Senior GRC Analyst
$88k - $121kFlagship Pioneering
About the Role Flagship's GRC program has matured from build to operate. We have a functioning GRC system of record in Jira, active compliance tracks across HITRUST, NIST 800-171, ISO 27001, and SOC 2, and a TPRM workflow in production. What we need now is a hands‑on practitioner who can execute against that infrastructure — someone who is as comfortable running a vendor risk assessment in Jira as they are prepping evidence packages for an audit. This is not a policy‑writing or director‑level role. It is a technical execution role for someone who gets things done. What You’ll Do Own day‑to‑day execution of the GRC system of record in Jira — maintaining control records, updating compliance status, logging implementation and auditor notes, and keeping the SOR current across all active frameworks Run TPRM assessments end‑to‑end: intake, questionnaire review, risk scoring, CISO decision documentation, and post‑approval tracking Coordinate audit evidence collection and control testing activities across HITRUST, ISO 27001, SOC 2, and NIST 800-171 frameworks, working directly with the external audit firm Maintain the compliance calendar and drive sprint‑by‑sprint execution against framework deadlines Manage sub‑processor and DPA tracking for portfolio company privacy programs, including gap identification and remediation follow‑up Support DSR and privacy program operations, including data inventory maintenance and deletion workflow tracking Build and maintain GRC automation using AI tools (Claude, Jira automation, Zapier) to reduce manual burden on recurring compliance tasks Produce clear, accurate reporting on compliance posture for the CISO and cross‑functional stakeholders What We’re Looking For 3–6 years of hands‑on GRC experience, ideally in a fast‑moving tech or life sciences environment Direct experience working in Jira as a compliance or GRC tool — not just a project management tool; you should understand issue types, custom fields, bulk operations, and reporting Working knowledge of at least two of: HITRUST CSF, ISO 27001, NIST 800-171/CMMC, SOC 2, HIPAA Experience running vendor risk assessments — intake to decision — not just filling out questionnaires Comfort with AI‑assisted work: you should already be using tools like Claude or ChatGPT to accelerate your GRC work, not learning to do so for the first time Strong written communication — you'll be producing evidence narratives, audit responses, and control documentation that external auditors and regulators will read Ability to operate with high autonomy; the CISO will provide direction but not day‑to‑day supervision Nice to Have CISA, CRISC, CISM, or equivalent certification Experience with privacy program operations (CCPA, GDPR, DSR workflows) Familiarity with Drata, Vanta, or similar compliance automation platforms Experience supporting a portfolio company or multi‑entity compliance program Why This Role You’ll own a real compliance program, not support someone else’s. The CISO is your direct partner, not a distant approver. You’ll use modern tools — Jira, Claude, Zapier — to do GRC work that most teams still do in spreadsheets. And you’ll have visibility into a genuinely diverse security environment spanning drug discovery AI, clinical platforms, and life sciences infrastructure. Salary and Benefits The salary range for this role is $88,000 - $121,000. Compensation for the role will depend on a number of factors, including a candidate’s qualifications, skills, competencies, and experience. Flagship Pioneering currently offers healthcare coverage, annual incentive program, retirement benefits and a broad range of other benefits. Compensation and benefits information is based on Flagship Pioneering's good faith estimate as of the date of publication and may be modified in the future. Equal Opportunity Employer All qualified applicants will be considered for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by law. #J-18808-Ljbffr Flagship Pioneering
$95k - $110k
...has earned consistent recognition from customers and industry analysts alike. WHY BLACK KITE We’re a fast-moving, high-impact... ...matters — you’re in the right place. THE OPPORTUNITY The Senior GRC Analyst reports to the Director of Information Security and...SeniorWorldwideFlexible hours$95k - $110k
Blackkite in Boston seeks a Senior GRC Analyst to manage compliance platforms and customer security assessments. The ideal candidate will have 2-4 years in GRC or information security, paired with skills in SOC 2 and ISO 27001. You'll support FedRAMP ConMon reporting and...Senior- ...Title: GRC Analyst Location MassDOT, 10 Park Plaza, Boston, MA 02116 Duration: 1 year W/possible extensions Skill Set - disaster recovery, IT, Hours / Shift: Monday -Friday 9:00 to 5:00 40 hour work week Notes: . 37.5...SuggestedFor contractorsWork at officeRemote workMonday to FridayFlexible hoursShift work
$60k - $90k
...GRC Analyst, Operations & Risk As a GRC Analyst, Operations & Risk, you will support the WHOOP Governance, Risk, and Compliance program by helping manage GRC intake, coordinate third-party risk activities, strengthen operational workflows, and improve visibility across...SuggestedFull timeWork at officeRelocation$75 per hour
...We're looking for a hands-on ServiceNow GRC Analyst to join a growing Security organization and support the implementation of an established security control framework across SaaS applications. This is an execution-focused role, not a strategy or architecture position....Suggested- ...Information Security Governance, Risk and Compliance (GRC) Analyst The ideal candidate is a self-starter with a passion for building relationships and collaboration. The candidate should have strong written and verbal communication skills. Sample Duties and Responsibilities...
- Northeastern University is hiring a Governance, Risk and Compliance Analyst in Boston. This hybrid role involves supporting compliance initiatives and NIST frameworks in government and higher education environments. The ideal candidate will have a Bachelor's degree, 2-4...
$75 per hour
Insight Global is seeking a ServiceNow GRC Analyst in Boston to join a growing Security team. This role will be responsible for operationalizing security controls in ServiceNow across SaaS applications, working closely with system owners and technical leads. The ideal candidate...- Alignerr is seeking a Governance, Risk & Compliance (GRC) Analyst to collaborate with top AI research labs on groundbreaking projects. In this role, you'll review security policies and evaluate compliance scenarios to improve AI reasoning. The position offers fully remote...Remote jobFlexible hours
$88k - $121k
Flagship Pioneering in Cambridge, MA, is seeking a GRC Specialist to own the execution of their GRC program. You will utilize Jira to manage compliance activities across frameworks like HITRUST and NIST. Ideal candidates have 3-6 years of relevant experience and are comfortable...$60k - $90k
Whoop is searching for a GRC Analyst in Boston, MA, to enhance the Governance, Risk, and Compliance program. This role involves managing GRC intake processes, coordinating third-party risk reviews, and ensuring effective compliance operations. The ideal candidate will have...- ...Senior Regulatory Affairs Manager- REMOTEI'm looking for a senior manager, regulatory affairs to lead our growing, dynamic team through global phase 3 clinical trials of a certain product and support other clinical studies. This role includes driving global submission...Senior
- ...strategies and have a function and may have a companywide impact. The AD will typically collaborate, influence and negotiate with senior Nonclinical / Clinical leaders on product strategies and actions leveraging their advanced Nonclinical / Clinical knowledge....Senior
- Responsibilities: Real-time Inspection Readiness. Develop, manage and contribute to ongoing maturity of GMP and GDP Inspection Readiness Plans associated with regulatory filings and real-time inspection readiness activities. Work directly with CMOs and ...SeniorWork experience placement
- ...A leading technology firm in Boston seeks a Senior Industry Principal to advise C-suite stakeholders on supply chain transformation. This remote position requires 10-15 years of experience in consulting or industry leadership. The ideal candidate will possess deep expertise...SeniorRemote work
- ...Senior Manager, RDQ Compliance The Senior Manager, RDQ Compliance is responsible for leading quality assurance and compliance activities in support of Compliance and Issues Management. This role requires expertise in overseeing investigations, root cause analysis,...SeniorWork experience placement
$74k - $118k
...A healthcare compliance organization is seeking a Senior Compliance Analyst to implement compliance programs and manage incident responses. The role involves collaborating with stakeholders, conducting analyses, and developing reporting insights. Candidates should have...SeniorRemote work$70k - $80k
A leading financial institution based in Boston is seeking a Senior Risk Analyst to assess and execute control monitoring and testing programs. Responsibilities include collaborating with risk teams, implementing continuous testing, and supporting assessments. The ideal...Senior- ...About the Company : A growing biopharmaceutical portfolio focused on innovative therapies. About the Role : The Manager/Senior Manager, Regulatory Affairs — Advertising, Promotion & Labeling is responsible for supporting U.S. promotional regulatory strategy and related...Senior
- A leading global consulting firm is looking for a Senior Consultant to join their Risk Technology practice in Boston. In this role, you will assess, design, and implement integrated risk management solutions for diverse clients. Ideal candidates have a Bachelor’s in a...Senior
- A leading cancer research organization located in Brookline is seeking a Regulatory Compliance Director to develop and oversee a comprehensive compliance program. The ideal candidate will have significant experience in regulatory healthcare compliance and leadership. This...Senior
- A leading global financial services firm in Boston is looking for an ERM Analyst to drive risk management efforts. The successful candidate will identify, assess, and mitigate operational risks while collaborating with various teams. This role requires a Bachelor's degree...Senior
- A biopharmaceutical company in Cambridge is seeking a Senior Director, Regulatory Affairs to lead regulatory strategies for new treatments related to kidney disease. The ideal candidate has over 8 years of experience in the pharmaceutical industry, with successful submissions...Senior
- ...Senior Executive Director, Regulatory Affairs About the Company Well-funded clinical-stage biotech company Industry Biotechnology Type Privately Held About the Role The Company is seeking a Senior Executive Director for Regulatory Affairs to play...Senior
- Initial Therapeutics, Inc. is seeking a seasoned professional for a role in Global Regulatory Affairs, focusing on Chemistry Manufacturing & Controls. The successful candidate will lead the development of regulatory CMC strategies and manage submissions critical to product...Senior
- A medical device company in Cambridge, MA, is seeking a Regulatory Affairs professional to lead regulatory strategies for Class II medical devices. Responsibilities include managing FDA submissions, ensuring regulatory compliance throughout product development, and collaborating...Senior
- ...scenarios that align with global regulatory expectations and business objectives. • Collaborate closely with cross-functional teams and senior leadership to drive clarity, alignment, and accountability for regulatory deliverables, timelines, and interdependencies. •...SeniorWork at officeRemote workWork from homeWorldwide
$137k - $215.27k
By clicking the “Apply” button, I understand that my employment application process with Takeda will commence and that the information I provide in my application will be processed in line with Takeda’s Privacy Notice and Terms of Use. I further attest that all information...SeniorMinimum wageTemporary workLocal areaImmediate startRemote workWorldwide$46.99k - $112.2k
CVS Health is seeking a Senior Investigator to conduct complex investigations involving healthcare fraud and abuse. The candidate will investigate Medicaid-related claims, analyze data, and collaborate with law enforcement agencies. Required qualifications include over...SeniorFull time- ...locations, doing different roles, all united by one thing: a desire to make miracles happen. So, let's be those people. As the Senior Manager, Regulatory Affairs Advertising and Promotion within our GRA Advertising and Promo Team, you will be responsible for conducting...SeniorWork experience placement
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!
- senior development executive Cambridge, MA
- senior manager data science Cambridge, MA
- senior platform engineer Cambridge, MA
- senior procurement Cambridge, MA
- senior director product management Cambridge, MA
- senior electronic design engineer Cambridge, MA
- senior manager customer operations Cambridge, MA
- senior data engineer Cambridge, MA
- senior manager clinical operations Cambridge, MA
- senior vmware engineer Cambridge, MA

