Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Analyst

Upwind

GRC Analyst Opportunity

Upwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical risks, providing precise insights and efficient cloud security management. With industry-leading efficiency and eBPF-powered sensors, Upwind delivers comprehensive capabilities including agentless cloud posture discovery, real-time threat protection, and integrated API security. We are one of the fastest-growing companies in cloud and AI security, and we're building the GTM engine to match.

We are looking for a motivated and resourceful GRC Analyst to join our growing Security & Compliance team.

This is a hands-on role for someone who enjoys solving problems, takes ownership of their work, and is comfortable operating in a fast-paced environment where processes are continuously evolving and improving. We are looking for someone who is curious, willing to dig into unfamiliar topics, and comfortable finding practical ways to solve compliance and security challenges.

The GRC Analyst will support our core GRC functions - including risk assessments, internal audits, policy governance, third-party risk, customer trust and assurance, and compliance programs - while also serving as a practical partner to teams across the company. This role should be able to move beyond identifying a gap or requirement and help teams understand what good remediation looks like and how to build sustainable processes to address it. We also want someone who is comfortable using modern cloud-based security, compliance, automation, and AI-enabled tools to make GRC work more effective and scalable.

We also value people who have experience in using AI and automation to make GRC work smarter and more scalable, while applying appropriate judgment and validation to the output.

What You'll Do

  • Operate and improve Upwind's GRC and security compliance programs
  • Support compliance work across SOC 2, ISO 27001, NIST, and FedRAMP, including control implementation, evidence collection, documentation, remediation tracking, continuous monitoring, and audit readiness
  • Coordinate audit and compliance evidence from Engineering, IT, Security, Legal, and HR
  • Translate compliance requirements into clear actions for technical and business teams
  • Perform control assessments, gap analyses, and risk assessments, and recommend how to fix what you find
  • Work with process owners to build remediation that holds up over time and can be evidenced
  • Track vulnerabilities, risks, audit findings, and POA&Ms through completion
  • Handle customer security questionnaires, due diligence requests, and security documentation
  • Support third-party risk management and vendor security assessments
  • Write and maintain policies, standards, procedures, and control documentation
  • Maintain GRC systems, evidence repositories, and risk registers
  • Research new regulatory and customer requirements and determine how they apply to us
  • Use AI and automation to speed up research, documentation, evidence organization, and workflow, with appropriate validation and data handling
  • Raise gaps and issues early, with a proposed fix

Requirements

  • 3 to 5 years in GRC, cybersecurity, risk management, compliance, or audit. We'll consider less conventional backgrounds if the relevant experience is there.
  • Familiarity with NIST 800-53, SOC 2, ISO 27001, NIST CSF, or similar frameworks
  • Experience supporting audits, assessments, security questionnaires, or evidence collection
  • Strong written communication and documentation skills
  • Enough technical fluency to work effectively with Engineering, IT, and Security
  • Ability to turn audit findings into remediation plans that process owners will actually adopt
  • Comfort working in a fast-moving environment where priorities shift
  • Ownership. You drive assigned work to a conclusion and flag blockers rather than waiting.
  • Curiosity. You can research an unfamiliar requirement and figure out the right questions to ask.
  • Demonstrated use of technology to improve GRC work: risk analysis, evidence collection, control monitoring, remediation tracking, research, customer trust, or workflow automation
  • Organized and detail-oriented

Nice to Have

  • FedRAMP, NIST 800-53, or other U.S. government compliance experience, including POA&Ms, continuous monitoring, or assessment activities
  • Experience working with external assessors on formal readiness or assessment activities
  • Cloud security experience, particularly AWS or AWS GovCloud
  • Background in SaaS, cloud security, or a high-growth technology company
  • Experience with a global, distributed workforce across time zones
  • Hands-on experience with cloud-based GRC, compliance automation, or AI-enabled workflow platforms
  • Experience building GRC automations, integrations, or dashboards
  • Familiarity with Jira, GitHub, or similar tools
  • Certifications such as Security+, CISA, CRISC, CISM, CGRC, or ISO 27001
  • Relevant certifications such as Security+, CISA, CRISC, CISM, CGRC, ISO 27001, or similar.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the GRC Analyst in United States vacancy
  •  ...GRC Consultant (Auditing, Oracle EBS applications) Remote   Job Summary We are looking for a GRC Analyst with strong experience in IT auditing, Governance, Risk & Compliance (GRC), and Oracle E-Business Suite (Oracle EBS) . The candidate will be responsible... 
    Suggested
    Remote work

    Arnex Solutions LLC

    United States
    2 days ago
  •  ...A dynamic cybersecurity firm is looking for a detail-oriented Entry-Level GRC Analyst to join their remote team. In this role, you'll work closely with senior members to strengthen client cybersecurity and compliance programs. You'll be involved in assessing controls,... 
    Suggested
    Remote work

    Hotman Group, LLC

    United States
    3 days ago
  •  ...GRC Analyst Company: Corpay Work Type: Remote Employment: Full Time Location: US Seniority: Senior Level Technologies: ServiceNow, Unix/Linux, Microsoft Office Suites, SQL Requirements: 5+ years IT risk/audit or IS compliance; certifications (CISA/CISM/CISSP/CPA/CIA/CGEIT... 
    Suggested
    Full time
    Work at office
    Remote work

    Corpay

    United States
    1 day ago
  • $55 - $80 per hour

    IT GRC Analyst Remote, USA Compensation: $55 - $80 per hour Contract Length: 6-month Contract to Hire Hours: Standard full-time schedule, 8 hours/day, 5 days/week; potential for extended hours under heavy audit or incident response activity. Start Date: ASAP... 
    Suggested
    Hourly pay
    Full time
    Contract work
    Work at office
    Immediate start
    Remote work
    Flexible hours

    Medasource

    United States
    12 hours ago
  •  ...To support a growing Security & Compliance team, the full-time remote GRC Analyst will manage and enhance GRC functions, including risk assessments, compliance programs, and internal audits, while collaborating across departments to ensure effective remediation and sustainable... 
    Suggested
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    2 days ago
  • $105k - $135k

     ...Join Aya Healthcare, winner of multiple Top Workplace awards!  We are seeking a Senior Governance, Risk & Compliance (GRC) Analyst to help operate and mature Aya’s enterprise GRC program, with a strong emphasis on compliance automation, scalability, and operational... 
    Local area
    Remote work

    Aya Healthcare

    United States
    1 day ago
  •  ...Location : Remote Reports to : GRC Manager Time commitment : minimum 20 hours weekly Headcount: 2 people Summary: The GRC analyst with a legal background is a critical hire for our rapid team. You will be responsible for building and maintaining the... 
    Remote work

    Menzies Philanthropic Foundation

    Little Elm, TX
    4 days ago
  • $175k

     ...deployment, turning real-world deployment signals into better data, evaluations, and more capable models. Learn more at   Senior GRC Analyst About the role We're looking for a Senior GRC Analyst to help run our governance, risk, and compliance program day to... 
    Remote work

    Turing

    United States
    12 hours ago
  •  ...To support the security program, the full-time Senior GRC Analyst will develop, maintain, and assess an integrated security and privacy management framework while managing compliance with industry standards and leading risk assessments, all in a remote capacity for candidates... 
    Full time
    Work experience placement
    Remote work

    Virtual Vocations Inc

    United States
    3 days ago
  •  ...The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader IT department to... 
    Work at office
    Remote work

    CMG Financial

    United States
    2 days ago
  •  ...just a goal; it's a daily practice! For more information, please visit The Opportunity We are hiring a Security GRC & Risk Analyst to own the governance, risk, and compliance execution layer across a holding company and portfolio of businesses. This is a... 
    Full time
    Temporary work
    Live out
    Work at office
    Remote work

    Momentum

    Dallas, TX
    2 days ago
  •  ...Senior GRC Analyst | Deltek, Inc As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are... 
    Contract work
    For contractors
    Remote work

    Deltek

    United States
    3 days ago
  •  ...GRC Analyst We are looking for an individual who is personable, comfortable working within a growing & supportive environment and capable of building processes within new and existing technologies to showcase cybersecurity to IT and business leadership. This position... 
    Remote work

    Software Technology Inc

    Conshohocken, PA
    3 days ago
  • $100k - $135k

     ...builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our expanding Security team. Reporting to the Senior Manager, GRC, you will mature information security policies, drive... 
    Temporary work
    Work at office
    Local area

    King River Capital Group

    Los Angeles, CA
    12 hours ago
  • $80.05k - $165k

     ...to-end issue management activities , including intake, validation, prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate evidence, and alignment with audit, risk, and regulatory expectations... 
    Full time
    Work at office
    Local area

    Columbia Bank (WA, OR & ID)

    Denver, CO
    2 days ago
  •  ...Job Description As a Sr. GRC Analyst for Oceaneering, you will support the organization's cybersecurity governance, risk management, compliance, and security assurance programs. You will partners with business units, IT, OT, legal, and regulatory stakeholders to implement... 
    Permanent employment
    Work at office

    Oceaneering

    Houston, TX
    12 hours ago
  • $134k - $202k

     ...GRC Analyst Hybrid - San Francisco, New York City, Austin About the Role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy frameworks... 
    Work at office
    Remote work
    Work from home
    Monday to Friday
    Flexible hours

    c e r e m o n y

    San Francisco, CA
    3 days ago
  •  ...The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides strategic oversight of cyber and IT operational risk assessments, regulatory... 
    Full time
    Work experience placement
    Work at office

    Iccu

    Remote
    more than 2 months ago
  •  ...Job Title: Governance, Risk, and Compliance (GRC) Analyst Key Responsibilities: Governance Develop, maintain, and enforce IT security policies, standards, and procedures. Support internal governance frameworks and ensure alignment with industry best... 

    PROLIM Corporation

    Austin, TX
    5 days ago
  •  ...and creatives solving some of the most complex, interdisciplinary challenges of our time. About the Role We are seeking a GRC Analyst to help build and run Base's security governance, risk, and compliance program as the company scales across software, hardware,... 
    Shift work

    Base Power Company

    Austin, TX
    4 days ago
  •  ...The Team The Analyst Governance, Risk, and Compliance, a member of the Information Security – Governance, Risk and Compliance (GRC) team, focuses on implementing and maintaining governance frameworks, managing risk remediation activities, and ensuring adherence to regulatory... 

    American Tower Global

    Boston, MA
    12 hours ago
  • $90k - $110k

     ...journey and revolutionized the industry along the way. And we’re just getting started! Overview The Governance, Risk, and Compliance (GRC) Analyst is a strategic and critical role that closely collaborates with the Senior Director, Information Security on expanding and... 
    Work at office
    Local area
    Remote work
    Work from home

    Planet Fitness

    Boston, MA
    12 hours ago
  • $99k - $120k

     ...join our team. Want to know more? To hear from some of our team, click here: Benesch is proud to announce the opening for a GRC Analyst  in our Cleveland  office! This position is hybrid and has work from home flexibility. Position Summary Are you an... 
    Full time
    Work at office
    Local area
    Work from home

    Benesch

    Cleveland, OH
    12 hours ago
  •  ...entertainment related building projects. The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third‑Party & Human Risk Management (TPHRM) is a risk‑focused, highly analytical role that ensures all human and... 
    Immediate start
    Flexible hours

    Sky Mavis

    Saint Louis, MO
    1 day ago
  • $100k - $140k

     ...visit modine.com. Position Description We are seeking a highly structured, process-oriented, and proactive Senior GRC (Governance, Risk, and Compliance) Analyst to join our Information Security GRC team. In this critical role, you will be the driving force behind the... 
    Temporary work
    H1b
    Worldwide

    Modine Manufacturing Company

    Racine, WI
    3 days ago
  • $75k - $95k

     ...Location: Onsite - Fairfax, VA · U.S. Citizen Required (FedRAMP / Federal Customer) Type: Full Time NextgenID is hiring a GRC Analyst to do the hands‑on work that keeps our compliance program running. We verify and credential identity at the highest assurance level (IAL... 
    Full time
    For contractors
    Internship
    Local area
    Remote work
    Worldwide

    NextgenID

    Brooklyn, NY
    2 days ago
  •  ...Join to apply for the Junior GRC Risk Analyst role at Jobright.ai . Jobright is an AI-powered career platform that helps job seekers discover top opportunities in the US. We are NOT a staffing agency. Jobright does not hire directly for these positions; we connect you... 
    Full time

    jobright.com

    Durham, NC
    12 hours ago
  •  ...Sr GRC Analyst Location: Frisco TX Hybrid: 2 days a week on site Duration: 6-12 + months Main Skills Communication, Automotive, ISO/SAE 21434, UN R155 Job Description Conduct compliance audits to ensure adherence to automotive cybersecurity standards and... 
    2 days per week

    InterSources

    Frisco, TX
    12 hours ago
  •  ...GRC Analyst Rootshell Enterprise Technologies Inc. is a recognized provider of professional IT Consulting services in the US. We are actively seeking a GRC Analyst for one of our clients. Location: Philadelphia, PA - Hybrid Job Summary: Skills and Competencies... 

    Rootshell Inc

    Philadelphia, PA
    3 days ago
  •  ...Title: GRC Analyst Contract Length: 12 months Location: Fully Remote (Company Based in Irvine, CA) Role Summary: The GRC Analyst is responsible for managing MNAO's governance, risk, and compliance functions, with a specific focus on third-party risk management... 
    Contract work
    Remote work

    Experis/Manpower Group

    Irvine, CA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!