GRC Analyst
$95k - $150kZIP
About Zip Zip is the AI platform for enterprise procurement — built for humans and agents working together. By orchestrating procurement across teams, tools, and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before. The world’s most influential enterprises trust Zip, including T-Mobile, OpenAI, AMD, Mars, Dollar Tree, and more. Together they’ve saved over $8 billion and processed over $500 billion in spend. Zip’s team includes product leaders from Apple, Airbnb, and Meta, as well as former procurement leaders from United Health, Sanofi, MGM Resorts, Discover, and NASA. Backed by Adams Street, Alkeon, BOND, CRV, DST, Tiger Global, and Y Combinator, Zip has raised $371 million, most recently at a $2.2 billion valuation and has been recognized by Forbes Fintech 50, Fast Company's Most Innovative Companies, Inc. Best in Business, and LinkedIn Top Startups. Your Role The Security & Compliance team at Zip is committed to providing a high level of security assurance to customers, aligning security goals with business objectives and customer requirements. As a GRC Analyst at Zip, you’ll be a key driver for ensuring the success of compliance programs at a fast-growing company. Your contributions will be pivotal to the overall growth and competitive edge of Zip’s GRC program. You’ll ensure we can securely and compliantly build new features, help design and scale the compliance programs that power our expansion. You’ll help maintain our existing SOC and ISO certifications while supporting new certifications, from AI products to entry into new markets like the EU and highly-regulated industries. Responsibilities Drive and perform periodic compliance-related activities, such as user access reviews, internal audits, and vendor risk assessments Lead conversations and curate responses for customers’ security, compliance, and governance teams in due diligence and security questionnaires Guide internal control owners and stakeholders to understand requirements, take accountability, and operationalize their controls. Collaborate with internal stakeholders and external auditors to support third party audits including SOC 1, SOC 2, and ISO 27001 Develop, maintain, and lead the adoption of security policies, standards, and guidelines to ensure compliance with applicable regulatory requirements Required Qualifications Bachelor’s degree in a related field 2+ years of experience in GRC, information security consulting, cybersecurity risk, audits, or similar roles Strong written and verbal communication skills with both technical and non-technical stakeholders Familiarity with and participation in one or more of the following frameworks: SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP Familiarity with information security fundamentals for cloud software systems Preferred Qualifications Professional certifications in information security are a plus but not required The salary range for this role is $95,000 - $150,000. The salary for this position is determined based on a variety of job-related factors that may include location, relevant experience, education, or particular skills and expertise. Perks & Benefits At Zip, we’re committed to providing our employees with everything they need to do their best work. Start-up equity 100% health, vision & dental coverage options Catered breakfast, lunch, & dinner Flexible PTO ClassPass membership Monthly commuter benefit Team building events & happy hours Home office stipend Phone/internet reimbursement Paid parental leave Fertility stipend 401k plan Unlimited AI token usage We are committed to building a diverse and inclusive workspace where everyone (regardless of age, religion, ethnicity, gender, sexual orientation, and more) feels like they belong. #J-18808-Ljbffr
$134k - $202k
...customers, growing our community, or shaping our story, you’ll help define what comes next. About the role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with...SuggestedWork at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours$135k - $165k
...platform and customer relationships. As we continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk management programs. Role Overview Ivo is seeking a detail-oriented...SuggestedContract workFlexible hours$150k - $200k
...Galaxy Ventures, we are building the infrastructure for the next era of the global economy. Join us! Overview We're hiring a GRC Senior Analyst to help build the compliance foundation powering the future of global crypto payments. At Mesh, we're connecting hundreds of...SuggestedWork at officeRemote work2 days per week- Vercel in San Francisco is seeking a GRC Analyst to join our Governance, Risk & Compliance team. You will manage and maintain ongoing compliance with security and privacy frameworks, policies, and audits including ISO 27001, SOC 2, HIPAA, and PCI DSS. You will collaborate...SuggestedRemote jobWork at office
- Ivo is looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst in San Francisco. The ideal candidate will support compliance programs such as SOC 2 Type II and ISO 27001 while managing audits and risk assessments. This onsite role offers a competitive...Suggested
- Zip is hiring a GRC Analyst to drive compliance programs across SOC 1, SOC 2, ISO 27001, and expanding into the EU and regulated industries. You’ll partner with internal teams and external auditors to maintain certifications and enable secure product development. In this...
- Anthropic is seeking a Senior Third Party Risk Manager to lead the top tier of vendor risk, including mission-critical compute, data center, and data-pipeline partners. You will shape risk assessments, escalation, and remediation across security, privacy, and operations...Work at officeVisa sponsorship
- Youcom is seeking a GRC Analyst to support the compliance function within our Security, IT, and Privacy team. This role focuses on managing compliance programs across key frameworks like SOC 2 and ISO 27001. The successful candidate will coordinate audit activities, conduct...Flexible hours
- Fluidstack is seeking a Security Compliance Lead in San Francisco to own end-to-end controls across SOC 2 Type II, ISO 27001, NIST 800-53, and FedRAMP, building a scalable program for global sites. You will collaborate with engineering and operations to gather evidence,...
- Salesforce.com, inc. is seeking a detail-oriented Security GRC Analyst to join their Security and Compliance team. In this role, you will lead the Unified Audit program ensuring compliance across various frameworks like SOC 2 and HIPAA, while managing evidence collection...
$218k - $269k
...7001, NIST 800‑53, and FedRAMP Moderate equivalency: continuous evidence collection, control monitoring, and audit readiness held on GRC platforms (Vanta) and the tooling we build in‑house. Own the policy and procedure set: draft, maintain, and run the review cycle so...Local area$135k - $165k
Icehouseventures is seeking a proactive GRC Analyst to join our team in San Francisco. This role will support compliance and risk management initiatives essential for maintaining high security standards. The ideal candidate will have 3-5 years of experience in GRC and relevant...Contract work$117.2k - $176.7k
...Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceLocation: San Francisco, CAThe Senior Security GRC Analyst role is part of our Assurance team, sitting at the intersection of internal operations and external audit relationships. This...Full timeWork at office- Perplexity is seeking a Governance, Risk & Compliance Analyst to shape and run our compliance and risk management program. You will lead the implementation of frameworks, oversee data privacy regulations, and build scalable audit systems in a fast‑growing startup environment...
- Mercury is seeking an Information Security GRC Analyst to mature security, risk, and compliance programs and build guardrails for business continuity and resilience. You will lead risk assessments, partner with cross‑functional teams, and drive audit readiness across SOC...
- ...enable self-service responses. You will manage risk and control workflows, triaging issues and escalating as needed. You will analyze GRC posture, align standards to policies, and automate evidence collection and controls across the org. The role emphasizes automation-...
- Discord Inc. is growing its Security GRC function and seeks a Security Analyst to own the day-to-day program, including questionnaires, risk tracking, analyses, tooling, and documentation. You will work with Security, Engineering, IT, and Legal to make compliance friction...
- Salesforce, Inc. is seeking a Security GRC Analyst to lead the Unified Audit program across SOC 2, HIPAA, ISO 27001, and GxP. The role partners with control owners and external auditors to ensure continuous compliance and audit readiness. The ideal candidate has 2-4 years...
- Salesforce is seeking a Security GRC Analyst to own the Unified Audit program across SOC 2, HIPAA, ISO 27001, and GxP. You will coordinate internal evidence collection, manage control owners, and serve as the main liaison with external auditors to ensure audit readiness...
- ...and bring people together through commerce.RoleWhatnot's Security GRC team is dedicated to building trust with regulators, customers,... ...goes a long way here.As our Governance, Risk, & Compliance Analyst you should have a minimum of 8+ years of relevant experience in...Local areaRemote workHome office
- Who Are We?Taking care of our customers, our communities and each other. That’s the Travelers Promise. By honoring this commitment, we have maintained our reputation as one of the best property casualty insurers in the industry for over 170 years. Join us to discover a ...Full timeLocal areaLong distanceNight shift
$132.6k - $195k
..., merchants, and drivers.About the RoleThe Global Governance, Risk, and Compliance (GRC) team is looking for a technical, security-focused Third-Party Risk Management (TPRM) Sr. Analyst. If you are comfortable and have experience working in a fast-paced environment, taking...Hourly payContract workWork at officeLocal areaRemote workFlexible hours$265k - $285k
Reference: 630009Posted: 2026-08-11Location: Brisbane, CaliforniaCompany: Planet Pharma GroupContact: ApplicationsEmail: ****@*****.*** include: Provides regulatory leadership in support of the development, registration, and life-cycle management...- ...experience in regulatory compliance, business banking, or commercial cardFamiliarity with vendor management, SOC1, SOC2, risk management and GRC processes and toolsExperience designing and overseeing compliance processesDynamic multi-tasker who can juggle multiple priorities...Flexible hours
$255k - $315k
Relay is a digital banking platform that gives self-made business owners the tools and know-how to be great with money—bringing clarity, confidence, and control to every dollar earned, so they can turn hard work into lasting success. We do this by replacing financial guesswork...Full timeImmediate start$160k - $260k
...Banking from an advisory perspective.What will you do?Review research notes / reports submitted to the Control Room by Supervisory Analysts for review and approval of content against the Watch / Restricted ListsRestricted List: daily updating and monitoring of the...Full timeWork at officeFlexible hoursWeekend work- Your OpportunityAt Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry together.The Liquidity Risk Management group within Treasury manages...Full timeWork experience placement
$127k - $165k
Career-defining. Life-changing. At iRhythm, you’ll have the opportunity to grow your skills and your career while impacting the lives of people around the world. iRhythm is shaping a future where everyone, everywhere can access the best possible cardiac health solutions...Full timeRemote work$195.5k - $272.5k
Vir Biotechnology, Inc. is a clinical-stage biopharmaceutical company focused on powering the immune system to transform lives by discovering and developing medicines for serious infectious diseases and cancer. Its clinical-stage portfolio includes programs for chronic ...Full timeWork at officeWork visa3 days per week- Job Overview: We are seeking an experienced and highly motivated Regulatory Manager to join our Regulatory Affairs team. In this role, you will be responsible for developing and executing regulatory strategies to ensure compliance and successful product approvals. You...Contract workWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!

