Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Governance Risk & Compliance Analyst I

$49.73k - $73.13k
Full-time

Commerce

Welcome to the Agentic Commerce Era

At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce, Feedonomics, and Makeswift, we connect the tools and systems that power growth, enabling businesses to unlock the full potential of their data, deliver seamless and personalized experiences across every channel, and adapt swiftly to an ever-changing market. We believe in harnessing AI responsibly to unlock new possibilities, and we’re looking for individuals who use it intentionally to solve problems, accelerate outcomes, and expand what’s possible in their role. Our purpose is to help businesses confidently solve complex commerce challenges so they can build smarter, adapt faster, and grow on their own terms. If you want to be part of a team of bold builders, sharp thinkers, and technical trailblazers who shape the future of commerce, this is the place for you.

We're looking for a detail-oriented and curious GRC Analyst to join our Governance, Risk & Compliance team. In this role, you'll support the day-to-day operations of our risk and compliance program, helping assess third-party vendors, maintain policy documentation, track control evidence, and support audit activities.

We're especially interested in candidates who've explored tools like Claude Code and are curious about how AI can be applied to cybersecurity and compliance work. This is a great opportunity for someone early in their career who wants to build a strong foundation in enterprise risk management and information security compliance, joining a senior, globally distributed team that will invest in your growth from day one.

What You'll Do

  • Support third-party risk assessments by reviewing vendor security questionnaires, documentation, and due diligence materials
  • Maintain and update the vendor risk register and track remediation activities to closure
  • Assist with internal control testing and evidence collection for compliance frameworks (SOC 2, ISO 27001, PCI-DSS, etc.)
  • Help coordinate audit requests and liaise with internal stakeholders to gather required documentation
  • Monitor policy and procedure documentation, flagging items due for review or update
  • Assist in tracking risk exceptions, escalating items that require senior review
  • Support reporting and metrics preparation for leadership and committee-level reviews
  • Contribute to process improvement initiatives as the program scales


What We're Looking For

  • 0–2 years of experience in GRC, risk operations, compliance, or a related function (internships count)
  • Bachelor's degree Computer Science, Cybersecurity, Information Systems, Business, or a related field. Equivalent work experience also considered.
  • Genuine interest in GRC engineering and a willingness to learn quickly in a fast-paced environment required
  • Hands-on familiarity with Claude Code or similar AI coding tools, and an ability to think through how they could be applied to cybersecurity or GRC work (hobby projects welcome)
  • Strong written and verbal communication skills - you'll be working cross-functionally and with external vendors
  • High attention to detail and comfort working with documentation, spreadsheets, and tracking tools
  • Proficiency in Microsoft Office or Google Workspace


Nice To Have

  • Coursework or certification in cybersecurity or risk management (Security+, CISA, etc.)
  • Exposure to compliance frameworks such as SOC 2, ISO 27001, NIST, or PCI-DSS
  • Experience in an operations or process-driven role (internship or otherwise)

#LI-RA-1

Salary Transparency Range: $49,729.00 - $73,130.00

Compensation Transparency


The national base salary range for this role is posted above in this job post.

Final compensation will be determined based on factors such as relevant experience, skills, qualifications and geographic location. We also consider internal equity to help ensure fair and consistent pay practices across our teams.

Where applicable, this role may also be eligible for variable compensation (such as bonus or commission), equity, and benefits in accordance with local policies. Details will be shared during the hiring process. We are committed to equitable and transparent pay practices that align to market data, internal equity, and individual contribution.

Inclusion and Belonging

At Commerce, we believe that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community. We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive.

We are committed to creating an inclusive and accessible hiring experience for all candidates. If you require accommodations or adjustments at any stage of the recruitment process, please let us know and we will work with you to meet your needs.

Learn more about the Commerce team, culture and benefits at

Identity Verification


To protect our candidates and company from fraudulent activity, our interview process includes a government ID and biometric verification via Persona, our trusted identity verification provider. All information is collected and processed securely in accordance with applicable privacy laws.

Protect Yourself Against Hiring Scams: Our Corporate Disclaimer


Commerce, along with many other employers, has become the subject of fraudulent job offers to hopeful prospective job seekers.

Be advised:
Commerce does not offer jobs to individuals who do not go through our formal hiring process.

Commerce will never:
  • require payment of recruitment fees from candidates;
  • request personally identifiable information through unsanctioned websites or applications;
  • attempt to solicit money from you as part of the hiring process or as part of an employment offer;
  • solicit money to complete visa requirements as part of a job offer.


If you receive unsolicited offers of employment from Commerce, we urge you to be extremely cautious and avoid engaging or responding.

Vacancy posted 8 days ago
Similar jobs that could be interesting for youBased on the Security Governance Risk & Compliance Analyst I in Remote vacancy
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We partner with the world's leading AI research labs to build smarter, safer...  .... As a GRC Analyst, your hands-on expertise with security policies, audit frameworks, and risk controls will directly... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Worldwide
    Flexible hours

    Alignerr

    Chicago, IL
    16 hours ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter...  ...time inside compliance programs, risk frameworks, or security audits, your expertise is exactly what's needed to train... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Miami, FL
    16 hours ago
  • $95k - $105k

     ...support Connected Logistics is seeking a senior Risk and Compliance Analyst to support cybersecurity governance, enterprise risk management, compliance oversight...  ...on cybersecurity compliance, risk mitigation, security control effectiveness, and regulatory alignment... 
    Suggested
    Contract work
    Remote work

    Connected Logistics

    Springfield, VA
    16 hours ago
  •  ...possible. The Role at a Glance:   The IT Governance, Risk, and Compliance (IT GRC) Compliance Analyst is responsible for supporting the development, implementation...  ...Auditor) o CISSP (Certified Information Systems Security Professional Work Schedule & Hours: Remote... 
    Suggested
    Remote work
    Monday to Friday
    Flexible hours
    Shift work
    Day shift

    PETE & GERRY'S CAREER PAGE

    Monroe, NH
    13 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're looking for experienced GRC professionals to help evaluate and improve AI systems being trained on real-world security, compliance, and risk scenarios. Your practitioner knowledge... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    New York, NY
    16 hours ago
  •  ...GRC Analyst Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk management, security. You'll assess risks, support audits, and develop policies that align...  .... • Assist in the maintenance, governance, and execution of Threat and... 
    Casual work
    Work at office
    Work from home
    Home office
    Night shift
    Weekend work

    Delta Dental of Missouri

    Saint Louis, MO
    2 days ago
  •  ...Description JOB DESCRIPTION: The Senior IT GRC (Governance, Risk, and Compliance) Analyst oversees technical design, implementation, maintenance, and responsibilities for multiple information security disciplines such as security policy, awareness and education... 
    Work experience placement
    Remote work
    Work from home
    Flexible hours

    Emory University

    Atlanta, GA
    3 days ago
  •  ...services integrators in the defense and government services industry. We deliver...  ...and trusted results to enable national security missions worldwide. Job Description...  ...award of contract SOSi is seeking a Risk and Compliance Analyst to support mission requirements for a... 
    Full time
    Contract work
    For contractors
    Remote work
    Worldwide

    SOS International LLC

    Seattle, WA
    1 day ago
  • Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex...  .... You will work directly with clients to assess their security posture, develop policies, and guide them through... 
    Full time
    Remote work

    Districttechgroup

    Washington DC
    2 days ago
  • $100k - $155k

     ...we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. We work...  ...cybersecurity starts with you. About the Role: The Senior Governance, Risk, and Compliance Specialist is tasked with providing assurance and... 
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work

    CrowdStrike

    Remote
    6 days ago
  • $100k - $120k

     ...Governance Risk & Compliance Engineer Polsinelli is hiring a Governance Risk & Compliance Engineer for any of our offices, with the option to...  ...Guidelines to ensure that the Firm meets or exceeds client security requirements and completes the appropriate forms documenting... 
    Full time
    Temporary work
    Part time
    Work experience placement
    Remote work
    Flexible hours
    Shift work

    Polsinelli

    Salt Lake City, UT
    3 days ago
  •  ...Job Description Job Description Title: Governance, Risk & Compliance Analyst II Department: Admin & compliance 802900 Revision Date:...  ...800-171.  The Analyst II will work closely with IT, Security, Engineering, Manufacturing, and external assessment partners... 
    For contractors
    Remote work

    COMTECH TELECOMMUNICATIONS

    Orlando, FL
    6 days ago
  • $136.85k - $161k

    Boston Government Services, LLC. (BGS) has created this Evergreen Talent Pool post for...  ...for a position relating to Risk and Compliance Analyst to support our clients in various locations...  ...BGS is an engineering, technology, and security firm helping to advance missions of national... 
    Full time
    Contract work
    Temporary work
    Remote work
    Monday to Friday
    Night shift

    Boston Government Services, LLC (BGS)

    Knoxville, TN
    4 days ago
  •  ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship... 
    Full time
    Internship
    Remote work

    Ruleset Security

    United States
    22 hours ago
  • $150k - $200k

     ...Overview We're hiring a GRC Senior Analyst to help build the compliance foundation powering the future of global...  ...instrumental in ensuring we scale securely, responsibly, and with trust at the...  .... Conduct vendor and third-party risk assessments as we expand our global... 
    Remote job
    Full time
    Work at office
    2 days per week

    Mesh

    Remote
    a month ago
  • $130k - $135k

    CorporateThe Security GRC Analyst II supports the organization’s data protection and governance programs by implementing security tools, maintaining compliance with data protection requirements, and assisting...  ...role also contributes to risk assessments, supports policy... 
    Minimum wage
    Ongoing contract
    Full time
    H1b
    Local area
    Remote work
    Worldwide

    ZOLL Medical Corporation

    Broomfield, CO
    3 days ago
  •  ...which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch wide...  ...Overview: The Security Operations Center (SOC) Analyst is responsible for monitoring, detecting,... 
    Work at office
    Work from home
    Flexible hours
    2 days per week

    SUMITOMO MITSUI TRUST BANK, LIMITED

    New York, NY
    20 days ago
  • $80k - $100k

     ...Under the direction of the Director, Information Security, the Information Security Compliance Analyst supports the execution, administration, and...  ...improvement of ImageTrend's cybersecurity compliance, governance, and risk management programs. This role is responsible... 
    Full time
    Remote work

    ImageTrend

    Eagan, MN
    19 days ago
  •  ...Technology / Office of Information Security (OIT/OIS) program covering enterprise...  ...architecture and engineering. We are seeking Risk and Compliance Analysts to own the risk, compliance, and...  ...experience at a large company or Government agency similar in size and scope to... 
    Full time
    Contract work
    Interim role
    Work at office
    Remote work

    Triumph Enterprises

    Washington DC
    1 day ago
  •  ...highly skilled Principal Cybersecurity Analyst to serve as a technical authority...  ...shaping and advancing enterprise-wide governance, risk, and compliance (GRC) programs, with expanded accountability for emerging AI security and governance initiatives. This role operates... 
    Full time
    Work experience placement
    Local area
    Remote work
    Relocation package

    MD Anderson

    Houston, TX
    4 days ago
  •  ...cybersecurity initiative, the full-time remote Risk and Compliance Analyst will perform comprehensive risk...  ...Minimum of 7 years of Information Security experience, with at least 5 years in...  ...compliance at a large organization or government agency Expertise in risk management,... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    3 days ago
  • $98.14k - $115k

     ...transformative technology to our government customers so they can...  ...on strengthening enterprise security architecture, systems engineering...  ..., reduce organizational risk, and protect critical systems...  ...for an Engineer, 3, Risk and Compliance Analyst to join this team.... 
    Local area
    Remote work

    9th Way Insignia

    United States
    4 hours ago
  • A consulting firm seeks a Security & Compliance Analyst to support various client environments, concentrating on security operations, compliance preparedness, and risk management. This hands-on position involves collaboration with IT leadership to ensure effective maintenance... 
    Remote work

    Envision Consulting LLC

    Alexandria, VA
    5 days ago
  • $62k - $141k

    Risk Assessment AnalystThe Opportunity: Cyber threats are everywhere, and the constantly...  ...need your knowledge as an information security risk specialist to help break down...  ...experience with services for the Federal government or Federal advising within a professional... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Alexandria, VA
    16 hours ago
  •  ...remotely.Top 3-4 Required Skills:1. Has third party risk experience 2. Has owned the secruity compliance from start to finish 3. Strong communication skillsNice...  ...of audit reports, certifications, questionnaires, security assessments, and other risk artifacts. Recommend... 
    Remote work

    Mindlance

    Durham, NC
    2 days ago
  • $60 - $66.9 per hour

     ...We're currently hiring a Network Security Analyst II for a client based in Newport Beach,...  ...Overview The Network Security Risk & Compliance Analyst serves as the primary liaison...  ...requires experience with cybersecurity governance, control assurance, risk management,... 
    Hourly pay
    Full time
    Temporary work
    Currently hiring
    Local area
    Remote work

    Roth Staffing Companies

    Newport Beach, CA
    5 hours ago
  •  ...Supporting the Enterprise Risk Management program, the full-time Risk Administrator...  ...assessments, business continuity planning, and security awareness initiatives in a fully remote...  ...Party Risk Management program, ensuring compliance with regulatory expectations Assist in... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    3 days ago
  • $65k - $75k

     ...Compliance And Risk Specialist Location: Albany, Buffalo, Rochester, and Syracuse, NY (hybrid remote opportunity) Are you a dynamic...  ...for more than 165 years? Harris Beach Murtha's Information Governance and Risk Management team is in search of a Compliance and Risk... 
    Contract work
    Work at office
    Remote work

    Harris Beach Murtha

    Albany, NY
    4 days ago
  • $28 per hour

     ...Risk Operations Analyst At Prosegur, we make our world safer by taking care of people and businesses while remaining at the forefront of innovation. Every day, we work to secure what our clients value most, from their families to their assets, from their reputation... 
    Contract work
    Remote work
    Flexible hours

    Prosegur Security USA

    Lowell, MA
    3 days ago
  •  ...Biosciences Inc. is growing, and we are looking to hire a full-time Compliance Risk Analyst working from our headquarters in Friendswood, TX. with a...  ...-functional teams to maintain SOC 2 compliance, monitoring security controls, and communicating risk insights to leadership and... 
    Full time
    H1b
    Visa sponsorship
    Work visa

    Castle Biosciences, Inc.

    Friendswood, TX
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Governance Risk & Compliance Analyst I. Be the first to apply!