Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Analyst

Zone & Co

GRC Analyst

Colombia

Zone & Company Software Consulting LLC ("Zone") is the ERP-native AI platform for financial operations, purpose-built for organizations running on Oracle NetSuite. We are redefining how finance teams operate by delivering an AI-powered system that automates, connects, and scales financial workflows directly within the ERP.

As the AI operating system for finance teams in NetSuite, Zone enables more than 4,500 customers worldwide to run smarter, faster, and with greater accuracy. Our platform spans the full financial lifecycle, including Quote-to-Cash, Procure-to-Pay, Treasury, Payroll Management, and Record-to-Report, eliminating manual processes and unlocking real-time financial intelligence.

By embedding intelligence directly into NetSuite, Zone helps finance teams move beyond reactive work to proactive, strategic impact.

The Role: We are seeking a meticulous and proactive Security and Privacy Compliance Analyst to help safeguard our organization and our customers' data. Reporting directly to the Director of IT, Security and Compliance, you will play a critical role in maturing our governance, risk, and compliance (GRC) programs. In this position, you will bridge the gap between technical security controls and regulatory requirements, ensuring that Zone & Co's rapidly expanding suite of financial software maintains the highest standards of data protection and privacy.

This role requires a strong foundational knowledge of major security frameworks and privacy regulations, a keen eye for detail in auditing internal processes, and the ability to clearly communicate compliance postures to both internal engineering teams and enterprise customers.

Essential Job Functions:

  • Compliance Framework Governance: Lead the management and continuous scaling of Zone & Co's core security compliance frameworks, specifically SOC 2 Type II and ISO 27001.
  • Privacy Operations Leadership: Govern global data privacy operations to ensure strict, ongoing alignment with GDPR, CCPA/CPRA, and other emerging data protection laws.
  • Customer Trust & Revenue Enablement: Serve as the primary security liaison for enterprise customers, directly supporting the sales cycle by demonstrating and communicating a robust, mature security posture.
  • Risk & Audit Management: Manage the organization's internal audit program and oversee the third-party vendor risk lifecycle to proactively identify and mitigate vulnerabilities.

Responsibilities, Duties, and Tasks:

  • Audit Coordination: Coordinate evidence collection, manage project timelines, and partner directly with external auditors during annual compliance assessments.
  • Privacy Assessments: Conduct Data Privacy Impact Assessments (DPIAs) for new products and process Data Subject Access Requests (DSARs) within mandated SLAs.
  • Questionnaires & Trust Center: Accurately and efficiently complete incoming vendor security questionnaires from prospects and maintain up-to-date documentation in our customer-facing Trust Center.
  • Internal Control Testing: Design and execute internal audits to test whether technical and administrative controls are operating effectively. Track control gaps and drive engineering/IT remediation efforts.
  • Vendor Risk Reviews: Evaluate the security and privacy postures of prospective and existing third-party vendors and sub-processors through comprehensive risk assessments.
  • Policy & Training Development: Draft, update, and publish internal security policies, standard operating procedures (SOPs), and incident response plans. Develop and administer engaging company-wide security and privacy awareness training.

What You'll Bring (Qualifications and Experience):

  • Experience: 3+ years of direct experience in IT Audit, Information Security, Privacy Operations, or GRC (Governance, Risk, and Compliance), preferably within a B2B SaaS, FinTech, or cloud technology environment.
  • Deep Domain Expertise: Hands-on experience working with established compliance frameworks (SOC 2, ISO 27001) and navigating global privacy legislation (GDPR, CCPA).
  • SaaS/Cloud Acumen: A solid understanding of cloud computing architectures (AWS, Azure, GCP) and enterprise software environments. Familiarity with ERP systems (like NetSuite) is a strong plus.
  • Analytical & Problem-Solving Skills: Proven ability to translate complex regulatory requirements into actionable, practical controls for IT and engineering teams without stifling innovation.
  • Exceptional Communication: Outstanding written and verbal communication skills. You must be able to write clear policies, translate technical risks for business leaders, and confidently answer complex customer security questions.
  • Education & Certifications: Bachelor's degree in Information Systems, Cybersecurity, Business, or a related field. Relevant industry certifications such as CISA, CISM, CIPP/E, CIPP/US, or Security+ are highly preferred.

Benefits

At Zone, we provide the platform; you provide the grit. We operate as a high-velocity, fully remote, global team where autonomy isn't just a perk, it's the standard. We're looking for self-driven professionals eager to navigate the complexities of a unique SaaS environment and take full command of their professional evolution.

We ditch micro-management for high-trust flexibility, ensuring you have the space to innovate and scale. Our benefits are built to fuel this lifestyle, supporting your life beyond the screen so you can focus on making a global impact. Explore our offerings at

Join Our Global Mission

Zone & Co is an Equal Opportunity Employer committed to building a diverse, equitable, and inclusive workplace. We thrive on unique perspectives and strongly encourage candidates of all backgrounds to apply. Here, your identity is valued, and your talent is the only limit to your growth. All qualified applicants will receive consideration regardless of race, color, religion, sex, orientation, age, disability, or any other protected factor.

Employment Terms

United States

Employment with Zone is "At-Will", meaning either party may terminate the relationship at any time, with or without cause or notice, in accordance with applicable law. This job description does not constitute an employment contract or guarantee of continued employment. Duties and responsibilities may evolve as the company grows and may change at any time with or without notice.

Non-US Jurisdictions

This position is offered as a Fixed-Term or Permanent Contract based on your country of residence. Employment is subject to a written contract which outlines specific notice periods, probationary terms, and statutory entitlements.

Privacy Statement

#LI-Remote

Vacancy posted 20 hours ago
Similar jobs that could be interesting for youBased on the GRC Analyst in United States vacancy
  •  ...We’re looking for a GRC Analyst who thrives in fast-moving, high-impact environments and has experience with risk management standards as well as monitoring cybersecurity risks. What You’ll Do Execute control assessments and audit readiness activities to validate... 
    Suggested

    Lumen Resources

    Tampa, FL
    13 hours ago
  • $40 - $45 per hour

     ...Job Title: GRC Analyst (AI Risk & Governance Focus) Location: Indianapolis, IN (Hybrid) Duration: 12-month contract (potential for extension or conversion) Compensation: $40-45/hr (W-2) Overview Our client is seeking a GRC Analyst with exposure to AI risk... 
    Suggested
    Contract work
    Local area

    Brooksource

    Indianapolis, IN
    1 day ago
  • Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI - and we need practitioners who know how GRC actually works in the real world. Your expertise... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Dallas, TX
    2 days ago
  • $60k - $75k

     ...managing compliance, and helping keep cybersecurity and government contract requirements on track? Qualified Staffing is seeking a GRC Analyst for our client in Macon, GA. This position will support cybersecurity compliance, risk management, audit readiness, and... 
    Suggested
    Contract work
    Monday to Thursday

    Qualified Staffing

    Macon, GA
    3 days ago
  • $161.6k - $202k

     ...- and that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program! You'll join the Security team and work across four pillars: security certifications (HITRUST... 
    Suggested
    Work from home
    Flexible hours

    Headway - Design & Development

    Seattle, WA
    1 day ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We partner with the world's leading AI research labs to build smarter, safer AI systems - and we need practitioners who know how compliance and risk management actually work in the real... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Worldwide
    Flexible hours

    Alignerr

    Chicago, IL
    2 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst We're looking for experienced GRC professionals to help build and evaluate AI systems that reason about security, risk, and compliance. At Alignerr, we partner with the world's leading AI research labs — and your real-world... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    United States
    18 hours ago
  •  ...Governance, Risk & Compliance (GRC) Analyst We're looking for experienced GRC professionals to help build and evaluate AI systems that reason about security, compliance, and risk. At Alignerr, we partner with the world's leading AI research labs to create high-quality... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    United States
    17 hours ago
  •  ...Governance, Risk & Compliance (GRC) Analyst Location: Middleton, Wisconsin Hybrid: Travel to client office might be required on case basis. Client is seeking a GRC Analyst to lead our governance, risk, and compliance initiatives. This role will be instrumental... 
    Work at office

    Group Nine LLC

    Middleton, WI
    4 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst We're partnering with the world's leading AI research labs to build smarter, more reliable AI systems — and we need practitioners who know how GRC actually works in the real world. If you've spent time inside compliance programs... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    United States
    1 day ago
  •  ...GRC Analyst DataRobot delivers AI that maximizes impact and minimizes business risk. Our platform and applications integrate into core business processes so teams can develop, deliver, and govern AI at scale. DataRobot empowers practitioners to deliver predictive and... 
    Local area
    Remote work
    Worldwide
    Flexible hours

    DataRobot

    United States
    19 hours ago
  •  ...DataRobot, Inc. is seeking a GRC Analyst to join their Information Security Team. The successful candidate will collaborate with stakeholders to manage ISO27001, SOC 2, and HIPAA compliance programs. Key responsibilities include responding to customer security inquiries... 
    Flexible hours

    DataRobot

    Richmond, VA
    2 days ago
  •  ...Hotman Group is seeking an Entry Level GRC Analyst to work remotely in the USA. The role involves assessing client security, developing risk frameworks, and translating technical requirements into actionable steps. Candidates should possess a relevant degree and 1-2 years... 
    Remote work

    Hotman Group

    New York, NY
    13 hours ago
  •  ...inclusive and dynamic work environment at our various locations. Purpose: Athene is seeking a Sr. Governance, Risk & Compliance (GRC) Analyst to help strengthen and evolve enterprise technology risk management, cybersecurity governance, and regulatory compliance across... 
    Local area

    Athene Holding Ltd

    Urbandale, IA
    1 day ago
  •  ...Governance, Risk, and Compliance (GRC) Analyst We operate at the intersection of technology and law, in an industry that demands agility and innovation. Our team is dedicated to developing advanced solutions for legal professionals. Our daily work involves tackling... 
    Full time
    Flexible hours

    Fulcrum Global Technologies

    Phoenix, AZ
    1 day ago
  • Third Party Governance, Risk and Compliance (GRC) Analyst Los Angeles, California - Hybrid - 3 Days Onsite Full Time The Analyst will be a key player in overseeing third-party vendor risk, ensuring regulatory compliance, and supporting enterprise GRC initiatives... 
    Full time
    Contract work

    Veracity

    Los Angeles, CA
    2 days ago
  • $50 - $75 per hour

     ...Genesis10 is currently seeking a Governance, Risk, and Compliance (GRC) Analyst for an onsite position with a non-profit organization located in Austin, TX. This is a 12+ month contract opportunity. This role is responsible for advancing and operationalizing the... 
    Permanent employment
    Contract work
    Remote work

    Genesis10

    United States
    2 days ago
  •  ...Principal GRC Analyst | Deltek, Inc Principal GRC Analyst US (Remote) Deltek is the intelligent, industry-tuned platform that powers the project lifecycle – from ERP and accounting to delivery and analysis. Trusted by 30,000 organizations, Deltek delivers speed... 
    Remote work

    Deltek

    United States
    5 days ago
  •  ...implementation of company-wide security governance, risk management, and compliance programs. Under the direction of the GRC Functional Leader, the analyst contributes to policy development, risk oversight, and continuous improvement of the organization's security posture.... 
    Work experience placement
    Work at office
    Local area
    Remote work

    Artech

    United States
    1 day ago
  • $80k - $158k

     ...GRC Analyst City: Oregon State/Province: Ohio Posting Start Date: 5/21/26 Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clients' most complex digital... 
    Minimum wage
    Full time
    Local area

    Wipro

    Oregon, OH
    1 day ago
  •  ...GRC (3rd Party Risk) Analyst Duration: 12 – 24 Month Project Engagement The GRC Analyst is responsible for managing Client's governance, risk, and compliance functions, with a specific focus on third-party risk management. This role ensures Client operates in a compliant... 

    Datamtx LLC

    Peachtree City, GA
    2 days ago
  • $62k - $87k

     ...GRC Analyst The GRC Analyst is responsible for ensuring that Busey Bank implements, manages, and enforces information security and cybersecurity controls to effectively align to industry standards. This position will monitor the performance of key Information Security... 
    Temporary work
    For contractors
    Work experience placement
    Work at office
    Local area
    Remote work
    Flexible hours

    Busey

    Tomahawk, WI
    7 hours ago
  •  ...Senior GRC Analyst | Deltek, Inc Deltek is the intelligent, industry-tuned platform that powers the project lifecycle – from ERP and accounting to delivery and analysis. Trusted by 30,000 organizations, Deltek delivers speed, clarity, and control. Deltek brings everything... 
    Remote work

    Deltek

    United States
    20 hours ago
  • $70 - $80 per hour

     ...GRC / Risk Platform Developer Location: Urbandale, IA (Partial Remote) Employment Type: Contract Role Overview We are seeking a Developer with Governance, Risk, and Compliance (GRC) and Risk domain familiarity to help drive a transformation. This role blends hands... 
    Hourly pay
    Contract work
    Part time
    Remote work

    Apex Systems

    United States
    4 days ago
  • $130k - $160k

     ...Alumni Ventures is seeking a Senior GRC Analyst to operate and mature governance, risk, compliance, and audit readiness programs. This role involves collaboration across departments to ensure effective compliance practices. Ideal candidates have 5+ years in GRC and experience... 
    Remote work
    Flexible hours

    Benepass

    United States
    1 day ago
  •  ...collaborating with various teams to operationalize compliance requirements. The ideal candidate will have 3–5 years of experience in GRC with a hands-on approach to audits. Benefits include competitive compensation, private medical insurance, and flexible time off. #J-1... 
    Remote work
    Flexible hours

    Jobgether

    Indiana, PA
    3 days ago
  •  ...Location : Remote Reports to : GRC Manager Time commitment : minimum 20 hours weekly Headcount: 2 people Summary: The GRC analyst with a legal background is a critical hire for our rapid team. You will be responsible for building and maintaining the... 
    Remote work

    Menzies Philanthropic Foundation

    Little Elm, TX
    2 days ago
  •  ...Senior Analyst of GTS GRC (Governance, Risk and Compliance) BeOne continues to grow at a rapid pace with challenging and exciting opportunities for experienced professionals. When considering candidates, we look for scientific and business professionals who are highly... 
    Remote work

    BeOne Medicines

    United States
    3 days ago
  • £500 per month

     ...GRC Analyst We're looking for a GRC Analyst to take ownership of our Governance, Risk & Compliance program. As our regulatory footprint and customer trust requirements have grown, we're investing in a dedicated GRC function to ensure we maintain a strong, continuous... 
    Work at office
    Remote work
    Worldwide
    Home office
    Shift work

    Primer

    United States
    2 days ago
  •  ...Sr. GRC Analyst Sr. GRC Analyst Remote USC or GC only must be in the EST (highly preferred) or CST time zone. Brief Job Description ~6-8 years of experience as a GRC Analyst ~ Will be involved with assisting the clients internal GRC team to help with Third... 
    Remote work

    ShiftCode Analytics

    United States
    18 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!