Senior Security Governance Risk & Compliance Analyst
$49.73k - $84.1kCommerce Co.
Welcome to the Agentic Commerce EraAt Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce , Feedonomics , and Makeswift , we connect the tools and systems that power growth, enabling businesses to unlock the full potential of their data, deliver seamless and personalized experiences across every channel, and adapt swiftly to an ever-changing market. We believe in harnessing AI responsibly to unlock new possibilities, and we’re looking for individuals who use it intentionally to solve problems, accelerate outcomes, and expand what’s possible in their role. Our purpose is to help businesses confidently solve complex commerce challenges so they can build smarter, adapt faster, and grow on their own terms. If you want to be part of a team of bold builders, sharp thinkers, and technical trailblazers who shape the future of commerce, this is the place for you.We're looking for a Senior Security Governance Risk and Compliance Analyst to help support our compliance programs and work with our teams to implement risk improvement processes and projects. Commerce is committed to being a leader in Information Security in the e-commerce space. Your skills and your passion for protecting data and ensuring compliance will be a large factor in Commerce’s future success. This role will report into our GRC function and work cross-functionally with Product Security, Legal, Partnerships, Privacy, and Engineering teams.What you’ll do:Function as a frontline representative of Information Security leading by example, being diplomatic yet firm, fair, flexible and consistent in deploying industry standard information security best practices and applicable laws, regulations, and policies.Using a risk-based framework, manage third party risk assessments—from onboarding due diligence to continuous monitoring—leveraging platforms like OneTrust, SafeBase, or similarPartner with fraud operations and data science to model and detect threats such as account takeovers, payment abuse, promo fraud, and affiliate misbehavior; understand fraud detection platforms, e.g., e-Hawk, Recorded Future, etc.Maintain metrics and reporting that tie fraud risk to potential loss or customer impact in real terms.Demonstrate understanding of BC GRC Office strategic vision, be a self-starter, and responsible for actions promoting this strategic vision.Provides support and guidance regarding best practice, regulatory, and legal compliance, including PCI, GDPR, ISO 27001, NIST, and SOX.Assistance in evaluating the design and operating effectiveness of the BC Integrated Secure Controls Framework (BC SCF) built from Industry Standards such as NIST, ISO 27001, PCI DSS around technology controls, including, but not limited to Software Development Lifecycle (SDLC), Logical Security, Data interfaces, availability/redundancy, and Cyber / Info security.Preparing supporting evidence, documenting test plans which clearly describes the audit procedures performed, results of testing and conclusions reached for various processes.Creating technology diagrams detailing the systems and their dependencies during the audit processAssisting with the Department’s data collection and analytics efforts and Internal Audit report preparation.Assisting in the development and tracking of control recommendations for corrective action/improvement.Work with Internal Audit leadership to identify and continuously improve departmental practices.Monitor and demonstrate compliance with organizational policies and practices, as evidenced by strong quality assurance results, and strong performance within standards and related metrics.Stay abreast of current issues and obtain continuing education and training.Participate in special projects and perform other duties as requested.Interact with all levels of management to provide effective risk and control advice, maintaining active communication to enhance risk and control awareness and manage expectations.Provide data analysis support for ongoing compliance monitoringMaintain up-to-date knowledge about audit controls and techniquesUtilize innovative ideas and tools to enhance operational effectivenessEvaluate and recommend improvements to business practices, processes, and controlsWho You Are:5-6 years of relevant experience in a technology environment.Experience with translating business requirements into project implementation plans and validation, including user acceptance testing.Knowledge of network-based services, client/server applications, cloud-based and virtualized environments, mobile applications, enterprise systems and infrastructure, network architecture, and security infrastructure.Passion about process improvement and removing friction from systemsDirect experience with audit and compliance frameworks, e.g., ISO 27001, 2007:2017, PCI, etc.Background in IT hardware/software concepts and processes used within the business, coveringCore security conceptsCloud-based servicesWindows and Linux operating systemsOpen-source ecosystem (databases, applications, etc.)Experience with auditors and the evidence collection processExperience with the design and testing of IT security controls in a managed hosting and/or Software-as-a-Service environmentExperience in building relationships across business functions, locations, and technical stakeholders.Self-direction, attention to detail with a passion to solve practical problems while dealing with a number of variables.Ability to present ideas/solutions and communicate clearly, concisely, and accurately with others at all levels of the organization.Experience in reading the culture of a company, adjusting your style and adapting as needed.Collaborative, upbeat work ethic where you both take ownership and have fun.Able to meet deliverables and drive your work to completion within specified timelines.Great verbal and written communication skills.This is a Hybrid role - Beginning March 1, 2026, employees who live within commuting distance of a Dedicated Office will be expected to be in the office three days per week.#LI-KE1#LIHYBRID(Pay Transparency Range: $49,729.00 - $84,100.00)Compensation TransparencyThe national base salary range for this role is posted above in this job post.Final compensation will be determined based on factors such as relevant experience, skills, qualifications and geographic location. We also consider internal equity to help ensure fair and consistent pay practices across our teams.Where applicable, this role may also be eligible for variable compensation (such as bonus or commission), equity, and benefits in accordance with local policies. Details will be shared during the hiring process. We are committed to equitable and transparent pay practices that align to market data, internal equity, and individual contribution.Inclusion and BelongingAt Commerce, we believe that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community. We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive.We are committed to creating an inclusive and accessible hiring experience for all candidates. If you require accommodations or adjustments at any stage of the recruitment process, please let us know and we will work with you to meet your needs.Learn more about the Commerce team, culture and benefits at Yourself Against Hiring Scams: Our Corporate DisclaimerCommerce, along with many other employers, has become the subject of fraudulent job offers to hopeful prospective job seekers.Be advised:Commerce does not offer jobs to individuals who do not go through our formal hiring process.Commerce will never:require payment of recruitment fees from candidates;request personally identifiable information through unsanctioned websites or applications;attempt to solicit money from you as part of the hiring process or as part of an employment offer;solicit money to complete visa requirements as part of a job offer.If you receive unsolicited offers of employment from Commerce, we urge you to be extremely cautious and avoid engaging or responding. #J-18808-Ljbffr Commerce Co.
$88.95k - $150.43k
...commerce ecosystem that empowers businesses to innovate and grow with open, AI‑powered tools. Role Overview Senior Security Governance, Risk & Compliance Analyst Responsibilities Act as a frontline representative of Information Security, leading by example and deploying...SeniorWork at officeLocal area3 days per week- Job Description The Sr. Cybersecurity Governance, Risk, and Compliance (GRC) Associate plays a critical role in supporting the organization's GRC program, with a specialized focus on security framework compliance and information security risk management. Reporting to the...SeniorPermanent employmentTemporary workWork at officeFlexible hours
- BigCommerce Pty is seeking a Senior Security Governance Risk and Compliance Analyst based in Austin, TX. In this hybrid role, you will manage risk assessments and lead compliance initiatives while interacting with various teams across the company. Ideal candidates will...Senior
- BigCommerce Pty. is seeking a Senior Security Governance Risk and Compliance Analyst in Austin, TX. This hybrid position involves managing risk assessments and ensuring compliance with industry standards. The ideal candidate will have significant experience in information...SeniorRemote job
- Commerce.com US, Inc. is seeking a Senior Security Governance, Risk & Compliance Analyst in Austin, Texas. The role involves managing risk assessments, ensuring compliance with industry standards, and acting as a liaison with internal audit teams. The ideal candidate will...SeniorWork at office3 days per week
- Commerce is searching for a Senior Security Governance Risk and Compliance Analyst to enhance our compliance programs and assist teams in risk improvement. The ideal candidate will possess 5-6 years of technology experience and skills in data protection. This hybrid role...Senior
- ...IT Security Manager Key Responsibilities: Governance Develop, maintain, and enforce IT security policies, standards... ...awareness programs. Risk Management Identify, assess... ...track remediation efforts. Compliance Ensure compliance with regulatory...
$96.6k - $130k
...Sr. Cybersecurity Governance, Risk, and Compliance (GRC) Associate Join a team that values your ambition and empowers your growth At Corient... ...organization's GRC program, with a specialized focus on security framework compliance and information security risk management...SeniorPermanent employmentTemporary workWork at officeFlexible hours- EZCORP Inc is seeking a Senior Compliance Analyst to support the Compliance Management Program in Austin, Texas. The successful candidate will play a critical role in regulatory examination management, monitoring compliance, and overseeing compliance efforts. This position...SeniorRemote job
- Commerce Inc in Austin is looking for a Senior Security Governance Risk and Compliance Analyst to support compliance programs and implement risk improvement projects. This hybrid role involves managing third-party risk assessments, collaborating with cross-functional teams...Senior
$164.9k - $223.1k
Arm Limited is seeking a GRC Risk Manager in Austin, Texas, to oversee security risk management and lead supply-chain cyber risk assurance. The ideal candidate will have deep expertise in technical risk frameworks like ISO 27001 or NIST and possess strong analytical and...Senior$165k - $239k
Compliance Senior Specialist, Privacy and Security Policy, RCI Google Austin, TX, USA; Chicago, IL, USA; +1 more Benefits... ...in compliance, policy, risk management, investigation, auditing... ...compliance, assurance, risk, and governance functions across Google to help the...SeniorFull timeTemporary work- Corient is seeking a Sr. Cybersecurity Governance, Risk, and Compliance Associate in Austin, Texas. This role plays a critical part in enhancing security frameworks and managing organizational risks. The ideal candidate will have 3-6+ years in cybersecurity GRC, strong...Senior
$88.95k - $150.43k
## Senior Security GRC Analyst (PCI ISA Specialist)Applyremote type: Hybridlocations: Austin, TXtime type... ...of this program, ensuring that compliance is integrated into our "business as usual... ...specific focus on managing Targeted Risk Analyses (TRAs) and the customized approach...SeniorWork at office3 days per week$88.95k - $150.43k
Senior Security GRC Analyst and Internal Security Assessor (ISA) - Commerce Serve as the primary Subject... ...of the program to integrate compliance into business-as-usual operations. Support... ...the PCI 4.0 program, oversee Targeted Risk Analyses (TRAs) and customized approaches...SeniorWork at officeLocal area3 days per week- ...Role Sonic Healthcare USA is seeking a Senior Compliance Audit Specialist to support and enhance... ...operations Support the annual compliance risk assessment and work plan development... ...as abide by all applicable privacy and security standards. Employees are expected only...SeniorFull timeLocal area
- UMB Bank is seeking an EFT Risk Analyst in Austin, Texas, to assist with the administration and support of risk programs. This hybrid position... ...should have an associate degree and experience in banking or compliance. UMB offers competitive benefits, including a 401(k) matching...Remote work
$30.75 per hour
Wise is seeking a FinCrime Operations Senior Analyst in Austin, Texas, to help safeguard customers... ...and mitigating financial crime risks. You will conduct investigations, analyze... ...2 years of experience in operations or compliance, strong communication skills, and an understanding...SeniorHourly payFlexible hours- A leading security solutions provider in Austin, TX is seeking an Intel Analyst responsible for supporting proactive risk management through intelligence analysis. Key tasks include monitoring threats, developing reports, and collaborating across teams to ensure effective...Remote job
$60k
...programs across national security, defense, and public service... ...and improving essential government systems and services,... ...This role is remote. The Risk, Quality, and Performance Analyst serves as the Risk,... ...management activities to ensure compliance with contract...Contract workRemote work$107.7k - $199.3k
Position Purpose The Security Compliance Lead Information Risk Analyst is a senior individual contributor role with enterprise-wide responsibility for security governance, compliance execution, audit readiness, and GRC platform leadership. The role operates independently...Full timePart timeWork at officeRemote workFlexible hours$80k - $110k
Governance, Risk and Compliance (GRC) Analyst Location: Austin, Texas. Hybrid - 3 days in office. Overview The Governance, Risk and Compliance (GRC) Analyst will understand security and privacy principles and regulatory compliance for a US business. In this role, you...Work at office$80k - $110k
Storyful is seeking a Governance, Risk and Compliance (GRC) Analyst in Austin, Texas. This hybrid role involves supporting and maintaining the Cyber GRC... ...Candidates should have a minimum of 3 years in Cyber Security and familiarity with frameworks like NIST CSF and PCI...$125k
The University of Texas at Austin is seeking a Cybersecurity GRC Analyst to support governance, risk, and compliance for its Controlled Research Program. The role involves maintaining security programs, conducting assessments, and collaborating with IT and research stakeholders...Remote job$143k - $243k
A healthcare solutions organization is seeking a Senior Principal Actuary for a remote position in Austin, Texas. This role is pivotal in providing actuarial direction and creating innovative pricing strategies. The ideal candidate will have at least 10 years of actuarial...SeniorRemote work$80k - $110k
News Corporation is seeking a Governance, Risk and Compliance (GRC) Analyst in Austin, Texas. The role involves compliance support for security and privacy principles and regulatory compliance while developing and maintaining cybersecurity policies. The ideal candidate...- ...Engineering Services Pvt Ltd. is offering a remote position within the Information Security Office at The University of Texas at Austin. This role is crucial for supporting governance, risk, and compliance programs in cybersecurity. You'll work with an intelligent and dedicated...Remote jobWork at office
$125k
Overview Job Posting Title: Cybersecurity GRC Analyst Department: Information Security Office Location: AUSTIN, TX (This position can be a... ...on the development, maintenance, and execution of governance, risk, and compliance activities that support the university’s Controlled...Work at officeRemote work$125k
...University of Texas at Austin is seeking a Cybersecurity GRC Analyst to enhance their governance, risk, and compliance activities. This role focuses on compliance frameworks such as NIST and CMMC, supporting secure research practices. The ideal candidate should have at...Remote job$92.5k - $120k
...To support the continued growth of our Risk Advisory for State & Local Government practice, an opportunity has been created for a Senior Associate to join our nationally distributed... ...over operational and regulatory compliance risks, supporting them in the areas of internal...SeniorWork experience placementWork at officeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Governance Risk & Compliance Analyst. Be the first to apply!
- security analyst remote Austin, TX
- senior information security analyst Austin, TX
- information security compliance analyst Austin, TX
- security analyst intern Austin, TX
- security analyst Austin, TX
- national security analyst Austin, TX
- application security analyst Austin, TX
- IT security analyst Austin, TX
- entry level information security analyst Austin, TX
- cloud security analyst Austin, TX

