Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior GRC Analyst

$183k - $205k

Gusto

Senior GRC Analyst

San Francisco, CA - Hybrid

At Gusto, we're on a mission to grow the small business economy. We handle the hard stuff — payroll, health insurance, 401(k)s, and HR — so owners can focus on their craft and their customers. With teams in Denver, San Francisco, and New York, we support more than 500,000 small businesses nationwide and are building a workplace that reflects the people we serve.

All full-time employees receive competitive base pay, benefits, and equity (RSUs) — because everyone who helps build Gusto should share in its success. Offer amounts are determined by role, level, and location. Learn more about our Total Rewards philosophy.

AI is a fundamental part of how work gets done at Gusto. We expect all team members to actively engage with AI tools relevant to their role and grow their fluency as the technology evolves. AI experience requirements vary by role and will be assessed during the interview process.

Gusto is seeking a Security, Governance, Risk & Compliance professional to join our team managing our security governance, risk and compliance initiatives. This person will guide the company from foundational Governance, Risk & Compliance (GRC) maturity through to steady-state operations, leveraging AI to automate and improve old practices and tools, ensuring ongoing compliance with SOC 2 Type 2, IT General Controls, ICOC and related frameworks, while embedding security-minded practices throughout Gusto. This is a cross-functional role with key touchpoints in every department.

Here's what you'll do day-to-day:

  • Develop, maintain, and ensure adherence to security and compliance SOPs, internal documentation, and company-wide policies—particularly supporting SOC 2 and future framework adoption.
  • Own and manage trust management platforms including documentation of controls, risks, vendors, and exceptions, and lead the implementation of AI agents to automate and improve the implementation of our controls framework and evidence collection to support it
  • Collaborate with Legal, Enterprise Applications, and Gusto counterparts to establish and maintain data governance policies (e.g., classification, retention, handling).
  • Conduct ongoing internal risk assessments to identify exposure and control gaps; coordinate remediation plans with functional teams.
  • Manage the third-party vendor risk program, including onboarding reviews, monitoring, and renewal assessments.
  • Lead interactions with external auditors and regulatory bodies during compliance assessments (e.g., SOC 2 Type 2) and oversee responses to client security assessments and due diligence requests.
  • Stay current on relevant compliance frameworks, laws, and regulations to ensure appropriate coverage and adaptability.
  • Partner cross-functionally (e.g., Security, Legal, Engineering, Sales, IT) to implement scalable GRC processes, harmonize systems, and foster GRC understanding through employee enablement programs and KPI-driven insights.

Here's what we're looking for:

  • 8+ years of experience in governance, risk, and compliance within SaaS, ideally in the HCM, payroll, or fintech sectors.
  • Bachelor's degree in Business, Information Systems, or a related field.
  • Strong understanding of SaaS business models, with experience implementing controls and policies in fast-paced, product-driven environments.
  • Proven experience leading or supporting a SOC 2 Type 2 compliance initiative, including collaboration with auditors and cross-functional teams.
  • Familiarity with compliance tools and platforms such as Optro, Vanta, Drata, Viso Trust, or similar.
  • Demonstrated ability to translate complex GRC requirements into actionable, scalable processes.
  • Excellent written and verbal communication skills, including the ability to educate and influence cross-functional stakeholders.
  • A data-informed mindset, with the ability to use analytics to assess GRC performance and maturity.
  • One or more relevant professional certifications:
    • CISA, CRISC, or GRCP preferred
    • CGEIT, CRMA, or PMI-RMP are a bonus

Our cash compensation amount for this role is targeted at $183,000-205,000 in the San Francisco Bay Area. Stock equity is additional. Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above.

Gusto has physical office spaces in Denver, San Francisco, and New York City. Employees who are based in those locations will be expected to work from the office on designated days approximately 2-3 days per week (or more depending on role). The same office expectations apply to all Symmetry roles, Gusto's subsidiary, whose physical office is in Scottsdale.

Note: The San Francisco office expectations encompass both the San Francisco and San Jose metro areas.

When approved to work from a location other than a Gusto office, a secure, reliable, and consistent internet connection is required. This includes non-office days for hybrid employees.

Our customers come from all walks of life and so do we. We hire great people from a wide variety of backgrounds, not just because it's the right thing to do, but because it makes our company stronger. If you share our values and our enthusiasm for small businesses, you will find a home at Gusto.

Gusto is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Gusto considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Gusto is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. We want to see our candidates perform to the best of their ability. If you require a medical or religious accommodation at any time throughout your candidate journey, please fill out this form and a member of our team will get in touch with you.

Gusto takes security and protection of your personal information very seriously. Please review our Fraudulent Activity Disclaimer.

Personal information collected and processed as part of your Gusto application will be subject to Gusto's Applicant Privacy Notice.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior GRC Analyst in San Francisco, CA vacancy
  • United States Digital Space LLC in San Francisco seeks a Governance, Risk & Compliance Analyst to mature our security program and manage regulatory obligations, shaping compliance and risk practices to build customer trust in a fast-growing startup transforming search and... 
    Senior

    United States Digital Space LLC

    San Francisco, CA
    3 days ago
  • Perplexity is seeking a Governance, Risk & Compliance Analyst to shape and run our compliance and risk management program. You will lead the implementation of frameworks, oversee data privacy regulations, and build scalable audit systems in a fast‑growing startup environment... 
    Senior

    Apply

    San Francisco, CA
    2 days ago
  • $117.2k - $176.7k

     ...place! Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceLocation: San Francisco, CAThe Senior Security GRC Analyst role is part of our Assurance team, sitting at the intersection of internal operations and external audit relationships.... 
    Senior
    Full time
    Work at office

    Salesforce

    San Francisco, CA
    1 day ago
  • $96.3k - $145.2k

     ...the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all. Experience The Security GRC Analyst role is part of our Security and Compliance team, sitting at the intersection of internal operations and external audit relationships... 
    Senior
    Work at office

    Salesforce.Com Inc

    San Francisco, CA
    3 days ago
  •  ...raised our Series B and have grown 800% over the last 12 months. The Opportunity Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives. This role will play a key part in... 
    Suggested
    Contract work
    Work at office
    Remote work
    Visa sponsorship
    Relocation package
    Flexible hours

    IVO Inc

    San Francisco, CA
    4 days ago
  •  ...7001, NIST 800-53, and FedRAMP Moderate equivalency: continuous evidence collection, control monitoring, and audit readiness held on GRC platforms (Vanta) and the tooling we build in-house. Own the policy and procedure set: draft, maintain, and run the review cycle so... 
    Local area

    Fluidstack

    San Francisco, CA
    2 days ago
  • $95k - $150k

     ...high level of security assurance to customers, aligning security goals with business objectives and customer requirements. As a GRC Analyst at Zip, you’ll be a key driver for ensuring the success of compliance programs at a fast-growing company. Your contributions will... 
    Home office
    Flexible hours

    ZIP

    San Francisco, CA
    4 days ago
  • $134k - $202k

     ...customers, growing our community, or shaping our story, you’ll help define what comes next. About the role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with... 
    Work at office
    Remote work
    Worldwide
    Monday to Friday

    Webhosting.net

    San Francisco, CA
    19 hours ago
  • $135k - $165k

     ...platform and customer relationships. As we continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk management programs. Role Overview Ivo is seeking a detail-oriented... 
    Contract work
    Flexible hours

    Icehouseventures

    San Francisco, CA
    2 days ago
  • $135k - $165k

    Icehouseventures is seeking a proactive GRC Analyst to join our team in San Francisco. This role will support compliance and risk management initiatives essential for maintaining high security standards. The ideal candidate will have 3-5 years of experience in GRC and relevant... 
    Contract work

    Icehouseventures

    San Francisco, CA
    2 days ago
  • Zip is hiring a GRC Analyst to drive compliance programs across SOC 1, SOC 2, ISO 27001, and expanding into the EU and regulated industries. You’ll partner with internal teams and external auditors to maintain certifications and enable secure product development. In this... 

    Zip

    San Francisco, CA
    4 days ago
  • Salesforce.com, inc. is seeking a detail-oriented Security GRC Analyst to join their Security and Compliance team. In this role, you will lead the Unified Audit program ensuring compliance across various frameworks like SOC 2 and HIPAA, while managing evidence collection... 

    salesforce.com, inc.

    San Francisco, CA
    4 days ago
  • Fluidstack is seeking a Security Compliance Lead in San Francisco to own end-to-end controls across SOC 2 Type II, ISO 27001, NIST 800-53, and FedRAMP, building a scalable program for global sites. You will collaborate with engineering and operations to gather evidence,...

    FluidStack

    San Francisco, CA
    19 hours ago
  • Anthropic is seeking a Senior Third Party Risk Manager to lead the top tier of vendor risk, including mission-critical compute, data center, and data-pipeline partners. You will shape risk assessments, escalation, and remediation across security, privacy, and operations... 
    Work at office
    Visa sponsorship

    Anthropic

    San Francisco, CA
    3 days ago
  • Vercel in San Francisco is seeking a GRC Analyst to join our Governance, Risk & Compliance team. You will manage and maintain ongoing compliance with security and privacy frameworks, policies, and audits including ISO 27001, SOC 2, HIPAA, and PCI DSS. You will collaborate... 
    Remote job
    Work at office

    Webhosting

    San Francisco, CA
    9 hours ago
  • Ivo is looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst in San Francisco. The ideal candidate will support compliance programs such as SOC 2 Type II and ISO 27001 while managing audits and risk assessments. This onsite role offers a competitive... 

    IVO Inc

    San Francisco, CA
    1 day ago
  • Relation Insurance is seeking a Risk Advisor to drive new insurance account production and sales with a focus on employee benefits. The role requires consultative selling, market research, and maintaining a profitable client book while leveraging our AI tools to engage...
    Senior

    Relation Insurance Inc

    San Francisco, CA
    19 hours ago
  •  ...Early Warning Services LLC is seeking a Sr. Data Analyst - Risk Management to support the enterprise risk program, including three-lines of defense. You will lead risk projects, develop scorecards, and report on risk assessments and tolerances in a collaborative, fast-... 
    Senior

    Early Warning Services

    San Francisco, CA
    19 hours ago
  • $172.5k - $222.5k

     ...work environment where new ideas are encouraged and everyone is a stakeholder.What you’ll be responsible for: Circle is looking for a Senior Manager to join the Regulatory Assurance team who will help to create a central global function focused on developing a best in... 
    Senior
    Flexible hours

    Circle

    San Francisco, CA
    1 day ago
  • $132.6k - $195k

     ..., merchants, and drivers.About the RoleThe Global Governance, Risk, and Compliance (GRC) team is looking for a technical, security-focused Third-Party Risk Management (TPRM) Sr. Analyst. If you are comfortable and have experience working in a fast-paced environment, taking... 
    Senior
    Hourly pay
    Contract work
    Work at office
    Local area
    Remote work
    Flexible hours

    Doordash

    San Francisco, CA
    1 day ago
  • $240k - $275k

    The International Executive Service Corps is hiring a Director of Clinical Regulatory Affairs to shape and execute the global clinical regulatory strategy. The role involves overseeing clinical submissions and ensuring compliance with regulatory requirements. The ideal...
    Senior

    International Executive Service Corps

    San Francisco, CA
    19 hours ago
  • $218.06k - $327.09k

    Job DescriptionThe Senior Director, Oncology Cell and Gene Therapy Regulatory Affairs, leads the development and implementation of the global regulatory strategy for CGT products of high complexity and visibility and may serve as Franchise GRL on complex programs with... 
    Senior
    Hourly pay
    Full time
    Temporary work
    Worldwide
    Flexible hours
    3 days per week

    AstraZeneca

    San Francisco, CA
    14 hours ago
  • Morrison Foerster is seeking a Senior Conflicts Resolution Analyst to join the Conflicts/New Business team in San Francisco or New York. You will support conflicts of interest attorneys by reviewing reports, conducting in-depth research, and preparing recommendations for... 
    Senior

    Morrison Foerster

    San Francisco, CA
    1 day ago
  •  ...Senior Vendor Risk Analyst Financial Services - Commercial Banking Job Description Senior Vendor Risk Analyst San Francisco Exp 2-5 years Deg Bachelors Relo Bonus Frequent Travel Major Responsibilities: Coordinate with stakeholders... 
    Senior
    Remote work
    Flexible hours

    Direct Staffing Inc

    San Francisco, CA
    4 days ago
  •  ...Senior Director, IT Compliance & Governance (Contractor) About the Company Innovative company designing & developing gene therapeutic products Industry Biotechnology Type Public Company Founded 2013 Employees 51-200 Categories Biotechnology... 
    Senior
    For contractors

    Confidential

    San Francisco, CA
    1 day ago
  •  ...Prosper is seeking a Senior Credit Risk Analyst to join the Credit Risk team in advancing our nationwide lending platform. You will develop credit and fraud strategies using data, machine learning, and analytics to optimize decisions across our marketplace. The role emphasizes... 
    Senior

    F-Prime Capital

    San Francisco, CA
    19 hours ago
  • Baker Tilly Public Sector Internal Audit & Risk Senior Consultant in the San Francisco region offers a dynamic, client‑facing role within a leading advisory firm. You will assess risks, strengthen controls and support governance improvements for government and public sector... 
    Senior
    Remote job

    Baker Tilly International

    San Francisco, CA
    1 day ago
  •  ...frameworks). Synthesize complex data into clear, actionable reports and dashboards illustrating risk exposure and portfolio trends for senior leadership and risk committees. Risk Project Delivery: Successfully manage the execution of multiple high-visibility, in-flight... 
    Senior
    Flexible hours

    L.E.A.D

    San Francisco, CA
    19 hours ago
  • $85k - $100k

    BDO USA, LLP is seeking a Senior, Risk Advisory Services professional to provide risk consulting to clients in areas such as compliance, internal audit, and fraud investigations. Responsibilities include engaging with clients, performing risk assessments, and supervising... 
    Senior

    BDO USA, LLP

    San Francisco, CA
    19 hours ago
  • $187.6k - $281.4k

     ...scoping, gap analysis, control documentation, assessment coordination, and continuous monitoringProven cross-functional influence at the senior level; able to drive compliance outcomes across Engineering, Product, Legal, and Sales without slowing the businessTrack record... 
    Senior

    Harvey

    San Francisco, CA
    19 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!