Sr. GRC Analyst-Enterprise Cybersecurity

Rivian and Volkswagen Group TechnologiesPalo Alto, CA
$117,200 - $161,150Hybrid

About The Position

As GRC Analyst, you will own the operational delivery of our information security certifications and enterprise cybersecurity risk program. This is a hands-on individual-contributor role: you will run certification cycles end to end, keep our ISMS evidence audit-ready year-round, operate the enterprise risk register, and coordinate a large group of internal control owners and external partners. You will not set strategy from a distance — you will do the work that earns and keeps our certifications and keeps risk visible and tracked.

Requirements

  • 5 years of experience in governance, risk, and compliance (GRC), IT/information security compliance, IT audit, or a closely related function.
  • Bachelor's degree or equivalent practical experience.
  • Working knowledge of ISO/IEC 27001/27002, TISAX and the NIST Cybersecurity Framework, including risk assessment and treatment concepts and control mapping.
  • Hands-on experience supporting or coordinating audits and certifications: evidence collection, control validation, and corrective-action tracking.
  • Experience operating or maintaining a risk register and driving remediation items to closure with accountable owners.
  • Strong documentation, organization, and project-tracking skills, with the ability to manage multiple concurrent deadlines.
  • Excellent written and verbal communication; able to work with both technical and non-technical stakeholders across a complex, multi-entity organization.
  • Ability and willingness to travel domestically and internationally up to a few weeks per quarter.

Nice To Haves

  • Professional certification such as CISA, CRISC, ISO 27001 Lead Implementer or Lead Auditor, or CompTIA Security+.
  • Hands-on experience with GRC/compliance tooling such as ServiceNow GRC, OneTrust, Vanta, Drata, Archer, AuditBoard, or ZenGRC.
  • Automotive industry experience, especially TISAX/VDA ISA assessments, UNECE R155/R156, ISO/SAE 21434, or IATF 16949.
  • Experience coordinating external auditors, certification bodies, or consultancies and managing deliverables to SLAs.
  • Proficiency with Jira, Confluence, and Google Workspace.
  • Experience in a fast-paced, high-growth, or joint-venture/multi-entity environment.

Responsibilities

  • Own TISAX follow-on certifications: take over subsequent waves and sites after the initial TISAX AL3 assessments (VDA ISA 6.0.3), and manage evidence maintenance, internal self-assessments, corrective-action tracking, re-assessment readiness, and the ongoing ISMS evidence infrastructure.
  • Own ISO/IEC 27001 certification: drive achievement and ongoing maintenance of certification, coordinate internal audits, maintain the Statement of Applicability and control evidence, and manage annual surveillance and recertification activities.
  • Support ISO 9001 efforts as they relate to infrastructure and IT.
  • Support CSMS compliance under UNECE R155 and software update management under UNECE R156 as they apply to enterprise/IT infrastructure — supporting the cybersecurity management system requirements in an automotive JV/supplier environment.
  • Track and drive corrective and preventive actions (CAPA) to closure across all frameworks, holding owners to due dates.
  • Operate the enterprise cybersecurity risk register end to end: risk intake, assessment, treatment tracking, and reporting.
  • Execute risk management processes in coordination with Legal and in accordance with documented standard operating procedures, including confidentiality classification steps.
  • Produce clear, prioritized risk reporting for the Sr. Manager, Enterprise Cybersecurity and other stakeholders, with named owners and remediation timelines.
  • Work across a large stakeholder group spanning two parent companies and the JV — IT, Legal, Facilities, Internal Audit, HR, and engineering teams — and coordinate with 15–30+ named control owners for evidence collection.
  • Manage external partners: certification bodies (accredited ISO/TISAX auditors), external consultants, and vendors — tracking written deliverables, due dates, and response SLAs.
  • Maintain accurate, audit-ready documentation and program tracking in the team's tooling (e.g., Jira, Confluence, Google Workspace).

Benefits

  • competitive base salary
  • annual company performance bonus program
  • equity in the form of Restricted Stock Units (RSUs)
  • health coverage
  • retirement savings
  • time off
  • family planning programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service