Governance, Risk, and Compliance Analyst
$150k - $180kYou.com
About Us At You.com, we are building the AI Search Infrastructure that powers modern AI systems. Our goal is to create the trusted knowledge layer that agents, applications, and enterprises rely on to retrieve real‑time, accurate, and citation‑backed information. Our platform combines proprietary vertical indexes with LLM‑optimized retrieval systems to power AI agents, applications, and enterprise workflows. We are solving hard problems across search, large language models, and large‑scale infrastructure to make AI systems more reliable, transparent, and useful. Our team includes engineers, researchers, product builders, and operators who care about solving meaningful problems and delivering real‑world impact. Whether you are improving core infrastructure, shaping product experiences, or helping bring new AI capabilities to market, your work will help define how modern AI finds and uses knowledge. The Role We're looking for a GRC Analyst to join our growing Security, IT, and Privacy function. You'll be the backbone of all the compliance work at the intersection of Engineering, Legal, and Product. This role will build and maintain the compliance programs as part of the security team. Our goal is simple: earn and keep the trust of our customers. The right person translates security and risk into terms that the business and product teams can act on. Key Responsibilities Own and manage compliance programs across frameworks including SOC 2, ISO 27001, GDPR, CCPA, HIPAA, and FedRAMP Coordinate audit activities end‑to‑end: evidence collection, documentation, auditor responses, and remediation tracking Leverage AI and other tools to deliver metrics that stakeholders can consume and understand Conduct vendor and third‑party risk assessments; manage the due diligence lifecycle for new and existing partners Help manage security and risk reviews (e.g. DDQs, VSQs) as part of the procurement process in collaboration with the Legal, Finance, and Security team Assist with building and maintaining compliance policies, procedures, and supporting documentation for security and compliance Translate regulatory and contractual requirements into actionable controls and processes Monitor the evolving regulatory landscape (especially AI‑specific regulations) and flag relevant obligations Support Privacy‑by‑Design reviews for new product features and data practices Track open compliance items and proactively drive them to closure across stakeholders Requirements 3–5 years of experience in GRC, Information Security compliance, or a related field Hands‑on experience with SOC 2 or ISO 27001 audits, including evidence collection and gap assessments Familiarity with privacy regulations: GDPR, CCPA, and ideally emerging AI regulatory frameworks (EU AI Act, etc.) Experience managing vendor risk assessments and third‑party due diligence processes Strong written and verbal communication skills. You can explain compliance requirements to engineers and legal concepts to product managers Highly organized, able to manage multiple workstreams and deadlines without dropping the ball Comfortable working independently in a fast‑paced environment with limited process overhead Leverage AI to help build automation and data analysis workflows for reporting and tracking Bonus points for: Experience at an AI or search company Familiarity with data broker or data licensing compliance CISA, CISM, or CRISC Our salary bands are structured based on a combination of geographic tiers and internal leveling. Compensation is determined by multiple factors assessed during the interview process, with the final offer reflecting these considerations. Salary Band: $150,000 – $180,000 USD Company Perks Hubs in San Francisco and New York City offering regular in‑person gatherings and co‑working sessions Flexible PTO with U.S. holidays observed and a week shutdown in December to rest and recharge* A competitive health insurance plan covers 100% of the policyholder and 75% for dependents* 12 weeks of paid parental leave in the US* 401k program, 3% match - vested immediately!*
- 500 work‑from‑home stipend to be used up to a year of your start date*
- 600 technology stipend to support a portion of our hybrid/remote team's cell phone and internet expenses*
- 1,200 per year Health & Wellness Allowance to support your personal goals*
- ...Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives. This... ...policies, standards, and procedures. Support AI governance and responsible AI compliance initiatives. What...SuggestedContract workWork at officeRemote workVisa sponsorshipRelocation packageFlexible hours
$135k - $165k
...foundational to our platform and customer relationships. As we continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk management programs. Role Overview Ivo is seeking a...SuggestedContract workFlexible hours- the company is seeking a highly experienced Governance, Risk & Compliance Analyst to join our world-class team. You will help shape our compliance and risk management program. If you are a self-motivated, organized professional with a passion for driving compliance and...Suggested
$140k - $178k
...achieve their truth-finding goals. As a GRCT Analyst, you will independently drive moderately complex trust, compliance, and risk workstreams that help Everlaw scale... ...external audiences. Support internal risk and governance processes such as security impact analyses...SuggestedLocal areaFlexible hoursShift work$153.4k - $191.8k
...technical mistake. More often, they stem from gaps in governance, risk management, operational discipline, and... ...We are looking for an Information Security GRC Analyst to help mature Mercury’s security, risk, and compliance programs. This is not a traditional compliance...Suggested- Perplexity is seeking a Governance, Risk & Compliance Analyst to shape and run our compliance and risk management program. You will lead the implementation of frameworks, oversee data privacy regulations, and build scalable audit systems in a fast‑growing startup environment...
- United States Digital Space LLC in San Francisco seeks a Governance, Risk & Compliance Analyst to mature our security program and manage regulatory obligations, shaping compliance and risk practices to build customer trust in a fast-growing startup transforming search and...
- Mercury is seeking an Information Security GRC Analyst to mature security, risk, and compliance programs and build guardrails for business continuity and... ...NIST, CIS, and ISO 27001. The role emphasizes scalable governance and practical controls to enable fast, secure...
- SmithRx is seeking a Compliance Analyst to help implement a robust compliance program in a dynamic PBM regulatory landscape. You will remediate non-compliance and support policy and procedure adherence across the organization. You will work with the Corporate Compliance...Remote jobFull timeHome office
- The California Public Utilities Commission is seeking an Analyst I to support enterprise risk management, risk and compliance, and division operations under the Program and Project Supervisor. The role involves research, analysis, report preparation, and workflow development...
- You.com is looking for a GRC Analyst to join our Security, IT, and Privacy function in San... ...will be crucial in building and maintaining compliance programs and ensuring trust with our... ...various frameworks and conducting vendor risk assessments. The ideal candidate has 3-5...
- ...Compliance Officer This position is within the Administrative Services Group Compliance Function and is responsible for taking a lead... ...Corporate Compliance Monitors major and critical compliance risks issues Oversees the implementation of training programs Disseminates...
$95k - $150k
...Startups. Your Role The Security & Compliance team at Zip is committed to... ...requirements. As a GRC Analyst at Zip, you’ll be a key driver... ...internal audits, and vendor risk assessments Lead conversations... ...customers’ security, compliance, and governance teams in due diligence and...Home officeFlexible hours$134k - $202k
...community, or shaping our story, you’ll help define what comes next. About the role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy...Work at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours$218k - $269k
...being responsible for the physical and logical security of that work makes everything else feel small. Role Scope Run the day‑to‑day compliance program end to end across SOC 2 Type II, ISO 27001, NIST 800‑53, and FedRAMP Moderate equivalency: continuous evidence collection...Local area$150k - $200k
GFT is seeking a Principal Cybersecurity Compliance Analyst to join our Security and Safety team in Northern California! This role follows... ..., implementation, and continuous improvement of governance, risk, and compliance (GRC) programs aligned with FERC (D2SI SPHP...Full timeWork at officeRemote work- ...expertise to JPMorgan Chase. As part of Risk Management and Compliance, you are at the center of keeping... ...interactions with research analysts, including pre-clearing and chaperoning... ...prominent corporate, institutional and government clients under the J.P. Morgan and Chase...Work at officeFlexible hours
$126k
...Requisition ID # 170677 Job Category: Compliance / Risk / Quality Assurance Job Level: Individual Contributor Business Unit: Strategy & Growth Work Type: Hybrid Job Location: Oakland; Alameda; Alta; American Canyon; Angels Camp; Antioch; Auberry; Auburn;...Work experience placementFlexible hours- Zip is hiring a GRC Analyst to drive compliance programs across SOC 1, SOC 2, ISO 27001, and expanding into the EU and regulated industries. You’ll... ...development. In this fast-growing environment, you’ll lead risk assessments, support due diligence questionnaires, and...
$135k - $165k
Icehouseventures is seeking a proactive GRC Analyst to join our team in San Francisco. This role will support compliance and risk management initiatives essential for maintaining high security standards. The ideal candidate will have 3-5 years of experience in GRC and relevant...Contract work- ...to join its AI practice. The role involves advisory, regulatory, litigation, and transactional matters, with a focus on AI governance and compliance. Duties include advising clients on AI governance and regulatory compliance, monitoring AI law developments, supporting AI...
- JPMorgan Chase & Co. in San Francisco is seeking a Control Room Senior Associate within Risk Management and Compliance. You will help maintain information barriers by monitoring information flows between private- and public-side teams and advise on policy applicability...
- ...experienced and highly motivated Senior Compliance Specialist to help scale our security, privacy... ...teams. Job Responsibilities Support governance activities across the security, privacy... .... Participate in enterprise risk management activities, including risk methodology...Contract workFor contractorsFor subcontractorWork at office
- Anthropic is seeking a Senior Third Party Risk Manager to lead the top tier of vendor risk, including mission-critical compute, data center, and data-pipeline partners. You will shape risk assessments, escalation, and remediation across security, privacy, and operations...Work at officeVisa sponsorship
- Ivo is looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst in San Francisco. The ideal candidate will support compliance programs such as SOC 2 Type II and ISO 27001 while managing audits and risk assessments. This onsite role offers a competitive...
- Vercel in San Francisco is seeking a GRC Analyst to join our Governance, Risk & Compliance team. You will manage and maintain ongoing compliance with security and privacy frameworks, policies, and audits including ISO 27001, SOC 2, HIPAA, and PCI DSS. You will collaborate...Remote jobWork at office
- Salesforce.com, inc. is seeking a detail-oriented Security GRC Analyst to join their Security and Compliance team. In this role, you will lead the Unified Audit program ensuring compliance across various frameworks like SOC 2 and HIPAA, while managing evidence collection...
- Fluidstack is seeking a Security Compliance Lead in San Francisco to own end-to-end controls across SOC 2 Type II, ISO 27001, NIST 800-53, and FedRAMP, building a scalable program for global sites. You will collaborate with engineering and operations to gather evidence...
- ...guidance on healthcare matters. In-house or law firm experience in healthcare regulatory law is preferred; you will draft and review contracts, advise on licensing and accreditation, and collaborate with the legal team to manage risk and compliance for #J-18808-Ljbffr AxiomRemote job
$117.2k - $176.7k
...Francisco, CAThe Senior Security GRC Analyst role is part of our Assurance... ...alike, you will help ensure compliance programs run smoothly and... ...program status and risk areas to leadership.Manage internal... ...years of experience in GRC (Governance, Risk, and Compliance), compliance...Full timeWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance, Risk, and Compliance Analyst. Be the first to apply!
- risk consultant San Francisco, CA
- risk compliance officer San Francisco, CA
- risk analyst San Francisco, CA
- governance risk & compliance analyst San Francisco, CA
- senior quantitative risk analyst San Francisco, CA
- operational risk consultant San Francisco, CA
- it risk analyst San Francisco, CA
- risk officer San Francisco, CA
- third party risk analyst San Francisco, CA
- transaction risk analyst San Francisco, CA

