Jobiba hiring network

Senior Grc Analyst Jobs

15 active opportunities · Updated for September 2026

Fresh results

15 shown

Explore current senior grc analyst jobs. Use filters to narrow by work mode, employment type, experience and date posted.

L
Litmos
📍 IndiaFull-timeFrom ₹24L/yr
3 days ago

Are you looking for an opportunity to help solve one of today's biggest business challenges? AI is changing the pace of business, and organizations everywhere are struggling to help their workforce, partners, and customers keep up. At Litmos, we're building the Learning Acceleration Platform that helps organizations build human capability faster—and we're looking for people who are passionate about making a meaningful impact for customers while growing alongside a collaborative, people-first team. Litmos is the Learning Acceleration Platform that helps organizations build capability faster, adapt at the speed business changes, and scale learning to anyone, anywhere. Combining an intuitive platform, AI-powered capabilities, trusted content, expert services, and a broad ecosystem of integrations, Litmos helps organizations accelerate workforce productivity, improve customer adoption and retention, enable high-performing partners, and reduce organizational risk through continuous learning. Organizations such as Hewlett Packard Enterprise, Graco, Sabre, and Russell Mineral Equipment trust Litmos to accelerate learning across their workforce, partners, and customers. Today, more than 11K customers with 30 million learners across 150 countries and 37 languages use Litmos to build the capabilities their organizations need to succeed. Backed by Francisco Partners, one of the world's leading technology investment firms, we're investing in the future of learning—and the people who are building it. Learn more at www.litmos.com . We are seeking an experienced and strategic Senior GRC Analyst to join our information security team. With 3-5 years of hands-on experience, you will serve as a subject matter expert across governance, risk, and compliance — owning critical programs, driving process maturity, and acting as a trusted advisor to leadership and cross-functional stakeholders. This role goes beyond execution; you will shape the direction of our GRC progra

awsazuregcp
View job →

Most security assurance work is reactive: a customer asks, a team scrambles, an answer goes out. This role exists to end that cycle. As a Senior Staff Analyst, you’ll own a named portfolio of our most significant customers from a security perspective, and get ahead of what they need — their regulatory environment, their audit calendar, their risk appetite, their control expectations — well enough to have the evidence ready before the request arrives. You’ll lead customer security audits hands-on, sit across from customer security teams as a peer rather than a form-filler, and build account security plans that make the next assessment predictable instead of painful. This is deliberately a hands-on senior individual contributor role. You’ll spend your time in audits, in customer conversations, and in the detail of controls and evidence — not in a management chain. If you’ve got deep SOC 2 and ISO 27001 knowledge, real technical range across cloud architecture, identity and vulnerability management, and the presence to hold a room with a sceptical CISO, this is a portfolio you can genuinely own. Here’s a breakdown of what you’ll do (not all of it, just the important stuff): Own a portfolio of strategic accounts as their dedicated security point of contact, building durable relationships with their security, risk, compliance and procurement teams. Lead customer security audits and assessments hands-on — scoping, preparing evidence, running the sessions, defending control design and driving findings to closure with internal owners. Build and maintain an account security plan for each account: their frameworks and regulators, audit and reassessment cycles, known concerns, open items and the roadmap commitments they care about. Anticipate requirements before they’re raised, tracking regulatory change, industry expectations and each account’s compliance calendar so documentation and evidence are staged in advance. Act

reactawsgit
View job →
R
Roblox
📍 San MateoFull-timeFrom $209.3K/yr
1mo ago

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team’s mission. The GRC team is at the heart of Roblox's security organization — empowering every builder to make risk-informed decisions by establishing a portfolio of governing policies and standards, a repeatable and scalable method of assessing and quantifying risk, and a formal oversight process for GRC capabilities across Roblox. Our program takes a balanced, "right-sized" approach to security governance — combining qualitative and quantitative risk management methodologies, including Factor Analysis of Information Risk (FAIR), to assess and prioritize the security risks that matter most to Roblox. GRC partners closely with Engineering, Legal, Finance, and leadership — including providing regular reporting to the Board of Directors and the Audit & Compliance Committee — to ensure that security risk is visible, well-understood, and actioned appropriately. The team is in an exciting phase of growth and innovation. We are using engineering to drive automation across risk management, policy lifecycle management, supply chain risk, AI risk, and controls pr

awsgitai
View job →
P
Pinterest
📍 San FranciscoFull-timeRemoteFrom $123.7K/yr
20 days ago

About Pinterest: Millions of people around the world come to our platform to find creative ideas, dream about new possibilities and plan for memories that will last a lifetime. At Pinterest, we’re on a mission to bring everyone the inspiration to create a life they love, and that starts with the people behind the product. Discover a career where you ignite innovation for millions, transform passion into growth opportunities, celebrate each other’s unique experiences and embrace the flexibility to do your best work. Creating a career you love? It’s Possible. At Pinterest, AI isn't just a feature, it's a powerful partner that augments our creativity and amplifies our impact, and we’re looking for candidates who are excited to be a part of that. To get a complete picture of your experience and abilities, we’ll explore your foundational skills and how you collaborate with AI. Through our interview process, what matters most is that you can always explain your approach, showing us not just what you know, but how you think. You can read more about our AI interview philosophy and how we use AI in our recruiting process here . Pinterest’s Security team (Pinfosec) is seeking an IC14 Security Engineer - Security Governance, Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and assurance programs. This role is ideal for someone who is detail-oriented, collaborative, and motivated by building scalable security processes that help the business manage risk effectively. Reporting to the Interim Head of Security Governance, Risk & Compliance, this individual contributor will partner closely with Security, Engineering, IT, Legal, Internal Audit, and other cross-functional stakeholders to help maintain and improve Pinterest’s security control environment. The role will contribute to core GRC activities including risk management, policy governance, control testing, audit support, awareness tracking, and internal risk assessmen

REMOTEawsrestai
View job →
O
3 days ago

Strength in Trust OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society. The Challenge We are looking for a dynamic Senior Information Security GRC Analyst to support IT and InfoSec by performing various governance, risk, and compliance activities as part of the OneTrust InfoSec GRC team. Your Mission Customer Security Assurance & Questionnaires Own a high volume of end-to-end completion of customer security questionnaires (CAQs) , RFP security sections, and other assurance artifacts (e.g., SIG, CAIQ, custom questionnaires). Provide accurate, consistent, and defensible responses by leveraging internal evidence repositories (SOC reports, ISO certificates, policies, standards, diagrams, pen test summaries, etc.). Partner with internal stakeholders (Sales, Marketing, Customer Success, Security, Engineering, Privacy, Legal, Compliance, Product) to validate responses and resolve gaps. Customer Engagement & Security Discussions Meet with customers and prospects to explain security controls, risk posture, and compliance commitments . Present security topics with confidence and clarity—tailoring depth for technical and non-technical audiences. Support Sales and Customer Success by addressin

awsgitai
View job →
P
1mo ago

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. About the Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. The Security Contracts workstream is a core part of our Security Assurance and Trust Enablement program — ensuring Plaid's contractual security obligations with customers and data partners are defensible, consistent, and never a bottleneck to deal velocity, all while building trust. About the Role You will own Plaid’s Security Contracts workstream end-to-end—the DRI for how security contract reviews get done, how fast they move, and how the program improves over time. You will review security provisions in customer MSAs, DPAs, and security addenda, identify unacceptable clauses, and provide Legal and GTM with the actionable security feedback they n

D
Discord
📍 San Francisco Bay AreaFull-time$144K – $162K/yr
1mo ago

Discord has a highly engaged community of millions of daily active users who use the platform for many different reasons, but there’s one thing that nearly everyone does: play video games. Discord plays a uniquely important role in the future of gaming, and we are focused on making it easier and more fun for people to hang out before, during, and after playing games. Discord's Legal team is growing its Security GRC function, and we're looking for a Security Analyst to help run and scale it. You'll own the day-to-day engine of the program: the questionnaires, risk tracking, analyses, tooling, and documentation that keep compliance moving. As we build, that's a mix of hands-on work today and the systems that shrink it over time, because we'd rather automate a control than babysit it. We care about the right level of compliance for Discord, our users, and our customers. You'll partner across Security, Engineering, IT, and Legal to make compliance feel friction-free, even invisible, rather than something teams have to fight. What you'll be doing Run the customer security questionnaire program end-to-end, from intake through response, and grow a reusable answer library that turns repeat questions into fast, near-self-service answers. Operate risk and control workflows: triage incoming risks, track gap closure and risk treatment through to completion, and keep the risk register accurate and current. You'll be the first point of contact for partner teams, resolving routine questions and escalating the ones that need senior judgment. Run GRC analyses that turn into decisions: how standards, procedures, and controls align to our policies and framework requirements; where the gaps are; and how mature and effective our controls actually are. Build and maintain the GRC toolchain and its automation: administer our GRC platform, ticketing, and knowledge bases, and design the integrations and workflows that collect evidence and check controls by default rather than by hand. Create

DC
Diligent Corporation
📍 VancouverFull-timeFrom C$250K/yr
3 days ago

Overview We are seeking a hands-on Director of AI Software Engineering to lead and scale AI engineering efforts supporting multiple business units across Governance, Risk, and Compliance (GRC). This role sits at the intersection of product delivery, platform evolution, and applied AI—driving real-world impact across core workflows. This is not a pure management role. We are looking for a builder who leads from the front, someone who has recently written production code, shipped systems end-to-end, and can operate comfortably in ambiguity while aligning teams and stakeholders. What You’ll Do Lead AI Engineering Across GRC Own delivery of AI-powered capabilities embedded directly into business unit workflows (e.g., risk analysis, compliance automation, reporting, due diligence) Partner with product, data, and platform teams to translate business problems into scalable AI systems Stay Hands-On Contribute to architecture, code reviews, and critical path implementation Prototype and validate new approaches (LLMs, agents, retrieval systems, classification pipelines, etc.) Set engineering standards for performance, reliability, and cost efficiency Build and Scale Teams Lead and mentor a high-performing team of AI/ML and software engineers Drive hiring, coaching, and career development Establish a culture of ownership, speed, and technical excellence Drive Execution Deliver production-grade systems—not experiments Balance speed with rigor (security, privacy, compliance) Operate across multiple concurrent initiatives with clear prioritization Communicate and Influence Act as a bridge between engineering and business stakeholders Clearly articulate trade-offs, risks, and outcomes to senior leadership Align cross-functional teams around shared goals and timelines What We’re Looking For Proven Builder 10+ years in software engineering, with recent hands-on coding experience Demonstrated track record of shipping production systems at scale Experience with modern

pythonjavaaws
View job →
DC
3 days ago

Role Overview You are a senior product leader who wants to shape how AI transforms IT and cyber risk management at scale. In this role, you will own one of the most strategic product areas in a global GRC SaaS platform, defining how organisations identify, assess, and act on cyber risk — and how CISOs and boards get the clarity they need when it matters most. You will set and drive the product vision, roadmap, and outcomes for IT & Cyber Risk on a multi-solution platform used by enterprises worldwide. You will partner closely with engineering, design, data science, and senior leaders to build AI-native capabilities that automate risk detection, prioritisation, and reporting. Your work will have high executive visibility, real strategic weight, and direct impact on how customers manage governance, risk, and compliance. Here’s a breakdown of what you’ll do (not all of it, just the important stuff) Lead the end-to-end product strategy and roadmap for IT & Cyber Risk, aligning to company objectives and broader platform direction. Design and deliver AI-powered features (LLMs, agents, ML models) that automate risk identification, assessment, and reporting for enterprise security and risk teams. Partner with engineering, data science, and design to define technical approaches, ship high-quality releases across web, mobile, and API, and iterate using product analytics. Develop deep market and customer insight by engaging regularly with CISOs, security leaders, and risk managers, and turn those insights into clear product bets. Define, track, and communicate product KPIs, AI performance metrics, and north star outcomes to senior stakeholders, including business cases for major investments. Work cross-functionally with Sales, Customer Success, Professional Services, and Marketing to ensure successful launches and adoption of new IT & Cyber Risk capabilities. These are the essentials you’ll need to get an interview 7+ years of product management experience, includi

awsgitagile
View job →
CV
1mo ago

Job Summary: We are seeking an experienced and highly analytical professional to join our Internal Audit team. This role is critical in providing independent assurance, enhancing the control environment, and leveraging data analytics to identify anomalies, control gaps, and potential fraud risks. The ideal candidate will have a strong background in internal audit, forensic investigations, and data analytics with extensive exposure to fintech or large service-based organizations. Key Responsibilities:  Lead and execute risk-based internal audits, including operational, financial, and compliance reviews.  Design and implement data analytics frameworks and continuous auditing techniques to enhance audit efficiency and coverage.  Conduct forensic reviews and investigations into suspected fraud, misconduct, or control failures.  Collaborate with cross-functional teams to understand key business processes and identify risks and controls.  Develop automated dashboards and data-driven tools to monitor key risk indicators and red flags.  Report audit findings to senior management and stakeholders with actionable recommendations.  Oversee documentation of working papers, audit procedures, and evidence in line with professional standards.  Mentor junior audit staff and build analytics capability within the team.  Liaise with external auditors, regulators (as needed) on investigations or audits.  Monitor regulatory and industry developments to ensure audit approaches are up to date. Required Qualifications ; Skills:  Chartered Accountant (CA), Certified Internal Auditor (CIA), or Certified Fraud Examiner (CFE) preferred.  2–7 years of relevant experience in internal audit, forensic investigations, or risk advisory in a fintech, BFSI, or large service industry setup.  Strong command of data analytics tools (e.g., SQL, ACL, IDEA, Power BI, Python, R).  Proficient in audit management systems and GRC platforms.  Exceptional analytical, investigative, and report-w

pythonsqlgit
View job →
P
Postman
📍 San FranciscoFull-time
1mo ago

Who Are We? Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster. The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman. P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman. The Opportunity The Security GRC team is responsible for the overall security posture of Postman by ensuring compliance with applicable regulations and contractual obligations and maintaining effective and efficient governance, risk, and compliance programs. In addition, the Security GRC team is directly involved with supporting and enabling Sales and driving security and compliance initiatives to further the growth of Postman. We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills to build and scale automation across governance, risk, and compliance. This is a hands-on technical role focused on designing and operating GRC tooling, integrations, and AI-assisted workflows that reduce manual effort while improving security assurance. The ideal candidate has experience implementing and maturing compliance programs, including SOC 2, ISO 27001, HIPAA, GDPR, CCPA, and FedRAMP, and can translate security and risk requirements into practical engineering solutions. As a senior member of the Security GRC team, you will partner with Security, Engineering, IT, Legal, Sales, and other stakeholders to

javascriptpythonjava
View job →
O
3 days ago

Strength in Trust OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society. The Challenge We are looking for a Senior Technical Architect (GRC) to join our Technical Advisory team (part of Customer Success). This is a customer-facing role for someone who combines strong GRC expertise with attention to details, and the ability to build trust with customers. You will work with risk leaders, compliance teams, audit, control owners, procurement, and technology stakeholders to understand business objectives and challenges, assess maturity and platform adoption, and provide clear recommendations to unlock business outcomes. You will act as a trusted advisor and product expert without owning hands-on implementation or configuration. Your Mission Lead outcome-focused discovery, advisory engagements, workshops, and expert sessions with customers. Apply your GRC expertise to understand customer objectives, processes, pain points, constraints, and desired outcomes before recommending a path forward. Guide customers across relevant capabilities such as IT risk management, compliance automation, enterprise policy management, audit and compliance management, third-party risk, and related GRC workflows. Expl

awsgitai
View job →
S
1mo ago

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. FedRAMP and GovRAMP (formerly StateRAMP) are transforming how Smartsheet serves government and regulated customers. We need a FedRAMP and GovRAMP subject matter expert to lead these programs—someone with real hands-on experience obtaining and maintaining ATO authorizations, navigating 3PAO assessments, and managing continuous monitoring requirements. In this role, you'll own Smartsheet's FedRAMP and GovRAMP certifications, manage relationships with our 3PAOs, drive annual assessment preparation, manage POA&M processes, and ensure we maintain authorizations at the highest level. You'll understand the nuances of federal compliance, speak fluently with government agencies and authorized assessors, and translate complex regulatory requirements into clear roadmaps for engineering and operations teams. You'll be the voice of federal compliance at Smartsheet and the trusted advisor to government customers on our security posture. You Will: Own FedRAMP and GovRAMP (formerly StateRAMP) certifications and roadmaps: Lead the overall strategy for obtaining and maintaining federal authorizations, including package management, compliance timelines, and authority coordination. Manage 3PAO relationships and assessments: Work with accredited third-party assessment organizations to conduct initial assessments and annual re-assessments. Coordinate scoping, evidence preparation, testing coordination, and results validation. Lead continuous monitoring (ConMon) execution: Oversee the delivery of monthly, annual, and event-driven Fed

REMOTEawsazuregcp
View job →
V
Vanta
📍 United StatesFull-time
1mo ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Our Senior Software Engineers lead and mentor engineers, delivering high-value products for our customers and infrastructure that enables our business to scale. Vanta’s team and technology surface are growing quickly, and it’s essential that we invest in the right abstractions and systems to enable us to scale with our business. As a Senior Software Engineer, you’ll be responsible for setting technical direction to enable our product and infrastructure to scale with our business, driving complex projects across our technical stack, and mentoring our talented engineering team. Your past experience will be leveraged to enable and accelerate Vanta’s growth. Our business has found incredible product-market fit and has monetized effectively since the day we signed our first customer. We’re growing at a blistering pace, which presents career-defining opportunities for engineers to accelerate their growth and to contribute to a rapidly-scaling company. Visit our Vanta Engineering Blog to learn more about what our team is working on! The GRC (Governance, Risk and Compliance) organization is the primary org responsible for developing and maintaining Vanta's core product offerings. These teams are at the heart of Vanta moving upmarket to support enterprise customers and build products that enable our customers’ existing security and compliance programs to integrate seamlessly with Vanta, giving them invaluable insights and recommendations to continue to operate, mature and evolve their programs. What you’ll do as a Senior Software Engineer at Vanta: Lead complex projects with multiple stakeholders and engineers to deliver significant imp

typescriptreactnode.js
View job →
V
1mo ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Our Senior Software Engineers lead and mentor engineers, delivering high-value products for our customers and infrastructure that enables our business to scale. Vanta’s team and technology surface are growing quickly, and it’s essential that we invest in the right abstractions and systems to enable us to scale with our business. As a Senior Software Engineer, you’ll be responsible for setting technical direction to enable our product and infrastructure to scale with our business, driving complex projects across our technical stack, and mentoring our talented engineering team. Your past experience will be leveraged to enable and accelerate Vanta’s growth. Our business has found incredible product-market fit and has monetized effectively since the day we signed our first customer. We’re growing at a blistering pace, which presents career-defining opportunities for engineers to accelerate their growth and to contribute to a rapidly-scaling company. Visit our Vanta Engineering Blog to learn more about what our team is working on! Please note we are only able to hire in Alberta, Ontario, and British Columbia. The GRC (Governance, Risk and Compliance) organization is the primary org responsible for developing and maintaining Vanta's core product offerings. These teams are at the heart of Vanta moving upmarket to support enterprise customers and build products that enable our customers’ existing security and compliance programs to integrate seamlessly with Vanta, giving them invaluable insights and recommendations to continue to operate, mature and evolve their programs. What you’ll do as a Senior Software Engineer at Vanta: Lead comp

typescriptreactnode.js
View job →
🔔

Get new senior grc analyst jobs by email

Daily job updates · Unsubscribe anytime