About The Position

YipitData is seeking a GRC Analyst to help answer critical questions about the effectiveness of security controls, identify and manage risks, and ensure compliance as the company's products, technology, and AI usage evolve. This role involves a wide range of activities including audits, risk assessments, control testing, vendor reviews, customer questionnaires, policy management, and compliance programs. The GRC Analyst will collaborate with various departments such as Security, IT, Engineering, Legal, Finance, and People to understand business operations, pinpoint areas for improvement, and drive tasks to completion. The position emphasizes a deep understanding of evidence, thoughtful challenge of controls, and meticulous follow-up, rather than just administrative tasks. This is a remote-friendly opportunity within the US, with flexible work hours, though most employees align with East Coast hours. The role is designed for ambitious professionals who thrive in a dynamic environment and are eager to accelerate their growth and impact.

Requirements

  • Ability to operate in an environment that is constantly changing: where not every process is perfect or every answer is immediately available
  • Experience in security, compliance, risk, audit, privacy, vendor risk, or another field that taught you how to evaluate whether expectations are being met
  • Understanding that evidence is only useful if it actually proves the control
  • Ability to connect a policy or framework requirement to what people and systems are doing in the real world
  • Familiarity with SOC 2, NIST CSF, or similar security and compliance frameworks
  • Strong writing skills to make complicated requirements clear for those not familiar with security frameworks
  • Ability to notice inconsistencies, missing information, and answers that do not quite add up
  • Comfortable asking follow-up questions and respectfully pushing back when something needs a closer look
  • Ability to keep multiple workstreams organized, meet deadlines, and follow through
  • Good communication skills with both technical and non-technical teams and ability to explain why a requirement matters
  • Takes ownership, uses good judgment, and knows when to work independently versus when to escalate
  • Interest in figuring out how traditional governance needs to evolve for AI and other emerging technologies

Responsibilities

  • Take ownership of GRC workstreams and drive them from the initial request through evidence collection, testing, remediation, and completion
  • Help keep YipitData audit-ready throughout the year
  • Test security controls and determine whether they are actually working, rather than simply confirming that a document exists
  • Conduct risk assessments, identify meaningful gaps, and help teams develop remediation plans that are realistic and effective
  • Map controls across SOC 2 and other frameworks so one strong control can satisfy multiple requirements
  • Coordinate recurring work such as access reviews, control testing, policy reviews, risk updates, and audit evidence requests
  • Review vendors and help determine whether their security practices meet YipitData’s expectations
  • Support customer security questionnaires by finding the right information, validating it, and making sure our answers are accurate and consistent
  • Translate compliance requirements into clear actions for teams that do not live and breathe GRC
  • Draft and maintain policies, standards, control narratives, risk records, metrics, and other program documentation
  • Track findings and remediation commitments, follow up with owners, and keep issues from quietly sitting open forever
  • Look for ways to simplify and automate repetitive GRC work so the program can scale with the business
  • Help us think through governance for emerging technologies, including AI products, agents, and new ways of handling data

Benefits

  • Flexible work hours
  • Flexible vacation
  • Generous 401K match
  • Parental leave
  • Team events
  • Wellness budget
  • Learning reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service