Governance, Risk & Compliance (GRC) Analyst

IvoSan Francisco, CA
Onsite

About The Position

Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives. This role will play a key part in maintaining and enhancing Ivo's compliance programs, including SOC 2 Type II, ISO 27001, CSA STAR, and ISO/IEC 42001. The ideal candidate has experience supporting security audits, managing evidence collection, conducting risk assessments, maintaining policies and procedures, and partnering cross-functionally with engineering, IT, legal, HR, and business stakeholders. This is a fully onsite role based out of Ivo's San Francisco headquarters to support close cross-functional collaboration with Security, Engineering, IT, and Operations teams.

Requirements

  • 3–5 years of experience in Governance, Risk & Compliance (GRC), Information Security, IT Audit, or related field.
  • Hands-on experience supporting SOC 2 Type II, ISO 27001, CSA STAR, and in-depth knowledge of ISO/IEC 42001.
  • Experience administering or working extensively with Vanta or similar GRC/compliance automation platforms.
  • Experience managing and maintaining a customer-facing Trust Center, including security documentation, compliance artifacts, sub-processor disclosures, and customer assurance materials.
  • Strong understanding of information security principles and common security controls.
  • Experience with audits, evidence management, and customer security reviews.
  • Excellent written and verbal communication skills.

Nice To Haves

  • Experience working at a SaaS or AI company.
  • Familiarity with GDPR, CCPA, privacy regulations, and third-party risk management.
  • Knowledge of cloud environments such as GCP, AWS, or Azure.
  • Relevant certifications such as Security+, CISA, CRISC, CCSK, or ISO 27001 Lead Implementer/Auditor.
  • Would describe yourself as being relentlessly resourceful.
  • You have a strong internal sense of urgency.
  • You have a bias towards doing things today , rather than tomorrow.
  • Experience working in a startup environment is preferred but not required.
  • Are excited about the adventure of building a company!

Responsibilities

  • Support and coordinate Ivo's compliance programs including SOC 2 Type II, ISO 27001, CSA STAR, and ISO/IEC 42001.
  • Assist with annual audits, surveillance audits, and customer security assessments.
  • Coordinate evidence collection and maintain audit readiness across teams.
  • Support and maintain Ivo's Vanta GRC platform and associated compliance workflows.
  • Monitor automated compliance evidence collection and control monitoring within Vanta.
  • Perform vendor and third-party risk assessments.
  • Support enterprise risk management and risk register maintenance.
  • Maintain and update security policies, standards, and procedures.
  • Support AI governance and responsible AI compliance initiatives.

Benefits

  • Competitive Compensation
  • Equity
  • Relocation and Visa Support
  • Comprehensive medical, dental, and vision plans
  • Access to HSA and FSA accounts
  • Life insurance coverage
  • 401(k) Program
  • Commuter Benefits
  • Unlimited PTO
  • Catered lunch five days a week
  • Premium snacks and coffee
  • In-building gym
  • Dog-friendly environment
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service