Security Governance Risk & Compliance Analyst I
$49.73k - $73.13kBigCommerce Pty
Welcome to the Agentic Commerce Era At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce, Feedonomics, and Makeswift, we connect the tools and systems that power growth, enabling businesses to unlock the full potential of their data, deliver seamless and personalized experiences across every channel, and adapt swiftly to an ever-changing market. We believe in harnessing AI responsibly to unlock new possibilities, and we’re looking for individuals who use it intentionally to solve problems, accelerate outcomes, and expand what’s possible in their role. Our purpose is to help businesses confidently solve complex commerce challenges so they can build smarter, adapt faster, and grow on their own terms. If you want to be part of a team of bold builders, sharp thinkers, and technical trailblazers who shape the future of commerce, this is the place for you. We're looking for a detail-oriented and curious GRC Analyst to join our Governance, Risk & Compliance team. In this role, you'll support the day-to-day operations of our risk and compliance program, helping assess third-party vendors, maintain policy documentation, track control evidence, and support audit activities. We're especially interested in candidates who've explored tools like Claude Code and are curious about how AI can be applied to cybersecurity and compliance work. This is a great opportunity for someone early in their career who wants to build a strong foundation in enterprise risk management and information security compliance, joining a senior, globally distributed team that will invest in your growth from day one. What You’ll Do Support third-party risk assessments by reviewing vendor security questionnaires, documentation, and due diligence materials Maintain and update the vendor risk register and track remediation activities to closure Assist with internal control testing and evidence collection for compliance frameworks (SOC 2, ISO 27001, PCI-DSS, etc.) Help coordinate audit requests and liaise with internal stakeholders to gather required documentation Monitor policy and procedure documentation, flagging items due for review or update Assist in tracking risk exceptions, escalating items that require senior review Support reporting and metrics preparation for leadership and committee-level reviews Contribute to process improvement initiatives as the program scales What We’re Looking For 0–2 years of experience in GRC, risk operations, compliance, or a related function (internships count) Bachelor's degree Computer Science, Cybersecurity, Information Systems, Business, or a related field. Equivalent work experience also considered. Genuine interest in GRC engineering and a willingness to learn quickly in a fast-paced environment required Hands‑on familiarity with Claude Code or similar AI coding tools, and an ability to think through how they could be applied to cybersecurity or GRC work (hobby projects welcome) Strong written and verbal communication skills - you'll be working cross-functionally and with external vendors High attention to detail and comfort working with documentation, spreadsheets, and tracking tools Proficiency in Microsoft Office or Google Workspace Nice To Have Coursework or certification in cybersecurity or risk management (Security+, CISA, etc.) Exposure to compliance frameworks such as SOC 2, ISO 27001, NIST, or PCI-DSS Experience in an operations or process-driven role (internship or otherwise) Salary Transparency Range: $49,729.00 - $73,130.00 Where applicable, this role may also be eligible for variable compensation (such as bonus or commission), equity, and benefits in accordance with local policies. Inclusion and Belonging At Commerce, we believe that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community. We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive. We are committed to creating an inclusive and accessible hiring experience for all candidates. If you require accommodations or adjustments at any stage of the recruitment process, please let us know and we will work with you to meet your needs. #J-18808-Ljbffr BigCommerce Pty
- ...together through commerce. Role Whatnot's Security GRC team is dedicated to building... ...GRC team. Leading our security risk management program to prioritize security... ...impact goes a long way here. As our Governance, Risk, & Compliance Analyst you should have a minimum of 5+...SuggestedLocal areaRemote workWork from homeHome office
- Commerce seeks a detail-oriented GRC Analyst to join our Governance, Risk & Compliance team. You will support third-party risk assessments, maintain the vendor risk register, and assist with control testing and audit activities across SOC 2, ISO 27001, PCI-DSS. Ideal candidates...Suggested
- Commerce is seeking a GRC Analyst to join our Governance, Risk & Compliance team. You’ll support day-to-day risk and vendor assessments, ensure documentation, and assist audits. This is an opportunity for early career professionals to grow within a globally distributed...Suggested
- Commerce, a leader in enterprise risk and compliance, seeks a detail-oriented GRC Analyst for its Governance, Risk & Compliance team. You will support day-to-day risk and compliance operations, assess third-party vendors, maintain policy documentation, and help with audits...Suggested
- Vercel is seeking a GRC Analyst to join the Governance, Risk & Compliance team. You will manage ongoing compliance across security and privacy frameworks (ISO 27001, SOC 2, HIPAA, PCI DSS) and collaborate with cross‑functional teams to promote accountability and ethical...SuggestedRemote job
- ...than 1,000 clinicians alongside care coordinators, analysts, operators, and professionals from all... ...CuranaHealth.com. Summary Curana Health is seeking an IT Governance, Risk, and Compliance Analyst to join our IT Security and Governance team. In this role, you will help...
- Air Liquide in Houston, TX seeks an Information Security Analyst - Business Security and Compliance to uphold governance, risk management, and compliance across Digital & IT environments. Focus on protecting sensitive data and aligning with Global Cyber security Framework...
- Whatnot seeks a Governance, Risk, & Compliance Analyst to strengthen its Security GRC program. You will assess security controls, support external audits, and guide risk management across the company. Ideal candidates have 5+ years in security governance, a BS in CS or...
- Curana Health is seeking an IT Governance, Risk, and Compliance Analyst to join our IT Security and Governance team. In this role, you will strengthen security and regulatory programs by supporting risk management, audit readiness, policy administration, control monitoring...
- TAB Bank is seeking a Regulatory Compliance Analyst in Ogden, UT to perform compliance monitoring, testing, and feedback within the bank's Compliance Program. The role supports the development and maintenance of compliant procedures for new products and services. The ideal...Full time
- BECU is seeking an Enterprise Risk Analyst - AI Risk to shape how AI is adopted and governed across the organization. The role focuses on identifying, assessing,... ...collaboration across Risk, Technology, Governance, Compliance, and Business teams in a remote-friendly...Remote job
- # AI Governance & Risk AnalystOperates the Managed AI program for our clients on a recurring cadence... ...this roleThe AI Governance & Risk Analyst operates the Managed AI program for our... ...looking for* 3+ years in IT governance, security GRC, or comparable risk-analysis role*...
- Blue Cross NC is seeking an IT Governance Analyst to help identify, assess, monitor, and mitigate third-party vendor risks across technology, cybersecurity, data privacy... ..., procurement, information security, legal and compliance to ensure risk controls align with our...Remote jobFlexible hours
- Orion Advisor Solutions is seeking a Senior Privacy & AI Risk Analyst to lead privacy initiatives and oversee AI governance from a privacy perspective. You will collaborate across Legal, InfoSec, and business units to ensure privacy controls are applied to AI use cases...Work at office3 days per week
- Unió Digital is seeking an AI Governance & Risk Analyst to operate the Managed AI program from Tucson, AZ or remotely. You will own AI policy maintenance, vendor risk monitoring, DPA management, and quarterly evidence packaging for client audits and insurance reviews. This...Remote job
- EY seeks a Threat & Risk Analyst to lead intelligence efforts across the Americas, partnering with Global and Regional Security to protect personnel, facilities, assets and reputation. You will monitor incidents, produce analyses and briefings, and communicate threats to...
- Amentum is seeking a seasoned analyst to assess national security risks from transactions before CFIUS and Team Telecom, focusing on critical infrastructure and ICTS under EO 13873. You will work with DHS leadership and interagency partners to guide cases through the full...
$72.86k - $110.01k
## Senior Privacy & AI Risk AnalystApplyremote... ...Senior Privacy & AI Risk Analyst, you will be expected... ...also support Orion's AI governance efforts from a privacy... ..., Information Security Team, and relevant business... ...experience in financial compliance, risk, privacy or anti...Work at officeLocal area3 days per week- Blue Cross NC is seeking an IT Governance Analyst to assist in identifying, assessing, monitoring, and mitigating risks from third-party vendors, suppliers, and outsourced... ...across procurement, information security, legal, and compliance. You’ll develop dashboards and...
- Park National Bank is seeking a Business Risk & Controls Program Analyst to help maintain and enhance our governance framework. This remote role collaborates with business lines to embed policy and compliance into processes and supports risk governance activities across...Remote job
- Air Liquide in Houston, TX is seeking an Information Security Analyst to support Governance, Risk Management and Compliance across Digital & IT environments. The role helps maintain cybersecurity for IT and OT systems and protect sensitive data. You will join a global...
- EY’s Threat & Risk Analyst role focuses on leading strategic and tactical threat intelligence for the Americas, coordinating with Global Security and regional teams. Responsibilities include monitoring incidents, producing risk assessments, and informing crisis management...
- FiveBy Solutions is a Seattle-based security consultancy seeking a Risk Intelligence Analyst to support sanctions research and due diligence for clients. The role emphasizes curiosity, methodological rigor, and cross-functional collaboration, with a strong emphasis on...Remote job
- ...critical role in strengthening data governance, monitoring data loss... ...opportunity to work alongside data security leaders, governance SMEs, and... ...the organization’s data risk posture while supporting both... ...comfortable operating in structured, compliance-driven environments...
- Medasource is seeking an IT GRC Analyst to join the IT Security and Governance team on a 6-month contract-to-hire basis, remote within the USA. The role focuses on governance, risk, and compliance across HIPAA, SOC 2, and NIST, collaborating with IT, Security, Privacy,...Remote jobContract work
- Medasource is seeking an IT GRC Analyst to join our IT Security and Governance team on a 6-month contract-to-hire basis, working remotely within the... ...The role focuses on security governance, regulatory compliance, risk management, audit readiness, policy administration,...Remote jobContract work
$134k - $202k
...help builders move from idea to production with speed, security, and exceptional developer experience. Now,... ...comes next. About the role We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage...Work at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours- ...dynamic team to navigate complex risk landscapes and fortify technology governance, making a pivotal impact in our firm... ...aspects of Governance, Risk, and Compliance in line with the firm's standards... ..., control evaluation, and security governance is crucial in advising...
- Capital One seeks a Principal Analyst in Capital Markets & Risks in McLean, VA to lead SOX advisory and end-to-end risk management across lines of... ...and remediation actions, driving control improvements and governance across financial reporting. The role requires 3+ years...
$72.6k - $135.7k
...The opportunity The Threat & Risk Analyst leads strategic and tactical threat intelligence... ...efforts in partnership with Global Security and Regional Security teams, with a focus... ...relationships with other corporate and government intelligence teams to share...Summer holidayLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Governance Risk & Compliance Analyst I. Be the first to apply!
- rate analyst Brooklyn, NY
- work from home security analyst Brooklyn, NY
- entry level information security analyst Brooklyn, NY
- national security analyst Brooklyn, NY
- application security analyst Brooklyn, NY
- information security analyst Brooklyn, NY
- entry level security analyst Brooklyn, NY
- security analyst Brooklyn, NY
- security operations analyst Brooklyn, NY
- information security compliance analyst Brooklyn, NY



