GRC Analyst
Virtru
About Virtru:
While the rest of the security industry obsesses over locking data down to prevent it from being lost or stolen, we're doing something fundamentally different at Virtru. We're setting data free so that you can intentionally share it with others, but without sacrificing security, privacy, or control.
We've created both a suite of powerful data protection applications and an open platform that's sparking an ecosystem of innovation. Through the Trusted Data Format (TDF) open standard, we're not just protecting data; we're creating a new paradigm where security enables sharing rather than preventing it.
Think of us as the Android of data protection: a robust platform with an open core that developers and partners can build upon, coupled with our own best-in-class applications that showcase what's possible when you reimagine security from the ground up.
Backed by Iconiq Capital, Bessemer Venture Partners, Foundry Capital, and Tiger Global, we're helping Fortune 500 companies and government agencies discover that true data security means having the freedom to share, collaborate, and innovate — without compromise.
Team & Position Details:
Here at Virtru you’ll help build a cutting edge security compliance program aligned with FedRAMP, SOC 2, PCI, HIPAA, GDPR, and just about any other security/privacy framework you can think of, whilst getting your hands on some of today’s most important tools and tech like Kubernetes, GCP, AWS, Terraform. We put a high value on input from everyone on our team. Your voice will have a significant impact. With a constantly growing customer base, there is no shortage of challenging and exciting scaling/optimization work to ensure that we can provide the most secure and performant service.
As a GRC Analyst at Virtru, you will be the primary point of contact for compliance-related inquiries. You will lead and manage the organization's efforts to achieve and maintain CMMC compliance, by conducting gap analyses and developing a roadmap to address compliance requirements. You will also play a vital role in supporting our existing FedRAMP, SOC2, and PCI DSS compliance.
Get in touch if you are excited to help us grow into a world-class security compliance program.
As a Security Governance Risk & Compliance (GRC) Analyst, your responsibilities will include:
- Manage and implement complex controls frameworks for large systems, consisting of Cloud infrastructure and Software as a Service (SaaS) services (GCP, AWS, GitHub, Okta, etc).
- Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
- Conduct risk assessments across business units and processes. Identify risk findings and recommend remediation and risk mitigation strategies.
- Participate in incident response (IR) activities, providing risk analysis and remediation support as needed.
- Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders.
- Incorporate CMMC certification into Virtru’s slate of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI).
- Facilitate the third-party vendor on-boarding and annual review process by evaluating the security of current and prospective partners.
- Enhance the team with your individualism, spirit, and love of learning.
Skills that will help you thrive in this role:
- Minimum of 5+ years of information security, IT audit and/or IT Risk Management, or GRC Analyst/Engineer experience
- Deep understanding of at least few of the following: CMMC, NIST 800-53 & 800-171, FedRAMP, SOC 2, PCI, and/or other global privacy compliance frameworks
- Technical acumen. Strong understanding of modern cloud technologies (AWS, GCP, Azure, etc.) and familiarity with GRC tools (Hyperproof, Vanta, Drata, etc) and SIEM tools (Datadog, Splunk)
- You’re a relationship builder and have worked with both business and technical risk and understand how to translate risk to various levels of the organization
- Have experience training and coaching teams to become better security and privacy practitioners
- Like working on an autonomous agile team. At Virtru, you will have ownership of security, but you’ll collaborate with everyone to make sure we produce and implement the right solutions
- Ability to resolve conflicts and drive issues to completion.
- Work independently with little or no supervision while maintaining a high level of efficiency.
Virtruvian qualities that will set you up for success:
- Thinking outside of the box to respectfully challenge your teammates and managers in the pursuit of excellence
- Strong sense of urgency with an action-oriented mindset
- Able to collaborate and adapt to shifting priorities as business needs evolve
- Comfortable with asynchronous communication including slack, email, zoom, etc.
Perks & Benefits:
At Virtru, we believe people do their best work when their wellbeing is put first. This is why we make your wellbeing our priority with a thoughtful and holistic program that encompasses Occupational, Mental, Social, Physical, and Environmental Wellness by offering benefits such as…
- A Flexible PTO policy — we strongly encourage you to take time off (in addition to 14 holidays) to ensure that you are getting the proper time needed to unplug and recharge.
- A $1,500 annual Learning & Development Stipend focused on providing you the resources to continually learn and professionally grow.
- Frequent company-sponsored team celebrations that provide ample opportunities to connect with teammates and be social!
- Access to an Employee Assistance Program
- Access to Headspace, a mental health app tailored to your specific needs.
- A flat 3% contribution to your retirement account
- A high degree of flexibility— Have an appointment, errand, or family emergency to take care of? Hop to it! We give you the time and space to take care of you and your own first.
In addition to wellbeing, Virtru places a strong emphasis on diversity, equity, inclusion, and belonging. Our DB&I Council is dedicated to fostering an inclusive workplace and making the psychological safety of each and every one of our teammates a top priority.
Additional perks include:
- Competitive compensation
- Generous parental, medical, and bereavement policies
- Uncapped commissions for Sales roles
- 401K contribution and stock options
- Full medical, dental, and vision benefits
- New Hire Swag and IT Welcome boxes
- Structured semi-annual 360° performance reviews
$80.05k - $165k
...end-to-end issue management activities, including intake, validation, prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate evidence, and alignment with audit, risk, and regulatory...SuggestedFull timeWork at office$134k - $202k
...our customers, growing our community, or shaping our story, you’ll help define what comes next.About the role:We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance...SuggestedWork at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours- ...Governance, Risk & Compliance (GRC) Analyst Job Category : Information Technology Requisition Number : GOVER001449 Posted : July 1, 2026 Full-Time Hybrid Locations Showing 1 location Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk...SuggestedFull timeCasual workWork at officeWork from homeHome officeNight shiftWeekend work
- ...The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides strategic oversight of cyber and IT operational risk assessments, regulatory...SuggestedFull timeWork experience placementWork at office
- ...external audit activities Develops, maintains, and reports on operational compliance metrics General Governance, Risk, and Compliance (GRC) Support Leads process analysis, development, & improvement efforts Assists in developing, testing, and delivering solutions, support...SuggestedWork experience placementWork at officeLocal areaRemote workRelocation
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're looking for experienced GRC professionals to help evaluate and improve AI systems being trained on real-world security, compliance, and risk scenarios. Your practitioner knowledge...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We partner with the world's leading AI research labs to build smarter, safer AI systems - and we need practitioners who know how compliance and risk management actually work in the real...Hourly payOngoing contractContract workFreelanceRemote workWorldwideFlexible hours
- ...Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports the Information Technology, Information Systems, and other technology teams aligned under the Chief Information Officer. This role executes governance, risk, and...Work at officeRemote work
- ...Governance, Risk & Compliance (GrC) Analyst We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI — and we need practitioners who know how GRC actually works in the real world. Your expertise in security policies, compliance...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, more reliable AI systems - and we need practitioners who know how GRC actually works in the real world. If you've...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...raised our Series B and have grown 800% over the last 12 months. The Opportunity Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives. This role will play a key part in...Contract workWork at officeRemote workVisa sponsorshipRelocation packageFlexible hours
- ...Job Title: GRC (3rd Party Risk) Analyst Duration: 12 - 24 Month Project Engagement Role Summary: The GRC Analyst is responsible for managing Client's governance, risk, and compliance functions, with a specific focus on third-party risk management. This role ensures...Remote work
$30 - $55 per hour
...Governance, Risk & Compliance (GRC) Analyst $30-55/hr Remote Freelance CODING About the Role We're looking for experienced GRC professionals to help train and evaluate cutting-edge AI systems. At Alignerr, we partner with the world's leading AI research labs —...Ongoing contractFreelanceRemote workFlexible hours- ...best company for remote workers Responsibilities Workato is seeking a detail-oriented, driven, and technically experienced Senior GRC Analyst to strengthen and advance its security governance, risk, and compliance (GRC) program - with a primary focus on FedRAMP...Remote workFlexible hours
- ...IT Security GRC Analyst (2 Openings) Location: Charlotte, NC (Hybrid Schedule) 2 days onsite / 3 days remote Employment Type: 3-Month Contract-to-Hire (W2 through Everforth Apex Systems) About the Opportunity Everforth Apex Systems is seeking 2 IT Security GRC Analysts...Permanent employmentContract workImmediate startRemote work
- ...To enhance the security framework of a growing organization, the full-time remote GRC Analyst will design, implement, and manage control and risk workflows, perform third-party risk assessments, and ensure compliance with industry standards and regulations. Key responsibilities...Full timeRemote work
$95k - $150k
...high level of security assurance to customers, aligning security goals with business objectives and customer requirements. As a GRC Analyst at Zip, you'll be a key driver for ensuring the success of compliance programs at a fast-growing company. Your contributions will...Home officeFlexible hours$105k - $135k
...Join Aya Healthcare, winner of multiple Top Workplace awards! We are seeking a Senior Governance, Risk & Compliance (GRC) Analyst to help operate and mature Aya’s enterprise GRC program, with a strong emphasis on compliance automation, scalability, and operational excellence...Full timeLocal areaRemote work$70k - $88k
...across various U.S. locations and offer co-managed IT solutions as well. Job Overview Coretelligent is seeking a diligent GRC Analyst to join our team. This role will serve as a key contributor to Coretelligent's holistic cybersecurity solutions by managing critical...Full timeRemote workFlexible hours$127.2k - $205.1k
...orchestrate their most critical business processes, and that trust is something we earn every single day. As our Senior InfoSec GRC Analyst, you will join a small, senior, and highly collaborative InfoSec team that lives our FAITH values (Focus, Ambition, Integrity, Talent...Full timeWork at officeLocal areaRemote workWork from homeWorldwideHome officeFlexible hours$55 - $80 per hour
...IT GRC Analyst Remote, USA Compensation: $55 - $80 per hour Contract Length: 6-month Contract to Hire Hours: Standard full-time schedule, 8 hours/day, 5 days/week; potential for extended hours under heavy audit or incident response activity. Start...Hourly payFull timeContract workWork at officeLocal areaImmediate startRemote workFlexible hours$100.8k - $168k
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being...$99k - $225k
Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and technical...Full timeContract workPart timeWork at officeLocal areaRemote work$70k - $88k
...This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC Analyst based in United States. This is a governance, risk, and compliance role supporting cybersecurity programs across diverse...Full timeRemote workFlexible hours$150k - $200k
...Ventures, we are building the infrastructure for the next era of the global economy. Join us! Overview We're hiring a GRC Senior Analyst to help build the compliance foundation powering the future of global crypto payments. At Mesh, we're connecting hundreds of...Work at officeRemote work2 days per week- ...Job Description Job Description Governance, Risk & Compliance (GRC) Analyst – State Agency – $40-46/hr W2 – Phoenix Hybrid – Contract-to-Hire SunSoftOnline is hiring a GRC / Information Security Analyst for an Arizona state agency's technology division, a 4-month...Permanent employmentFull timeContract workRemote workVisa sponsorshipMonday to Friday
- ...We are seeking a highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team. In this role, you will own and grow RainFocus's governance, risk, and compliance program — maintaining our control framework, leading risk assessments, supporting...Full time
- ...challenging and exciting scaling/optimization work to ensure that we can provide the most secure and performant service. As a GRC Analyst at Virtru, you will be the primary point of contact for compliance-related inquiries. You will lead and manage the organization's...Full timeFlexible hoursShift work
- Description The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader IT...Work at officeRemote work
- Position Summary The Federal Exchange GRC Analyst owns federal Health Insurance Exchange and Enhanced Direct Enrollment compliance for the health business, including Audit Readiness Certification and Annual Marketplace Privacy Evaluation obligations and Centers for Medicare...Work at officeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!



