligence requests, and trust or compliance documentation. Response Libraries: Maintain reusable questionnaire content, approved responses, compliance artifacts, and customer-facing assurance materials. Security Awareness: Support employee security awareness programs and create clear internal guidance for policies, controls, and compliance responsibilities. Vendor Risk: Support vendor security reviews, third-party risk assessments, remediation tracking, risk acceptance documentation, and vendor compliance evidence. Tooling & Process Improvement: Use GRC platforms such as Vanta, Drata, Thoropass, Secureframe, or similar tools to improve evidence collection, control monitoring, task tracking, reporting, and repeatable compliance operations. What Were Looking For 5+ years of experience in GRC, information security compliance, IT audit, risk management, security assurance, or a closely related field. Hands-on experience supporting SOC 2 audits and readiness activities. Working knowledge of ISO 27001/27002, HITRUST, NIST CSF, or similar security and compliance frameworks. Experience maintaining security policies, controls, control narratives, evidence repositories, and audit documentation. Experience supporting internal or external audits, including evidence collection, auditor coordination, control owner follow-up, and remediation tracking. Strong written communication skills, with the ability to produce clear policies, questionnaire responses, process documentation, and stakeholder updates. Excellent attention to detail and project management discipline. Experience responding to customer security questionnaires, RFP security sections, or due diligence requests. Familiarity with GRC, compliance automation, or audit management tools. Experience in SaaS, fintech, benefits, healthcare, or other regulated environments. Comfort working in a startup or fast-moving environment where processes need to be mature enough to scale without creating unnecessary friction. Ability to work with both technical and non-technical teams and communicate security and compliance expectations clearly. Nice-to-Haves Certifications such as CISA, CISM, CRISC, HITRUST CCSFP, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or Security+. Experience supporting HITRUST readiness or validated assessments. Experience with vendor risk management or third-party security assessments. Experience supporting HIPAA, PCI DSS, GDPR, or other privacy and security frameworks. Experience at a startup or high-growth technology company. Familiarity with customer trust centers, security assurance portals, or reusable security response libraries. Compensation
$130,000-160,000 + Equity Range(s) is subject to change. Benepass takes a number of factors into account when determining individual starting pay, including market comparables, interview performance, peer compensation, and years of experience. What We Offer 95% coverage of medical, dental, and vision Fantastic benefits, including: $250 WFH setup (one time) $500/year Learning & Development Benefit $150/month cell phone + internet $100/month Wellness $100/month Co-working and Commuter Benefit We offer several team onsites a year Flexible PTO At Benepass, we are working towards reimagining how companies take care of their people. We are committed to creating an inclusive environment for all our employees and are seeking to build a team that reflects the diversity of the people we hope to serve with our revolutionary products. Benepass is proud to be an equal-opportunity employer. #J-18808-Ljbffr
Vacancy posted 8 hours ago
Similar jobs that could be interesting for youBased on the Senior GRC Analyst in Richmond, VA vacancy
$135k - $190k
...City, Mumbai and Bangalore for employees who prefer to work in an office some or all of the time. About your role As a Senior GRC Analyst, you are responsible for supporting the organizations governance, risk management, and compliance (GRC) program. The ideal candidate...SeniorFull timeWork at officeLocal areaRemote workWork from homeFlexible hours$95k - $110k
...Blackkite is looking for a Senior GRC Analyst to oversee compliance efforts and support customer security assessments in the United States. This role requires expertise in compliance frameworks like SOC 2 and ISO 27001, along with strong communication skills. The successful...SeniorFlexible hours- ...DataRobot, Inc. is seeking a GRC Analyst to join their Information Security Team. The successful candidate will collaborate with stakeholders to manage ISO27001, SOC 2, and HIPAA compliance programs. Key responsibilities include responding to customer security inquiries...SuggestedFlexible hours
- ...About the Role: As aGRC Analyst II on our Governance Team, you’ll play a critical role in helping our customers establish and implement robust security governance programs. You’ll work directly with clients to support customer onboarding, policy development, gap reviews...Suggested
- ...rapidly growing boutique firm as a full-time, remote Entry-Level GRC Analyst. This is a contract-to-hire position with top performers... ...cybersecurity and compliance programs. Youll work side-by-side with senior team members and partners to: Assess and improve client...SuggestedPermanent employmentFull timeContract workRemote work
- ...their AI assets. Organizations worldwide rely on DataRobot for AI that makes sense for their business — today and in the future.The GRC Analyst will collaborate with process owners, auditors, and other stakeholders to support the DataRobot Information Security Team in...Local areaWorldwideFlexible hours
$143k - $243k
Prime Therapeutics is seeking a Senior Principal Actuary to provide actuarial direction and strategic consulting. This remote position will innovate pricing strategies and lead actuarial staff. The ideal candidate will have 10 years of actuarial experience, a relevant...SeniorRemote work$119k - $170k
...shape the future of cybersecurity. Role We are looking for a Senior Governance, Risk & Compliance Specialist to join our Technology... ...the implementation, maintenance, and enhancement of integrated GRC frameworks for FedRAMP and DoD authorizations. Your work will directly...SeniorFull timeWork at officeLocal areaRemote work- ...A leading healthcare provider is looking for a Senior Analyst to support risk management and internal audit initiatives. The role involves assessing enterprise risks, managing audit projects, and mentoring junior staff. The ideal candidate should have at least 3 years...SeniorFull time
$87.7k - $100.1k
A financial services company is looking for a Senior Risk Associate in Richmond, VA. This role focuses on regulatory onboarding for derivatives and securities transactions, emphasizing customer service and compliance with financial regulations. Ideal candidates have at...SeniorRemote workFlexible hours- ...A leading financial institution is seeking a Senior Associate for its Regulatory Operations Onboarding team. The candidate will provide exceptional customer service while managing onboarding documentation to ensure compliance with regulatory requirements. This role demands...SeniorRemote workWork from home
- ...OKX is seeking a Senior Compliance Manager, Regulatory Compliance to enhance its compliance framework. This role involves maintaining the AFS license, implementing compliance controls, and developing compliance policies. Candidates should have a Bachelors degree in a...Senior
$143k - $243k
...purpose-driven career? Come build the future of pharmacy with us.Job Posting TitleSenior Principal Actuary - REMOTEJob DescriptionThe Senior Principal Actuary is responsible for providing actuarial direction and thought leadership to Prime's existing and potential owners...SeniorWork experience placementLocal areaRemote workWork visa$87.7k - $100.1k
Capital One is seeking a Senior Risk Associate for the Upmarket and Discover Card segments in Richmond, VA. This hybrid position involves supporting high visibility risk management activities, executing critical risk assessments and fostering relationships with key stakeholders...Senior- Capital One National Association is seeking a Principal Risk Specialist for the Business Cards and Payments team in Richmond, Virginia. This role will manage horizontal functions within the Well Managed Team, focusing on supporting process execution and risk reporting. ...Senior
- A leading financial services company is seeking a Senior Business Analyst in Richmond, VA, to drive their AI agenda within the Enterprise Risk Organization. You will analyze business challenges and collaborate with cross-functional teams to influence decision-making. Candidates...Senior
- ...A healthcare technology company in the United States seeks a Senior Data Analyst to oversee data submissions, ensuring accuracy and compliance. The ideal candidate will have two years of experience with Medicare Risk Adjustment, proficiency in SQL, Python, and R, and skills...Senior
$96.5k - $110.1k
...Senior Risk Associate, Investigations Quality As a Senior Associate on Capital One's Anti-Money Laundering (AML) Investigations Quality... ...within Financial Crimes Investigations. Partner with Analysts and Developers to design or optimize quality reports and system...SeniorFull timePart timeWork at officeLocal area- A leading financial services firm seeks a motivated Senior Business Analyst for its Liquidity, Market, and Capital Risk Oversight team. This role involves analyzing risks and contributing to capital management strategies. Candidates should possess a Bachelor's or Master...Senior
- ...Exiger is a recognized, award-winning leader in supply chain AI and a FedRAMP authorized provider to the federal government. Senior SCRM Analyst - Healthcare Supply Chain Risk Location: Richmond, VA or McLean, VA Work Environment: Hybrid Role Summary:...SeniorWork at officeWork from homeFlexible hours
- ...OHSU is seeking a financial analyst specializing in grant management to support its Office of Proposal & Award Management. The role involves reviewing setup accuracy, preparing financial reports, and collaborating with various departments to resolve issues. Candidates...SeniorWork at office
$87.7k - $100.1k
Capital One National Association is seeking a Senior Risk Specialist for their Retail Risk Office in Richmond, VA. This role emphasizes collaboration with Business and Risk stakeholders to strengthen control activities and influence effective design in their risk environment...SeniorWork at office$167.28k - $196.8k
...Framework Ventures is seeking a Security Compliance Senior Analyst to drive IT SOX initiatives and enhance the IT SOX program. This role involves leading security initiatives, conducting SOX planning activities, and assessing the implications of new products. The ideal...Senior- ...A dynamic consulting firm in the United States seeks a Senior Associate for its Cyber Security & Data Privacy (CSDP) group. This role... ...and strong knowledge of compliance frameworks. Experience with GRC tools is also essential. The firm values collaboration, mentorship...Senior
$101.1k - $115.4k
A leading financial services company in Richmond is seeking a Senior Associate Risk Manager to apply risk management skills within the Enterprise Services Risk organization. The role involves collaboration across teams to support the development of risk solutions while...Senior$170k - $190k
...Senior Manager, Global Regulatory Affairs Labeling This range is provided by Planet Pharma. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more. Base pay range $170,000.00/yr - $190,000.00/yr Direct message the job poster...SeniorFull timeWork experience placementLocal areaRemote work- A leading global consulting firm is seeking a Senior Consultant for its Risk Technology practice, focusing on ServiceNow IRM solutions.... ...have a bachelor's degree in a related field and experience with GRC principles. This position offers a collaborative environment, competitive...Senior
$87.7k - $100.1k
...One Commercial Bank Operations is seeking a dynamic, experienced professional to join the Regulatory Operations Onboarding team as a Senior Associate. This team supports the highly transactional Derivatives and Securities sales and trading business handling all...SeniorFull timeTemporary workPart timeLocal areaWork from homeHome office$94.2k
...or SOC 2 Security Trust Principle audits ~ IT / Information security risk advisory experience ~ Governance Risk and Compliance (GRC) tool experience such as ARCHER ~ In-depth understanding of network security architecture, network and networking protocols ~ Security...SeniorFor contractorsLocal areaRemote work$96.5k - $110.1k
...Senior Risk Associate, Enterprise Data Risk Management Do you want to be part of an organization that’s dedicated to helping Capital One manage data and, identify and effectively mitigate risk – for our customers, our communities and our associates? As part of Enterprise...SeniorFull timePart timeLocal areaImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!
Related searches
- senior development executive Richmond, VA
- senior technical manager Richmond, VA
- senior manager data science Richmond, VA
- senior platform engineer Richmond, VA
- senior procurement Richmond, VA
- senior director product management Richmond, VA
- senior cost manager Richmond, VA
- senior tax director Richmond, VA
- senior manager customer operations Richmond, VA
- senior data engineer Richmond, VA


