GRC Analyst
$134k - $202kVercel Corp
About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience. Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents. We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide . Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next. About the role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy frameworks, policies, procedures, and commercial assessments, including ISO 27001, SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company operates ethically, responsibly, and in accordance with regulatory requirements. You will collaborate with cross-functional teams to promote a culture of accountability and integrity throughout the organization and foster an environment where everyone understands the importance of adhering to established guidelines and ethical practices. You will report to the Head of GRC and will be located ((remote, onsite, hybrid)). Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics. If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team. What you will do: Collaborate with internal teams to maintain an effective suite of internal controls and driving remediation efforts to completion with clear documentation of progress. Build strong working relationships across the business so compliance accountability is shared and stakeholders are informed. Streamline annual audits by managing audit deliverables, developing treatment plans, and coordinating across teams to document and track completion to ensure audit success. Monitor and improve controls , processes, and evidence management practices, identify opportunities to automate and streamline GRC operations, and contribute to controls maturity scoring and reporting Enable go-to-market teams and accelerate deal cycles by supporting security questionnaires, addressing compliance inquiries, and maintaining clear, customer-facing documentation on Vercel’s security and compliance posture. Design and manage company training and enhance visibility on compliance-specific topics for internal stakeholders to ensure an understanding of compliance, ethics, and regulatory requirements within the organization. About you: At least 3 years of relevant experience in supporting the audit lifecycle in a cloud-centric environment (SOC 2, ISO 27001, PCI, HIPAA, etc.), with strong organizational skills to be flexible and proactive in a high-growth, start-up environment. Experience collaborating closely with internal partners to seamlessly incorporate policies and technical controls into the SDLC. Strong project management skills and sense of ownership with the ability to communicate and collaborate effectively, and execute projects across various business units and levels. Bonus if you have : Strong experience with cloud infrastructure (e.g., Azure, AWS) Familiarity with compliance or software development tools and systems (e.g., Drata, Linear, Datadog, etc.) Experience with frontend development and open source components Relevant industry certifications (i.e., CISM, CISSP, CCEP) is a plus, but not required Benefits: Competitive compensation package, including equity. Inclusive Healthcare Package. Learn and Grow - we provide mentorship and send you to events that help you build your network and skills. Flexible Time Off. We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed. The San Francisco, CA base pay range for this role is $134,000-$202,000. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process. #J-18808-Ljbffr
- ...raised our Series B and have grown 800% over the last 12 months. The Opportunity Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives. This role will play a key part in...SuggestedContract workWork at officeRemote workVisa sponsorshipRelocation packageFlexible hours
$95k - $150k
...high level of security assurance to customers, aligning security goals with business objectives and customer requirements. As a GRC Analyst at Zip, you’ll be a key driver for ensuring the success of compliance programs at a fast-growing company. Your contributions will...SuggestedHome officeFlexible hours$218k - $269k
...7001, NIST 800‑53, and FedRAMP Moderate equivalency: continuous evidence collection, control monitoring, and audit readiness held on GRC platforms (Vanta) and the tooling we build in‑house. Own the policy and procedure set: draft, maintain, and run the review cycle so documentation...SuggestedLocal area- Zip is hiring a GRC Analyst to drive compliance programs across SOC 1, SOC 2, ISO 27001, and expanding into the EU and regulated industries. You’ll partner with internal teams and external auditors to maintain certifications and enable secure product development. In this...Suggested
- United States Digital Space LLC in San Francisco seeks a Governance, Risk & Compliance Analyst to mature our security program and manage regulatory obligations, shaping compliance and risk practices to build customer trust in a fast-growing startup transforming search and...Suggested
$135k - $165k
...platform and customer relationships. As we continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk management programs. Role Overview Ivo is seeking a detail-oriented...Contract workFlexible hours- Anthropic is seeking a Senior Third Party Risk Manager to lead the top tier of vendor risk, including mission-critical compute, data center, and data-pipeline partners. You will shape risk assessments, escalation, and remediation across security, privacy, and operations...Work at officeVisa sponsorship
$135k - $165k
Icehouseventures is seeking a proactive GRC Analyst to join our team in San Francisco. This role will support compliance and risk management initiatives essential for maintaining high security standards. The ideal candidate will have 3-5 years of experience in GRC and relevant...Contract work- Salesforce.com, inc. is seeking a detail-oriented Security GRC Analyst to join their Security and Compliance team. In this role, you will lead the Unified Audit program ensuring compliance across various frameworks like SOC 2 and HIPAA, while managing evidence collection...
- Fluidstack is seeking a Security Compliance Lead in San Francisco to own end-to-end controls across SOC 2 Type II, ISO 27001, NIST 800-53, and FedRAMP, building a scalable program for global sites. You will collaborate with engineering and operations to gather evidence,...
- Ivo is looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst in San Francisco. The ideal candidate will support compliance programs such as SOC 2 Type II and ISO 27001 while managing audits and risk assessments. This onsite role offers a competitive...
- Vercel in San Francisco is seeking a GRC Analyst to join our Governance, Risk & Compliance team. You will manage and maintain ongoing compliance with security and privacy frameworks, policies, and audits including ISO 27001, SOC 2, HIPAA, and PCI DSS. You will collaborate...Remote jobWork at office
- Perplexity is seeking a Governance, Risk & Compliance Analyst to shape and run our compliance and risk management program. You will lead the implementation of frameworks, oversee data privacy regulations, and build scalable audit systems in a fast‑growing startup environment...
$117.2k - $176.7k
...Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceLocation: San Francisco, CAThe Senior Security GRC Analyst role is part of our Assurance team, sitting at the intersection of internal operations and external audit relationships. This...Full timeWork at office- Discord is seeking a Security Analyst to lead and scale its Security GRC program. You will own the day-to-day workflows—from questionnaires to risk tracking—partnering with Security, Engineering, IT, and Legal to make compliance friction-free. The role emphasizes automation...
- Mercury is seeking an Information Security GRC Analyst to mature security, risk, and compliance programs and build guardrails for business continuity and resilience. You will lead risk assessments, partner with cross‑functional teams, and drive audit readiness across SOC...
$96.3k - $145.2k
...the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all. Experience The Security GRC Analyst role is part of our Security and Compliance team, sitting at the intersection of internal operations and external audit relationships...Work at office- Salesforce, Inc. is seeking a Security GRC Analyst to lead the Unified Audit program across SOC 2, HIPAA, ISO 27001, and GxP. The role partners with control owners and external auditors to ensure continuous compliance and audit readiness. The ideal candidate has 2-4 years...
$183k - $205k
...security governance, risk and compliance initiatives. This person will guide the company from foundational Governance, Risk & Compliance (GRC) maturity through to steady-state operations, leveraging AI to automate and improve old practices and tools, ensuring ongoing...Full timeWork at office2 days per week3 days per week- Salesforce is seeking a Security GRC Analyst to own the Unified Audit program across SOC 2, HIPAA, ISO 27001, and GxP. You will coordinate internal evidence collection, manage control owners, and serve as the main liaison with external auditors to ensure audit readiness...
$132.6k - $195k
..., merchants, and drivers.About the RoleThe Global Governance, Risk, and Compliance (GRC) team is looking for a technical, security-focused Third-Party Risk Management (TPRM) Sr. Analyst. If you are comfortable and have experience working in a fast-paced environment, taking...Hourly payContract workWork at officeLocal areaRemote workFlexible hours- Who Are We?Taking care of our customers, our communities and each other. That’s the Travelers Promise. By honoring this commitment, we have maintained our reputation as one of the best property casualty insurers in the industry for over 170 years. Join us to discover a ...Full timeLocal areaLong distanceNight shift
$140k - $178k
...information they need to achieve their truth-finding goals. As a GRCT Analyst, you will independently drive moderately complex trust,... ...customer security questionnaires and experience with trust portals or GRC tooling. Experience using workflow, metrics, or dashboard data...Local areaFlexible hoursShift work$150k - $180k
...bring new AI capabilities to market, your work will help define how modern AI finds and uses knowledge. The Role We're looking for a GRC Analyst to join our growing Security, IT, and Privacy function. You'll be the backbone of all the compliance work at the intersection of...Full timeImmediate startRemote workWork from homeFlexible hours- ...company is seeking a highly experienced Governance, Risk & Compliance Analyst to join our world-class team. You will help shape our compliance... ...expansion to additional compliance frameworks Build internal GRC platform and tooling Conduct risk assessments and mitigate data...
- SmithRx is seeking a Compliance Analyst to help implement a robust compliance program in a dynamic PBM regulatory landscape. You will remediate non-compliance and support policy and procedure adherence across the organization. You will work with the Corporate Compliance...Remote jobFull timeHome office
- ...Compliance, Business, or related field. CRCM and/or CAMS certification. Experience with securities compliance. Familiarity with GRC tools, Jira, Notion, and SQL . Experience supporting payroll, HCM, payments, embedded finance, or money movement products ....Full timeContract workTemporary workImmediate start
- You.com is looking for a GRC Analyst to join our Security, IT, and Privacy function in San Francisco. This role will be crucial in building and maintaining compliance programs and ensuring trust with our customers. Responsibilities include managing compliance work across...
$153.4k - $191.8k
...management, operational discipline, and accountability. Strong GRC programs help prevent those failures by making security a business... ...security. We are looking for an Information Security GRC Analyst to help mature Mercury’s security, risk, and compliance programs...- The California Public Utilities Commission is seeking an Analyst I to support enterprise risk management, risk and compliance, and division operations under the Program and Project Supervisor. The role involves research, analysis, report preparation, and workflow development...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!


