GRC Analyst

Cast & Crew
$110,000 - $120,000Onsite

About The Position

The GRC Analyst supports the Information Security Office by managing third-party vendor risk, processing security questionnaires, and assisting with audit and compliance activities across the enterprise. This role is well-suited for someone with a strong compliance background who is looking to grow within information security. The ideal candidate is detail-oriented, organized, and experienced working with compliance frameworks, audit processes, and GRC tools such as Drata or similar platforms. A willingness to learn security concepts and stay current on evolving practices is essential.

Requirements

  • 5+ years of experience in compliance, audit, GRC, or a related field, with exposure to information security concepts. Equivalent experience in risk management, regulatory compliance, or internal audit will be considered.
  • Working knowledge of compliance frameworks, audit processes, or risk management programs
  • SOC 1 or SOC 2 audit support or audit evidence collection (direct audit experience a plus)
  • Development or maintenance of policies, procedures, and compliance documentation
  • Third-party or vendor risk processes (experience with formal TPRM programs a plus)
  • GRC or compliance automation tools (e.g., Drata, Andromeda, or similar platforms)
  • Excellent oral communication skills and comfortable in group or small team settings
  • Excellent written communication skills
  • Ability to take highly technical material and present/communicate it to a non-technical audience
  • Builds excellent working relations with all IT colleagues and users, works effectively with department and executive management, and maintains a professional relationship with outside clients and vendors
  • Exhibits mature organization and time management skills
  • Excellent problem-solving skills
  • Effectively planning and organizing daily work following priorities set by the Risk Manager
  • Demonstrates strong follow-up and follow-through skills in ensuring timely completion of projects
  • Self-starter who actively takes responsibility to resolve issues but also knows when to ask questions to avoid major delays in delivery of work product
  • Knowledge of SOC 1 Type 2 and SOC 2 Type 2 audit processes and control frameworks
  • Knowledge of GRC and compliance automation tools, with preference for Drata
  • Knowledge of security questionnaire frameworks (e.g., SIG, CAIQ, NIST) and third-party risk methodologies
  • Knowledge of evidence collection, reporting, and security documentation best practices
  • Skill In: Coordinating SOC audit activities, evidence collection, and auditor communication
  • Skill In: Working with compliance frameworks such as NIST CSF, NIST 800-53, or ISO/IEC 27001 (familiarity sufficient; deep expertise not required)
  • Skill In: Completing or supporting security questionnaire responses (SIG, CAIQ, or similar)
  • Skill In: Writing clear, well-organized compliance documentation and communicating requirements across teams

Nice To Haves

  • CISA or CISM (compliance/audit-focused; strongly relevant to this role)
  • CRISC (risk and controls focus)
  • CISSP, GIAC/GSEC, or vendor certifications (AWS/Azure)

Responsibilities

  • Managing the end-to-end third-party vendor risk management program, including onboarding assessments, periodic reviews, and ongoing monitoring of vendor security posture.
  • Supporting an internal ISRM program focused on uncovering cybersecurity risk and adding it to a risk register for prioritization and acceptance and ownership or remediation
  • Completing and responding to inbound security questionnaires (e.g., SIG, CAIQ, custom questionnaires) from clients and partners in a timely and accurate manner.
  • Coordinating information gathering and interviewing of internal stakeholders to support third-party security questionnaire responses.
  • Supporting and maintaining the organization's compliance automation platforms (e.g., Drata and Andromeda), including evidence collection, control mapping, and readiness tracking.
  • Supporting SOC 1 Type 2 and SOC 2 Type 2 audits, including evidence collection, auditor coordination, and remediation of identified gaps.
  • Developing, maintaining, and improving security documentation, policies, standards, procedures, and runbooks.
  • Monitoring and reporting on internal control effectiveness and audit readiness posture.
  • Advising internal lines of business, IT partners, and third parties on how to remediate security gaps identified through assessments or audits.
  • Understanding applicable regulations, guidelines, and industry best practices to manage risk and ensure compliance.
  • Drafting and presenting risk reports and proposals to executive leadership and senior staff.
  • Performing other duties as directed.

Benefits

  • Medical
  • Dental
  • Vision
  • PTO
  • health and wellness programs
  • employee discounts
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service