Governance, Risk, Compliance & Trust Analyst
$140k - $178kEverlaw
At Everlaw, our mission is to promote justice by illuminating truth. We build technology that helps legal teams find the information they need to achieve their truth-finding goals. As a GRCT Analyst, you will independently drive moderately complex trust, compliance, and risk workstreams that help Everlaw scale responsibly and earn customer and regulator trust over time. This role sits at the intersection of customer trust, compliance operations, audit readiness, risk management, documentation quality, and cross‑functional execution. Key responsibilities include translating Everlaw’s security and compliance posture into clear, accurate, audit‑ready, and customer‑ready outputs while operating with integrity, discipline, and respect for others. Responsibilities Compliance Support audit readiness across core frameworks such as FedRAMP, SOC 2, and ISO 27001/27017/27018 by organizing evidence, maintaining documentation quality, and partnering with control owners to close gaps. Manage compliance operations that require structured follow‑through, including evidence requests, policy and procedure updates, control narrative maintenance, and recurring review cycles. Partner cross‑functionally with Security Engineering, DevOps, IT, Legal, People, Procurement, and other stakeholders to gather inputs, validate implementation details, and produce audit‑ready or stakeholder‑ready outputs. Help maintain strong execution against defined compliance SLAs, milestones, and recurring obligations, escalating risks early and driving issues through resolution. Translate technical, operational, and regulatory topics into clear written deliverables for internal and external audiences. Support internal risk and governance processes such as security impact analyses and change‑related compliance reviews. Contribute to the ongoing operation of the Public Sector Clearance Program, guiding new cohorts, maintaining status, and communicating updates. Customer Trust Manage customer security questionnaires, trust inquiries, and related diligence requests with minimal supervision. Maintain and improve customer‑facing trust content across repositories, portals, knowledge resources, and response libraries. Partner closely with Security Engineering, DevOps, Legal, GTM, Product, IT, and other stakeholders to collect inputs, resolve ambiguities, and ensure trust responses are accurate. Help maintain strong execution against trust‑related SLAs and operating expectations. Identify gaps in trust materials and proactively drive updates. Support broader trust enablement initiatives such as trust center improvements and process improvements. Use workflow data and request trends to identify recurring concerns and recommend improvements. Manage trust inquiry workflows, researching answers, synthesizing evidence, and ensuring timely responses. Vendor Reviews Own end‑to‑end delivery of moderately complex vendor review workstreams. Conduct security and compliance reviews of third parties by gathering documentation such as security questionnaires, architecture details, data flow information, attestations, policies, and contractual commitments. Evaluate vendor security posture against Everlaw requirements for confidentiality, integrity, availability, privacy, access control, incident response, change management, and regulatory obligations. Partner with Procurement, Legal, Security Engineering, IT, and other stakeholders to validate use cases and ensure risks are understood before onboarding or renewal decisions. Document gaps, assumptions, compensating controls, and recommended next steps. Maintain strong execution against vendor review SLAs and recurring obligations, escalating blockers early. Security Training Own delivery of security training program workstreams, including planning, content coordination, stakeholder alignment, rollout tracking, and continuous improvement. Support design and maintenance of security and compliance training required for Everlaw personnel. Maintain training content so it is accurate, current, and aligned with Everlaw policies and external requirements. Partner with GRCT, Legal, HR, Security, IT, and business stakeholders to gather subject matter input and validate training expectations. Coordinate recurring training cycles, onboarding assignments, acknowledgements, re‑certifications, and evidence collection. Help maintain strong execution against program deadlines, audit requests, and training obligations. Contribute to a training program that reinforces Everlaw principles and promotes disciplined execution. Qualifications 5+ years of experience as an individual contributor in a Governance, Risk, Compliance, and Trust team. Strong working knowledge of customer trust, compliance operations, risk, and evidence and control narratives. Experience supporting FedRAMP, SOC 2, ISO 27001/27017/27018 or similar compliance frameworks. Led completion of customer security questionnaires and experience with trust portals or GRC tooling. Experience using workflow, metrics, or dashboard data to improve trust and compliance operations and meet defined SLAs. Independently researches complex questions, synthesizes inputs, and produces high‑quality written deliverables. Communicates complex topics simply and concisely, tailoring communication to the audience. Organized, reliable, and escalates thoughtfully before risks become blockers. Considers long‑term impact of decisions on operations, compliance posture, and stakeholder experience. Comfortable operating with ambiguity, shifting priorities, and multiple stakeholders. Brings sound judgment, professional maturity, and accountability for sensitive or high‑visibility work. Benefits Salary range: $140,000 – $178,000 (subject to change). Equity program. 401(k) retirement plan with company matching. Health, dental, and vision. Flexible Spending Accounts for health and dependent care expenses. Paid parental leave and approximately 10 days (80 hours) per year of sick leave. Seventeen paid vacation days plus 11 federal holidays. Membership to Modern Health. Annual allocation for learning and development opportunities and professional membership dues. Company‑sponsored life and disability insurance. Perks Work in Downtown Oakland near BART line and restaurants. Powerful Linux laptop with desk customization. Team lunches and out‑of‑the‑box events. Free eDiscovery resources through Everlaw for Good. Paid volunteer hours (4 per quarter). Learning and career development opportunities. Ranked #1 on G2 for Ediscovery Software and Momentum. Ranked #9 on Glassdoor’s Best Places to Work 2023 for US small and medium companies. Ranked #2 on 2022 Bay Area Best Places to Work and #9 on other industry awards. Equal Opportunity Employer Statement Everlaw is an equal opportunity employer. We pride ourselves on having a diverse workforce and do not discriminate against any employee or applicant because of race, creed, color, religion, gender, sexual orientation, gender identity or expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law. We respect the gender, gender identity, and gender expression of our applicants and employees, and honor requests for pronouns. We comply with all applicable national, state and local laws pertaining to nondiscrimination and equal opportunity, including the California Equal Pay Act. Pursuant to the San Francisco Fair Chance Ordinance, we consider qualified applicants with arrest and conviction records. We collect and process the personal information you provide along with your job application in accordance with our Applicants Privacy Notice and Notice at Collection. When preparing to engage with Everlaw as a candidate, you may use AI tools for research, polishing application materials, and interview prep. However, any assessments not explicitly stated, remote interviews or live interviews must be completed independently without AI support. By submitting your application, you agree to adhere to these rules. Here is our full policy; please reach out with any questions. #J-18808-Ljbffr Everlaw
- ...agreements between people who don't fully trust each other. Sumerians pressed... ...-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance... ..., and procedures. Support AI governance and responsible AI compliance initiatives...SuggestedContract workWork at officeRemote workVisa sponsorshipRelocation packageFlexible hours
$135k - $165k
...negotiate, and manage contracts. Security, privacy, and trust are foundational to our platform and customer... ...continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk...SuggestedContract workFlexible hours$150k - $180k
...systems. Our goal is to create the trusted knowledge layer that agents,... ...Role We're looking for a GRC Analyst to join our growing Security,... ...be the backbone of all the compliance work at the intersection of... ...translates security and risk into terms that the business...SuggestedFull timeImmediate startRemote workWork from homeFlexible hours$153.4k - $191.8k
...often, they stem from gaps in governance, risk management, operational discipline... ...an Information Security GRC Analyst to help mature Mercury’s security, risk, and compliance programs. This is not a... ...business continuity, customer trust, and long term resilience. In...Suggested$150k - $200k
...Overview We're hiring a GRC Senior Analyst to help build the compliance foundation powering the future of... ...scale securely, responsibly, and with trust at the center of everything we do.... ...Conduct vendor and third-party risk assessments as we expand our global network...SuggestedFull timeWork at officeRemote work2 days per week- Perplexity is seeking a Governance, Risk & Compliance Analyst to shape and run our compliance and risk management program. You will lead the implementation... ..., GTM, and Engineering. You will help drive customer trust by staying ahead of regulatory developments. #J-18808-...
$100k - $120k
...Governance Risk & Compliance Engineer Polsinelli is hiring a Governance Risk & Compliance Engineer for any of our offices, with the option to work remotely. However, our preference is for this role to be based in Kansas City. CORE RESPONSIBILITIES Participate...Full timeTemporary workPart timeWork experience placementRemote workFlexible hoursShift work$145k - $160k
...economy. About the Role: As a Senior Risk and Compliance Analyst at Mytra, you will join the Security team during... ...operational foundation for scalable security governance, SOC 2 and ISO 27001 readiness, customer trust, vendor risk management, and transparent execution...Work at office- You.com is looking for a GRC Analyst to join our Security, IT, and Privacy function... ...crucial in building and maintaining compliance programs and ensuring trust with our customers. Responsibilities... ...frameworks and conducting vendor risk assessments. The ideal candidate has...
$105k
Requisition ID# 172624 Job Category: Compliance / Risk / Quality Assurance Job Level: Individual Contributor Business Unit: Strategy &... ...Overview The Electric Risk & Compliance organization provides governance, oversight, and strategic direction on risk and compliance...Flexible hours2 days per week3 days per week$134k - $202k
...agents. We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and... ...comes next. About the role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and...Work at officeRemote workWorldwideMonday to Friday$117.2k - $176.7k
...meets action. Tech meets trust. And innovation isn’t... ...Senior Security GRC Analyst role is part of our Assurance... ...you will help ensure compliance programs run smoothly... ...program status and risk areas to leadership.... ...of experience in GRC (Governance, Risk, and Compliance)...Full timeWork at office$77k - $202k
...AssociateJob Description & SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate, you will focus on maintaining... ...factors thoughtfully to establish a secure and trusted workplace for all.SummaryLocation: NY-New York; GA-...Full timeH1b$110k - $140k
...Security Compliance Analyst We are looking for a highly motivated individual with information security governance and compliance experience to be part of our team! As a Security Compliance... ...be able to assist in running the risk management program that is managed by the...$133k - $238k
...Requisition ID # 172735 Job Category: Compliance / Risk / Quality Assurance; Accounting / Finance; Business Operations / Strategy Job... ...: The Electric Risk & Compliance organization provides governance, oversight, and strategic direction on risk and compliance matters...Full timeWork at officeFlexible hours- ...responsible for the physical and logical security of that work makes everything else feel small. Role Scope Run the day-to-day compliance program end to end across SOC 2 Type II, ISO 27001, NIST 800-53, and FedRAMP Moderate equivalency: continuous evidence collection...Local area
$99.2k - $148.8k
...trustworthy, and compliant platform. Earning the trust of our customers is a business enabler... ...this role, you'll report to the Senior Compliance Manager and serve as a core executor on... ...— this role supports work the U.S. government specifies can only be performed by a U.S...$150k - $200k
GFT is seeking a Principal Cybersecurity Compliance Analyst to join our Security and Safety team in Northern California! This role follows... ..., implementation, and continuous improvement of governance, risk, and compliance (GRC) programs aligned with FERC (D2SI SPHP...Full timeWork at officeRemote work- Youcom is seeking a GRC Analyst to support the compliance function within our Security, IT, and Privacy team. This role focuses on managing compliance... ...will coordinate audit activities, conduct vendor risk assessments, and ensure compliance policies are effectively...Flexible hours
- Salesforce.com, inc. is seeking a detail-oriented Security GRC Analyst to join their Security and Compliance team. In this role, you will lead the Unified Audit program ensuring compliance across various frameworks like SOC 2 and HIPAA, while managing evidence collection...
- ...Compliance Officer This position is within the Administrative Services Group Compliance Function and is responsible for taking a lead... ...Corporate Compliance Monitors major and critical compliance risks issues Oversees the implementation of training programs Disseminates...
- ...experienced and highly motivated Senior Compliance Specialist to help scale our security, privacy... ...teams. Job Responsibilities Support governance activities across the security, privacy... .... Participate in enterprise risk management activities, including risk methodology...Contract workFor contractorsFor subcontractorWork at office
$33 - $38 per hour
...standardized technologies. For decades, we have served as a trusted bridge between our licensors and licensees, driving a strong... ...products and technologies for people around the world. The Compliance Analyst Intern will join Via LA's Global Compliance team and support...Hourly payInternshipWork at officeLocal area3 days per week$99.2k - $148.8k
...trustworthy, and compliant platform. Earning the trust of our customers is a business enabler... ...this role, you'll report to the Senior Compliance Manager and serve as a core executor on... ...— this role supports work the U.S. government specifies can only be performed by a U.S...$36.92 - $41.85 per hour
...Compliance & Audit Coordinator Daly City, CA 94014 Overview Salary Range $36.92 - $41.85 Hourly Position Type Full Time Description... ...with regulatory guidelines. Supports NEMS Corporate Risk Management, Privacy & Compliance Officer in updating and enforcing...Hourly payFull timeContract workWork at office- Anthropic is seeking a Senior Third Party Risk Manager to lead the top tier of vendor risk, including mission-critical compute, data center, and data-pipeline partners. You will shape risk assessments, escalation, and remediation across security, privacy, and operations...Work at officeVisa sponsorship
$95k - $150k
...GRC Analyst The Security & Compliance team at Zip is committed to providing a high level of security assurance... ..., internal audits, and vendor risk assessments Lead conversations and... ...customers' security, compliance, and governance teams in due diligence and security...Home officeFlexible hours- Ivo is looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst in San Francisco. The ideal candidate will support compliance programs such as SOC 2 Type II and ISO 27001 while managing audits and risk assessments. This onsite role offers a competitive...
$193.8k - $228k
Senior GRC Analyst II job at Carta. San Francisco, CA. The Problems You'll Solve As a Senior GRC Analyst... ...and accordingly establish and maintain governance and risk frameworks. You will build and run security compliance programs to measure and reduce risk, report compliance...Full time$35k - $48k
...Junior Compliance Officer (Operations, Jr. Analyst) The MIL Corporation seeks a Junior Compliance Officer... ...an on-site schedule performed at government facilities during core business... ...maintain a DHS/ICE Tier 4 High Risk Public Trust fitness determination; prior favorable...Full timeContract workFor contractorsWork at officeRemote workWeekend work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance, Risk, Compliance & Trust Analyst. Be the first to apply!
- it risk analyst San Francisco, CA
- transaction risk analyst San Francisco, CA
- senior quantitative risk analyst San Francisco, CA
- operational risk specialist San Francisco, CA
- operational risk consultant San Francisco, CA
- third party risk analyst San Francisco, CA
- risk analyst San Francisco, CA
- risk officer San Francisco, CA
- risk consultant San Francisco, CA
- compliance coordinator San Francisco, CA

