GRC Analyst

Posted 2hrs ago

Employment Information

Industry
Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

GRC Analyst testing controls, managing audits, and assessing risk for YipitData’s alternative-data analytics business. Supporting SOC 2, vendor reviews, customer questionnaires, and AI governance.

Responsibilities:

  • Own GRC workstreams from initial request through evidence collection, testing, remediation, and completion
  • Help keep YipitData audit-ready throughout the year
  • Test security controls and validate that evidence proves controls are operating
  • Conduct risk assessments and help develop remediation plans
  • Map controls across SOC 2 and other frameworks
  • Coordinate access reviews, control testing, policy reviews, risk updates, and audit evidence requests
  • Review vendors' security practices
  • Support customer security questionnaires
  • Translate compliance requirements into clear actions
  • Draft and maintain policies, standards, control narratives, risk records, metrics, and program documentation
  • Track findings and remediation commitments
  • Simplify and automate repetitive GRC work
  • Help develop governance for AI products, agents, and new data-handling methods
  • Partner with Security, IT, Engineering, Legal, Finance, and People teams

Requirements:

  • Experience in security, compliance, risk, audit, privacy, vendor risk, or another related field
  • Hands-on SOC 2 experience, including supporting Type I or Type II audits, testing controls, validating evidence, coordinating with auditors, and tracking remediation through completion
  • Familiarity with SOC 2, NIST CSF, or similar security and compliance frameworks
  • Strong writing skills to make complicated requirements clear
  • Ability to identify inconsistencies, missing information, and unsupported answers
  • Comfort asking follow-up questions and respectfully pushing back
  • Ability to organize multiple workstreams, meet deadlines, and follow through
  • Ability to communicate with technical and non-technical teams
  • Ability to work independently and know when to escalate
  • Interest in governance for AI and emerging technologies
  • Flexible availability, with most employees working East Coast hours

Benefits:

  • Flexible work hours
  • Flexible vacation
  • Generous 401K match
  • Parental leave
  • Team events
  • Wellness budget
  • Learning reimbursement
  • Equity
  • Remote work opportunity