Nametag logo
Nametag

Deepfake Defense™ identity verification and account protection solutions.

Senior GRC Analyst

Security AnalystSecurity AnalystOtherRemoteSeniorTeam 11-50Since 2020H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

71 days ago

Salary

$120K - $160K / year

Seniority

Senior

No structured requirement data.

Job Description

Senior GRC Analyst

Nametag

Nametag is building the future of secure digital identity. Our mission is to make it easy for people and organizations to prove who they are online - safely and seamlessly. We’re pioneering next-generation identity verification and account protection so that users can control their own identity, and companies can build trust without friction. About the Role Nametag is seeking an experienced Senior GRC Analyst to own and evolve our security and compliance program. This role is ideal for someone who thrives in a fast-paced startup environment, has deep experience with SOC 2 and other compliance frameworks, and is comfortable building and running programs with limited resources. You will report directly to the Head of Engineering and partner closely with the engineering team to ensure security is built into everything we do. As a Senior GRC Analyst, you will own the entire security and compliance function as an individual contributor, maintaining our existing certifications, driving new compliance initiatives, coordinating penetration tests, and building trust with customers and prospects. You will work closely with engineering, product, sales, and customer success to ensure security enables the business rather than blocking it. What You'll Do Compliance Program Management - Own and maintain SOC 2 Type II certification, including evidence collection, control monitoring, and audit coordination - Drive IAL3 compliance readiness and implementation - Manage accessibility compliance (WCAG) requirements - Identify and pursue additional certifications as needed based on customer and market requirements Security Operations - Coordinate penetration testing cycles and drive remediation with engineering - Maintain a living view of organizational risk and surface it to leadership - Develop and maintain security policies, procedures, and controls - Respond to security incidents with speed and clarity Customer Trust - Respond to customer security questionnaires promptly and accurately - Support sales in security-sensitive enterprise deals - Maintain public-facing trust documentation - Participate in customer security calls and reviews as needed Cross-Functional Partnership - Partner with engineering to build security into the development process - Provide clear security guidance and timely reviews so teams can ship with confidence - Collaborate with product on security and accessibility features - Work with customer success to address customer security concerns Ideal Qualifications We know that no candidate will perfectly match every requirement, and that's okay. If you're passionate about what we're building and have most of the skills below, we'd love to hear from you. - 5+ years of experience in security, compliance, or GRC, with demonstrated hands-on ownership of SOC 2 Type II programs - Experience building or running compliance programs in startup or resource-constrained environments - Strong understanding of how auditors think, ideally from auditor-side experience or running multiple audit cycles - Technical fluency to read pen test reports, understand cloud architecture, and have informed conversations with engineers - Knowledge of GRC tooling and vendors, with opinions on what's worth investing in at different company stages - Excellent communication skills, able to translate security topics for executives, salespeople, and customers - Experience with identity verification, authentication, or security-focused products is a strong plus - Familiarity with IAL2/IAL3 or NIST 800-63 identity proofing standards is a strong plus - CISSP, ISO 27001 Lead Auditor, or similar certifications are a plus but not required What We Value - Intellectual horsepower: quickly grasping complex technical and business concepts - Kindness and integrity: earning trust is central to how we build relationships with customers and colleagues - Bias for action: we move quickly to deliver impact and protect our customers against fast-moving threats Compensation The base salary range for this full-time position is $120,000-$160,000, plus equity and benefits. Nametag is a founding member of the Open Imperative, publicly committed to pay equity in the technology industry. We post positions with ranges to encourage people of different backgrounds and experiences to apply. Every offer is benchmarked against market data to ensure fairness and consistency. Final compensation is determined by role, level, and additional factors such as skills, experience, and education. Your recruiter or hiring manager can share more details during the hiring process. Culture & Perks At Nametag, we believe trust starts with how we treat each other. We are a remote-first team that values autonomy, inclusivity, and collaboration, with regular in-person time to stay connected and innovate together. - Remote-first: Work from anywhere in the US. Our team spans Seattle, San Francisco, Ann Arbor, Denver, New York City, and beyond - Quarterly off-sites: We bring the team together once per quarter for in-person collaboration, often off-site in new places - Flexible schedules: Work in your own time zone; we align key meetings across a shared window We Offer - Competitive salary - Meaningful equity ownership - Comprehensive health benefits (medical, dental, vision) - Flexible paid time off - Quarterly team off-sites and travel support - New computer hardware and equipment - An inclusive environment where your voice has impact and your work drives change

Job Requirements

  • 5+ years of experience in security, compliance, or GRC, with demonstrated hands-on ownership of SOC 2 Type II programs
  • Experience building or running compliance programs in startup or resource-constrained environments
  • Strong understanding of how auditors think, ideally from auditor-side experience or running multiple audit cycles
  • Technical fluency to read pen test reports, understand cloud architecture, and have informed conversations with engineers
  • Knowledge of GRC tooling and vendors, with opinions on what's worth investing in at different company stages
  • Excellent communication skills, able to translate security topics for executives, salespeople, and customers
  • Experience with identity verification, authentication, or security-focused products is a strong plus
  • Familiarity with IAL2/IAL3 or NIST 800-63 identity proofing standards is a strong plus
  • CISSP, ISO 27001 Lead Auditor, or similar certifications are a plus but not required

Benefits

  • Competitive salary
  • Meaningful equity ownership
  • Comprehensive health benefits (medical, dental, vision)
  • Flexible paid time off
  • Quarterly team off-sites and travel support
  • New computer hardware and equipment
  • An inclusive environment where your voice has impact and your work drives change
  • Compensation
  • The base salary range for this full-time position is $120,000-$160,000, plus equity and benefits. Nametag is a founding member of the Open Imperative, publicly committed to pay equity in the technology industry. We post positions with ranges to encourage people of different backgrounds and experiences to apply. Every offer is benchmarked against market data to ensure fairness and consistency. Final compensation is determined by role, level, and additional factors such as skills, experience, and education. Your recruiter or hiring manager can share more details during the hiring process.
  • Culture & Perks
  • Remote-first: Work from anywhere in the US. Our team spans Seattle, San Francisco, Ann Arbor, Denver, New York City, and beyond
  • Quarterly off-sites: We bring the team together once per quarter for in-person collaboration, often off-site in new places
  • Flexible schedules: Work in your own time zone; we align key meetings across a shared window

Related Job Pages

More Security Analyst Jobs

Crisis24 logo

Senior Case Manager, Threat Assessment and Management

Crisis24

Crisis24 is a global, AI-enhanced provider of travel risk management, mass communications, critical event management, crisis-security consulting, personal protection solutions and global medical concierge capabilities. We operate at the intersection of precision, discretion, and elite readiness. Delivering world-class security solutions to high-profile clients, executives, and organizations across the globe. Our Threat Assessment and Management Division provides consultation and training. We deliver our services with discretion and care, allowing our clients to make informed decisions with confidence.

Security Analyst72 days ago
OtherRemoteTeam 1,001-5,000

About Crisis24 Crisis24 is a global, AI-enhanced provider of travel risk management, mass communications, critical event management, crisis-security consulting, personal protection solutions and global medical concierge capabilities, allowing prominent organizations, disruptive brands and influential people to operate with confidence in an uncertain world. At Crisis24, we go beyond mere employment; we pave the way to a realm where your skills become instrumental in shaping global security, guiding clients through a multifaceted and challenging landscape. Your journey with us will be deeply fulfilling, driven by a powerful sense of purpose and accomplishment. Within our thriving environment, you'll discover abundant chances for both personal and career advancement. Seize this moment to push your limits, broaden your expertise, and elevate your professional journey to unprecedented levels. Join the Crisis24 team today and be a part of something extraordinary where growth and impact converge. More information is available at www.crisis24.garda.com Crisis24 – Private Strategic Group (PSG) is the gold standard in global protective and consultative services. We operate at the intersection of precision, discretion, and elite readiness, delivering world-class security solutions to high-profile clients, executives, and organizations across the globe. Our Threat Assessment and Management Division provide consultation and training. We deliver our services with discretion and care, allowing our clients to make informed decisions with confidence and setting the standard for excellence in the Threat Assessment and Management field. We also provide our security agents with timely, informative reports to mitigate potential risks and support our overall protective mission. THIS IS A REMOTE ROLE Who We’re Looking For You are passionate about being part of the protective mission of keeping our clients safe and are experienced in managing threat assessment cases, including executive/public figure pursuit, workplace violence, and/or domestic violence. You have integrity and operate with unwavering discretion on confidential issues. You thrive in both working independently and working as a team member with other Analysts and Case Managers on joint projects. You are curious, with excellent writing and communication skills. You’re comfortable with every day bringing different challenges, and you are comfortable working on urgent projects in a fast-paced environment. You are detailed oriented and driven to get the best product to our clients in a timely manner. You excel at delivering written and verbal reports to our clients and have experiencing conducting trainings, including at an advanced level. You also enjoy training and mentoring other staff and to be a senior threat assessment representative to the company. What You Will Do - Act as one of the firm’s senior leaders in threat assessment with the ability to act independently with minimal oversight. - Assess, manage, and prepare reports regarding inappropriate communications and threats directed to public figures and C-suite executives and provide findings to executive protection teams and clients directly. - Assess, manage, and prepare reports regarding workplace violence and domestic violence cases, including conducting sensitive interviews. - Consult with corporate threat assessment teams on high-risk cases. - Manage complex and high-risk cases, including pursuing criminal charges, civil interventions, etc. when deemed appropriate. - Analyze investigative and OSINT findings in the development of management plans. - Build out and oversee threat assessment programs for individual and corporate clients. - Consult directly with clients on cases, both in writing and verbally. - Manage case managers and OSINT analysts, including reviewing and approving client reports. - Conduct threat assessment trainings for clients, including at the advanced level, for corporations and other organizations. - This role requires after-hours on call-call availability, including nights, weekends, and holidays as needed. - This is a fully remote position in the U.S. which may require up to 10 percent travel. What You Will Bring - 10+ years of experience in the threat assessment field. - Bachelor’s degree required and in a related field such as Psychology or Criminal Justice, preferred. - Member of the Association of Threat Assessment Professionals (ATAP) required. - ATAP Certified Threat Manager (CTM) or the ability to sit for the exam a plus. - Previous experience working with law enforcement on the resolution of criminal cases required. - Excellent writing, communication, and public speaking skills with the ability to work directly with high profile clients required. - Ability to multi-task with little supervision in a fast-paced environment required. - Previous experience managing teams preferred. - Previous experience conducting trainings or public speaking preferred. - Previous experience in assessing and managing cases involving executives, public figures, and/or politicians while working with protection teams a plus. - Previous experience working with or on a corporate threat assessment team a plus. Information Security Protect the data and systems of Crisis24 and its stakeholders by adhering to policies, reporting incidents and potential problems, completing regular training, and identifying opportunities for improvement. Crisis24, A GardaWorld Company is dedicated to equal opportunity in employment. We are committed to a work environment that celebrates diversity. We do not discriminate against any individual based on race, color, sex, national origin, age, religion, marital or parental status, sexual orientation, gender identity, gender expression, military or veteran status, disability, or any factors protected by applicable laws.

United States
Job Closed
Ensono logo

Security Compliance Analyst-Intern

Ensono

Ensono delivers complete Hybrid IT solutions, from mainframe to cloud, tailored to each client’s journey.

Security Analyst72 days ago
OtherRemoteTeam 1,001-5,000H1B Sponsor

At Ensono, our Purpose is to be a relentless ally, disrupting the status quo and unleashing our clients to Do Great Things! We enable our clients to achieve key business outcomes that reshape how our world runs. As an expert technology adviser and managed service provider with cross-platform certifications, Ensono empowers our clients to keep up with continuous change and embrace innovation. We can Do Great Things because we have great Associates. The Ensono Core Values unify our diverse talents and are woven into how we do business. These five traits are the key to achieving our purpose: Honesty, Reliability, Curiosity, Collaboration, and Passion. Our summer internship is the entry point into our 12-month rotational program. The program aims to create a pathway to full time employment and develop well rounded junior associates with great potential. Each summer we choose two interns to join Ensono full-time and gain experience in different departments over 3-month rotations. Because of this, our ideal intern candidate would graduate in Winter or Spring 2026 and be interested in full-time opportunities after the internship ends. We are looking for potential participants for our 2026 Summer Internship Program and are excited to invite driven and self-motivated candidates to apply! Ensono is dedicated to cultivating talented individuals with unique skillsets who know how to dream big and build bigger! Internship Dates: May 18th to August 7th, 2026 About the role and what you'll be doing: As a Security Compliance Analyst Intern, you will support Ensono’s internal audit and security control framework initiatives. Your work will help us enhance our audit processes, integrate AI solutions, and maintain a strong security compliance posture. Key responsibilities include: Document the Audit Process for All Ensono Audits · Learn and document Ensono’s current audit processes, including specific test procedures and process enhancements. Identify AI Opportunities for Internal Audit · Analyze audit test procedures and collaborate with Ensono’s AI team to identify automation opportunities using AI tools and technologies. · Develop and implement AI-driven solutions to improve audit efficiency and accuracy. ESCF Review and Update with Test Procedures · Review Ensono Security Control Framework (ESCF) to ensure controls reflect the latest AI-enabled test procedures. · Update documentation to incorporate newly developed testing methods and expected outcomes. We want all new Associates to succeed in their roles at Ensono. That's why we've outlined the job requirements below. To be considered for this role, it's important that you meet all Required Qualifications. If you do not meet all of the Preferred Qualifications, we still encourage you to apply. What You Will Need: - Overall understanding of the information security domain, especially in the infrastructure managed services industry. - Familiarity with artificial intelligence principles, tools, and technologies. - Skills in prompt engineering, workflow automation using AI, and Agentic AI concepts. Bonus Qualifications - Knowledge of information security auditing processes. - Understanding of mainframe technologies. - AI for automation. Creating agents for performing audits for example. In addition exposure to open ai. Why Ensono? Ensono is a place to make better happen – for our clients and for your career. You can do great things through innovation or collaboration, by learning or volunteering, or to promote diversity and inclusion. You can do great things for your own health or for a healthier planet. Whatever it means to you to do great things we want Ensono to be the place you can do it. Ensono is an Equal Opportunity/Affirmative Action employer. We are committed to providing equal employment to our Associates and building a diverse and inclusive workforce. All qualified applicants will be considered without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, or other legally protected basis, in accordance with applicable law. As of the date of this posting, a good faith estimate of the current pay scale for this role is $20.00/hr based on a full-time schedule. Please note that placement in the range may vary based on numerous factors including but not limited to skills, experience, internal equity, and business needs. Pay transparency nondiscrimination statement/posting OFCCP’s pay transparency policy can be found on OFCCP’s website. If you need accommodation at any point during the application or interview process, please let your recruiter know or email USTalentAcquisition@ensono.com.

United States
Job Closed
CEA logo

Senior Information Security Analyst – Governance

CEA

CEA is the exclusive distributor of JCB, Atlas Copco, Ditch Witch, & Dynapac equipment.

Security Analyst72 days ago
Full TimeRemoteTeam 201-500Since 1981H1B Sponsor

• Development and implementation of Information Security policies, standards and procedures • Creation and updating of policies and procedures related to information security • Analysis of the organization’s security needs and industry best practices • Reference and alignment with relevant frameworks and standards, such as ISO/IEC 27001 and NIST • Collaboration with other teams to ensure policies are practical and applicable • Ensure the organization has clear and effective guidelines to protect information and systems, and to ensure compliance with regulations and standards • Assessment and management of information security risks and vulnerabilities • Development of mitigation and contingency plans • Protect the company against threats and ensure appropriate measures are in place to minimize risks and impacts • Identification and assessment of vendors that have access to the organization’s critical data or systems • Use of questionnaires and checklists to evaluate vendors’ information security • Management and response to information security incidents • Implementation and monitoring of incident response processes • Ensure controls and practices comply with applicable regulations and standards

Brazil
ICF logo

Cyber Security Analyst- Remote

ICF

Founded in 1969, ICF is a global advisory and technology services company headquartered in Reston, Virginia. It delivers data-driven solutions across energy, environment, infrastru

Security Analyst72 days ago

ICF is seeking a Cyber Security Analyst that is involved in the testing, implementation and operation of secure state-of-the-art internet-facing services, systems, networks, and database products in both hosted and cloud environments. Conducts risk assessments and provides recommendations for system and application design. Participates in a wide range of security activities including event correlation, alerting, vulnerability management, access management, incident response, troubleshooting, infrastructure management, audit support and more. Analyses are performed through all stages of the system lifecycle, including: concept, design, build, test, integration, operation, maintenance and disposal. Provides analysis, evaluations, and recommendations to improve system consistency, efficiency, and effectiveness. Helps ensure solution requirements meet timing, technical, and financial constraints. Integrates new features into existing solutions, provides analysis to evaluate existing systems against future needs and trends. Uses advanced forensic tools and techniques for investigation and attack reconstruction. Provides recommendations for enhancements to systems, testing and processes. Interacts with other internal groups and external entities including customers, law enforcement, and intelligence/government agencies. Performance Objectives: Technical Work - Operation of infrastructure and application vulnerability detection systems - Review and validation of vulnerability findings - Analyze log data for emerging or unusual patterns - Modify, create, or propose alerts for events of interest - Work with stakeholders to resolve vulnerabilities and respond to events - Help monitor common channels for priority communications - Ensure systems meet documented standards - Assist with obtaining or creating artifacts for audit and compliance - Request and incident ticket intake and escalation - Learn and document common processes with senior resources - Participate in on-call rotation - Assist with disaster recovery and incident response testing and processes - Research and test emerging threats Basic Qualifications: - 3+ years general technology experience - 1+ year of general security experience - 1+ year of experience with basic information security practices (ie Least Privilege, Zero Trust, OWASP Top 10, control frameworks) - Ability to travel 1-2 times a year Preferred Qualifications: - Azure and/or AWS cloud familiarity and experience is highly desirable - Scripting and automation experience is a plus - CompTIA Security+, CEH, GIAC, or equivalent certification - Experience using commercial and open source security software such as Nmap, Nessus, Wireshark, Rapid7, WebInspect, Metasploit Framework, Kali Linux, etc. - Experience with log monitoring, analysis, and correlation - Experience performing enterprise incident monitoring, response, and analysis - Familiarity with generative and agentic AI machine learning algorithms, data preprocessing, and model deployment - Ethical hacking experience - Strong desire for growth and development of security skills - Excellent verbal and written communication skills - Strong ability to multi-task, react, and think quickly - Ability to maintain a high level of confidentiality - Must be flexible enough to work overtime when needed Scope Learning to use professional concepts. Applies company policies and procedures to resolve routine problems. Develops competence by performing structured assignments. Complexity Works on problems of limited scope. Follows standard practices and procedures in analyzing situations or data from which answers can be readily obtained. Builds stable working relationships internally. Discretion Work is closely managed. Normally receives detailed instructions on all work. Interaction Regularly interacts with functional peers within the immediate organization. Interaction normally involves exchange or presentation of factual information. Fairly limited interaction with external contacts. Working at ICF ICF is a global advisory and technology services provider, but we’re not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future. We can only solve the world's toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer. Together, our employees are empowered to share their expertise and collaborate with others to achieve personal and professional goals. For more information, please read our EEO policy. We will consider for employment qualified applicants with arrest and conviction records. Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process. To request an accommodation, please email Candidateaccommodation@icf.com and we will be happy to assist. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.  Read more about workplace discrimination rights or our benefit offerings which are included in the Transparency in (Benefits) Coverage Act. Candidate AI Usage Policy At ICF, we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) tools to generate or assist with responses during interviews (whether in-person or virtual) is not permitted. This policy is in place to maintain the integrity and authenticity of the interview process.  However, we understand that some candidates may require accommodation that involves the use of AI. If such an accommodation is needed, candidates are instructed to contact us in advance at candidateaccommodation@icf.com. We are dedicated to providing the necessary support to ensure that all candidates have an equal opportunity to succeed.   Pay Range - There are multiple factors that are considered in determining final pay for a position, including, but not limited to, relevant work experience, skills, certifications and competencies that align to the specified role, geographic location, education and certifications as well as contract provisions regarding labor categories that are specific to the position. The pay range for this position based on full-time employment is: $81,499.00 - $138,549.00 Nationwide Remote Office (US99)

United States
$81.5K - $138K / year
Job Closed