GRC Analyst (Remote - LATAM)
Atmosera
GRC Analyst
Atmosera empowers businesses to redefine what's possible with modern technology and human expertise. Our exceptional experience across Applications, Data & AI, DevOps, Security, and the Microsoft Azure platform enables organizations to accelerate innovation, enhance security, and optimize operational agility. As a Microsoft Partner with seven specializations, GitHub AI Partner of the Year, a member of the GitHub Advisory Board, and a member of the prestigious Microsoft Intelligent Security Association (MISA), Atmosera expertly delivers cutting-edge, integrated solutions that deliver business value.
The GRC Analyst delivers day-to-day Governance, Risk, and Compliance (GRC) services as part of Atmosera's Managed GRC (MGRC) offering. This role focuses on operational execution, coordination, and reporting across compliance, security assurance, and governance activities to help clients achieve and maintain regulatory alignment, security maturity, and operational trust.
The selected candidate will be responsible for client audits, evidence gathering, managing compliance tools, supporting security questionnaires, monitoring security controls, facilitating regulatory alignment, and overseeing ongoing governance activities throughout the Atmosera client portfolio.
The GRC Analyst operates within defined service hours (Monday–Friday, 8am–5pm PT) and works closely with Client Success Managers, security engineers, and subject-matter experts. This role does not perform executive security leadership, risk ownership, or vCISO decision-making responsibilities.
Core Responsibilities
Cloud Governance & Compliance Operations
- Validate that client environments meet MGRC baselines and support ongoing security policy alignment to:
- Microsoft Cloud Security Benchmark (MCSB)
- NIST frameworks (NIST SP 800-171, NIST SP 800-53, etc.)
- HIPAA (where applicable)
- FedRAMP
- CMMC 3.0
- ISO 27001-2022
- GDPR
- Assist with governance documentation updates and maintenance
- Support compliance tracking and evidence organization
- Provide consultative guidance on compliance and security-related questions by coordinating access to Atmosera cybersecurity experts
- Monitor security posture through Defender for Cloud and Azure Policy compliance recommendations
- Track misconfigurations, policy drifts, and high impact findings for remediation.
Security Questionnaires
- Assist with basic security questionnaires using Atmosera's standard response library
- Provide standardized responses through coordination with the Account Management or Client Success team
- Support optional full Security Questionnaire Management services when contracted, including:
- Intake and tracking
- Drafting and coordination of responses
- Supporting documentation preparation
Audit & Assurance Support
- Participate directly in client audits (SOC 2, HIPAA, PCI where applicable)
- Support ongoing audit readiness and management activities when included in scope, including:
- Evidence gathering and organization
- Audit request tracking
- Coordination with internal teams and external auditors
- Ensure ongoing audit readiness for clients enrolled in MGRC that is consistent with MGRC service definitions in shared documentation
- Maintain audit readiness documentation throughout the year
- Maintain audit request trackers and coordinate responses with internal SMEs.
- Support project management activities related to compliance audits (e.g., SOC 2)
Security Operations Governance Support
- Ensure proper documentation to support compliance with client governance requirements and client specific requirements
- Take ownership of monthly and quarterly MGRC reporting
- Assist with the development and maintenance of custom response playbooks for:
- Azure Sentinel SOAR (Security Orchestration, Automation, and Response)
- Support governance oversight of:
- CyberSOC reporting with enhanced security insights
- Actionable threat intelligence reporting
- Proactive threat hunting outputs
- Ensure governance artifacts align with managed detection and response activities
Security Readiness & Preparedness Activities
- Coordinate and support:
- Monthly phishing simulation preparedness activities
- Yearly tabletop exercise planning and execution support
- Bi-annual penetration testing preparedness and coordination
- Track outcomes, findings, and remediation activities for readiness exercises
Attack Surface & Security Posture Management
- Support Attack Surface Management activities, including:
- Continuous discovery and monitoring of exposed assets
- Documentation of digital attack surface insights
- Assist with security posture tracking and compliance reporting for:
- Executives
- Auditors
- Internal stakeholders
- Monthly Server vulnerability Scanning
- Design and implement workflows that improve the service
- Track findings, prepare client-facing reports, and coordinate remediation with security engineers
- Penetration Test Coordination
- Serve as the primary coordinator for client penetration testing engagements
- Manage scheduling, scope alignment, retesting cycles, evidence handoff and management of the relationship with penetration testing teams.
- Maintain communication and set expectations with organizations being tested
Cloud Governance Support
- Support Azure Policy implementation and monitoring using advanced governance features
- Assist with ensuring Azure resources and configurations remain compliant with defined security baselines
- Track and report service misconfigurations, compliance drift and remediation status
- Monitor security posture through Defender for Cloud and Azure Policy compliance results
- Validate that client environments meet MGRC baselines. Microsoft Cloud Security Benchmarks, and any additional client-specific compliance requirements supported by Azure
Collaboration & Service Delivery
- Work closely with:
- Client Success Managers
- Security Analysts and Engineers
- CyberSOC teams
- Account Management representatives
- Escalate issues, risks, or scope concerns to appropriate senior resources
- Operate within defined MGRC service boundaries and SLAs
Purview Compliance Manager Administration
- Own and manage Purview Compliance Manager for all subscribed MGRC clients.
- Track regulatory control posture, improvement actions, and evidence assignments.
- Guide clients through remediation and maintain year-round compliance readiness.
- Partner with engineering teams on policy and control mappings (Azure Policy, Defender for Cloud) that support compliance scoring as discussed in internal service map documentation.
Required Skills & Experience
- 2+ years of experience in GRC, IT risk, compliance, or security operations support
- Hands-on experience with Microsoft Purview Compliance Manager, including control mapping, evidence tasks, and regulatory templates
- Familiarity with Defender for Cloud, including secure score, recommendations, and compliance dashboards
- Working experience with Azure Policy concepts including assignments, compliance scanning and configuring and remediation tasks
Familiarity with:
- NIST frameworks
- SOC 2 concepts
- CIS Controls
- HIPAA compliance
- Experience supporting audits, questionnaires, or compliance programs
- Strong documentation, evidence collection, and organizational skills
- Ability to manage multiple client workstreams simultaneously
- Strong public speaking and presentation skills using Microsoft PowerPoint
- SC-900 Microsoft Certified: Security, Compliance, and Identity Fundamentals – within 90 days of hire
Preferred Skills & Experience
- Prior experience in managed services or MSSP environment
- Experience coordinating penetration tests or annual security testing cycles
- Ability to translate technical findings into clear business-oriented summaries
- Familiarity with Entra ID, Azure RBAC, Conditional Access, and cloud governance fundamentals
- Comfort working with security engineering teams and client facing roles
- Certifications (any of the following):
- SC-100 (Microsoft Certified: Cybersecurity Architect Expert)
- ISC2 CISSP
$95k - $105k
...Job Description Job Description Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven... .... As a result of that, this role is only available as a 100% remote position if you reside in one of the following states: AL,...Remote workTemporary workCurrently hiringRelocation- ...Alignerr is seeking a Governance, Risk & Compliance (GRC) Analyst to work remotely on AI training projects. The ideal candidate will leverage their expertise in GRC to shape AI systems that navigate security policies and compliance. The position demands a minimum of 2...Remote work
$100k - $130k
...New American Funding is seeking an IT GRC Analyst II to join their Cybersecurity Services team. This role focuses on Governance, Risk, and Compliance (GRC) while managing external audits and ensuring compliance with legal and regulatory requirements. The ideal candidate...Remote work- ...Job Title: GRC (3rd Party Risk) Analyst Duration: 12 - 24 Month Project Engagement Role Summary: The GRC Analyst is responsible for managing Client's governance, risk, and compliance functions, with a specific focus on third-party risk management. This role ensures...Remote work
- ...Alignerr is looking for a Governance, Risk & Compliance (GRC) Analyst to work remotely on developing and evaluating AI systems. This role requires expertise in compliance programs and risk assessments, focusing on real-world security policies and regulatory frameworks....Remote workFlexible hours
- ...Bamboo Health, Inc. is seeking a Senior Governance, Risk and Compliance (GRC) Analyst to enhance their compliance program and support auditing efforts. The role involves evaluating organizational policies and ensuring adherence to compliance requirements while working...Remote work
- ...GRC Analyst II The Governance, Risk, and Compliance (GRC) Analyst II configures, implements, and manages security devices through strategic... ...4350 Centennial Blvd., Colorado Springs, CO, 80907, US (Remote) Work Schedule 9/80 Rotation A - Exempt Minimum Salary 7...Remote workFull timeImmediate start
- ...System One is hiring a Governance Risk & Compliance Analyst in Lakewood, CO. In this hybrid role, you will support the Global Information... ...skills, and knowledge of ISO 27001 regulations. This position offers a combination of onsite and remote work. #J-18808-Ljbffr...Remote workWork at office
- A cybersecurity firm is seeking an Entry-Level GRC Analyst in Fort Worth, Texas. This remote position focuses on helping clients strengthen their cybersecurity and compliance programs through various assessments and processes. Ideal candidates should have a relevant degree...Remote workPermanent employment
$130k - $175k
...GRC Analyst United States - Remote At Mesh, our mission is to enable consumers to pay and be paid with any asset. Today, trillions of dollars in tokenized assets exist but remain largely unusable for everyday commerce. Mesh is bridging this gap by making crypto payments...Remote workWork at office2 days per week- ...Governance, Risk & Compliance (GRC) Analyst We're looking for experienced GRC professionals to help build and evaluate AI systems that... ...Organization: Alignerr Type: Hourly Contract Location: Remote Commitment: 10–40 hours/week What You'll Do Review...Remote workHourly payOngoing contractContract workFreelanceFlexible hours
- ...Hotman Group is seeking an Entry Level GRC Analyst to work remotely in the USA. The role involves assessing client security, developing risk frameworks, and translating technical requirements into actionable steps. Candidates should possess a relevant degree and 1-2 years...Remote work
- Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs... ...Organization : Alignerr Type : Hourly Contract Location : Remote Commitment : 10-40 hours/week What You'll Do Review...Remote workHourly payOngoing contractContract workFreelanceFlexible hours
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We partner with the world's leading AI research labs to... ...Organization : Alignerr Type : Hourly Contract Location : Remote Commitment : 10-40 hours/week What You'll Do...Remote workHourly payOngoing contractContract workFreelanceWorldwideFlexible hours
- ...Governance, Risk & Compliance (GRC) Analyst We're looking for experienced GRC professionals to help train and validate cutting-edge AI... ...Organization: Alignerr Type: Hourly Contract Location: Remote Commitment: 10–40 hours/week What You'll Do Review...Remote workHourly payOngoing contractContract workFreelanceFlexible hours
- ...Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for... ...day one. This is a full-time, remote, contract-to-hire position. Top... ...Will Do As an Entry Level GRC Analyst at Hotman Group you will work side by side...Remote workPermanent employmentFull timeContract workWork experience placementWork at office
$74.58k - $120k
...GRC Analyst Apply Online Tyler Technologies is seeking a Governance, Risk, and Compliance (GRC) Analyst to support our Data &... ...data-driven future. Location Seattle, Washington | Remote Responsibilities Own FedRAMP Moderate authorization...Remote workLocal areaShift work- ...benefits and wellness support Flexible work model: hybrid, remote, or in-office Real growth opportunities and leadership visibility... ...wins together About the role The Mid-Level GRC Analyst operates at the intersection of compliance, risk, and operational...Remote workWork at officeFlexible hours
- ...class service in the rental residential real estate business. To learn more, visit . JOB DESCRIPTION SUMMARY The Senior GRC Analyst is responsible for executing the day-to-day activities of the Global Information Security Governance, Risk, and Compliance (GRC)...Remote workFull timeContract workWork experience placementLocal areaImmediate start
- ...Senior GRC Analyst Palo Alto, California Workato delivers enterprise infrastructure for the agentic era, redefining iPaaS and helping... ...in North America Quartz ranked us the #1 best company for remote workers Responsibilities Workato is seeking a detail-...Remote workFlexible hours
- ...schedule with 4 days in the office; and 1 day remote. The company is an equal opportunity... ...Responsibilities As a Governance, Risk, & Compliance Analyst , you willsupport the W. R. Berkley... ...and industry standards. In addition, the GRC Analyst assists in the development,...Remote workFull timeWork at officeLocal areaVisa sponsorship
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research... ...Organization : Alignerr Type : Hourly Contract Location : Remote Commitment : 10-40 hours/week What You'll Do...Remote workHourly payOngoing contractContract workFreelanceFlexible hours
- ...Principal GRC Analyst | Deltek, Inc Principal GRC Analyst US (Remote) Deltek is the intelligent, industry-tuned platform that powers the project lifecycle – from ERP and accounting to delivery and analysis. Trusted by 30,000 organizations, Deltek delivers speed...Remote work
- ...Location : Remote Reports to : GRC Manager Time commitment : minimum 20 hours weekly Headcount: 2 people Summary: The GRC analyst with a legal background is a critical hire for our rapid team. You will be responsible for building and maintaining the...Remote work
- ...visit The Opportunity We are hiring a Security GRC & Risk Analyst to own the governance, risk, and compliance execution layer... ..., and relevant education or training. For roles eligible for remote work, the base salary is tailored to the designated work location...Remote workFull timeTemporary workLive outWork at office
- Alignerr is seeking a Governance, Risk & Compliance (GRC) Analyst to work on AI systems evaluating security and compliance. This is a unique... ...your expertise in GRC and risk management in a flexible remote role. The ideal candidate will have over 2 years of experience...Remote jobFlexible hours
$95k - $115k
...company specializing in identity verification is looking for an Analyst in GRC for the public sector. This role involves enhancing governance... ...cybersecurity and must be a U.S. Person. The company offers remote work opportunities and a competitive salary range of $95K to $...Remote job- ...Location: Remote Reports to: GRC Manager Time commitment: minimum 20 hours weekly Summary: As we grow, the protection of our customers... ...and proactive Governance, Risk, and Compliance (GRC) Analyst to help build and mature our data protection aspect. This role...Remote work
- ...people working all over the world, including Canada, Spain, Switzerland, the United Kingdom, the United States and more! Sr. GRC Analyst, Privacy Benevity is seeking a Sr. GRC Analyst, Privacy to anchor and advance our data protection program across a complex, multi...Remote workWork at officeFlexible hours
- CybSafe is seeking an Analyst, GRC - Public Sector to enhance governance, risk, and compliance operations. You will manage compliance efficiency and audit readiness for the public sector. Your role includes coordinating Third Party assessments, overseeing continuous monitoring...Remote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst (Remote - LATAM). Be the first to apply!
- grc analyst United States
- remote quality assurance United States
- remote wordpress developer United States
- remote accounts payable United States
- remote gis United States
- entry level remote United States
- remote medical billing part time United States
- sales engineer remote United States
- remote dba United States
- career coach remote United States


