Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Governance Risk & Compliance (GRC) Analyst

Virtru

While the rest of the security industry obsesses over locking data down to prevent it from being lost or stolen, we're doing something fundamentally different at Virtru. We're setting data free so that you can intentionally share it with others, but without sacrificing security, privacy, or control. We've created both a suite of powerful data protection applications and an open platform that's sparking an ecosystem of innovation. Through the Trusted Data Format (TDF) open standard, we're not just protecting data; we're creating a new paradigm where security enables sharing rather than preventing it. Think of us as the Android of data protection: a robust platform with an open core that developers and partners can build upon, coupled with our own best-in-class applications that showcase what's possible when you reimagine security from the ground up. Backed by Iconiq Capital, Bessemer Venture Partners, Foundry Capital, and Tiger Global, we're helping Fortune 500 companies and government agencies discover that true data security means having the freedom to share, collaborate, and innovate — without compromise. Here at Virtru you’ll help build a cutting edge security compliance program aligned with FedRAMP, SOC 2, PCI, HIPAA, GDPR, and just about any other security/privacy framework you can think of, whilst getting your hands on some of today’s most important tools and tech like Kubernetes, GCP, AWS, Terraform. With a constantly growing customer base, there is no shortage of challenging and exciting scaling/optimization work to ensure that we can provide the most secure and performant service. As a GRC Analyst at Virtru, you will be the primary point of contact for compliance-related inquiries. You will lead and manage the organization's efforts to achieve and maintain CMMC compliance, by conducting gap analyses and developing a roadmap to address compliance requirements. You will also play a vital role in supporting our existing FedRAMP, SOC2, and PCI DSS compliance. Get in touch if you are excited to help us grow into a world-class security compliance program. As a Security Governance Risk & Compliance (GRC) Analyst, your responsibilities will include: Manage and implement complex controls frameworks for large systems, consisting of Cloud infrastructure and Software as a Service (SaaS) services (GCP, AWS, GitHub, Okta, etc). Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services. Conduct risk assessments across business units and processes. Identify risk findings and recommend remediation and risk mitigation strategies. Participate in incident response (IR) activities, providing risk analysis and remediation support as needed. Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders. Incorporate CMMC certification into Virtru’s slate of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI). Facilitate the third-party vendor on-boarding and annual review process by evaluating the security of current and prospective partners. Skills that will help you thrive in this role: Minimum of 5+ years of information security, IT audit and/or IT Risk Management, or GRC Analyst/Engineer experience CMMC, NIST 800-53 & 800-171, FedRAMP, SOC 2, PCI, and/or other global privacy compliance frameworks Strong understanding of modern cloud technologies (AWS, GCP, Azure, etc.) and familiarity with GRC tools (Hyperproof, Vanta, Drata, etc) and SIEM tools (Datadog, Splunk) You’re a relationship builder and have worked with both business and technical risk and understand how to translate risk to various levels of the organization Have experience training and coaching teams to become better security and privacy practitioners Like working on an autonomous agile team. At Virtru, you will have ownership of security, but you'll collaborate with everyone to make sure we produce and implement the right solutions Work independently with little or no supervision while maintaining a high level of efficiency. Virtruvian qualities that will set you up for success: Able to collaborate and adapt to shifting priorities as business needs evolve This is why we make your wellbeing our priority with a thoughtful and holistic program that encompasses Occupational, Mental, Social, Physical, and Environmental Wellness by offering benefits such as… A Flexible PTO policy — we strongly encourage you to take time off (in addition to 14 holidays) to ensure that you are getting the proper time needed to unplug and recharge. Access to an Employee Assistance Program Access to Headspace, a mental health app tailored to your specific needs. A flat 3% contribution to your retirement account In addition to wellbeing, Virtru places a strong emphasis on diversity, equity, inclusion, and belonging. Generous parental, medical, and bereavement policies 401K contribution and stock options Full medical, dental, and vision benefits Structured semi-annual 360° performance reviews Virtru is committed to building an inclusive environment for people of all backgrounds and everyone is encouraged to apply. Virtru is an Equal Opportunity Employer and does not discriminate on the basis of race, color, gender, religion, disability, national origin, protected veteran status, age, or any other status protected by applicable national, federal, state, or local law.

Vacancy posted more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Governance Risk & Compliance (GRC) Analyst. Be the first to apply!