Doppler is the multi-cloud SecretOps Platform developers and security teams trust to provide secrets management at scale
Senior GRC Analyst
Location
United States
Posted
10 days ago
Salary
$150K - $185K / year
Seniority
Senior
Job Description
Senior GRC Analyst
Doppler
• Maintain Doppler's SOC 2 Type II and ISO 27001 certifications end-to-end: evidence collection, control monitoring, audit coordination, and deficiency remediation • Lead the compliance work for our next certifications, including gap assessments, policy updates, and required documentation • Evaluate additional certifications and attestations on an ongoing basis as customer and market requirements evolve • Own day-to-day administration of our GRC platform (Vanta), including control mapping, evidence workflows, and audit readiness • Lead our security working group: facilitate regular risk identification sessions, policy updates, maintain the threat register, track remediation progress, and drive accountability across teams • Design and maintain security controls mapped to our chosen frameworks (SOC 2, ISO 27001, etc.), ensuring they're practical and consistently operating • Coordinate penetration testing cycles and work directly with engineering to track and close findings • Author and maintain security policies that are enforceable and grounded in regulatory requirements (GDPR, PCI, and others relevant to a secrets management provider) • Support business continuity and disaster recovery governance • Respond to security questionnaires and RFPs promptly and accurately • Participate in customer security reviews and calls; represent our compliance posture credibly to security teams, procurement, and compliance officers • Maintain public-facing trust documentation that reflects our actual program • Partner with sales on security-sensitive enterprise deals, especially in regulated industries or where compliance is a gating factor • Translate compliance status and risk posture into clear, non-jargon updates for leadership and cross-functional stakeholders • Lead security awareness and compliance training for internal teams • Influence engineering and product roadmaps where security controls intersect with product decisions
Job Requirements
- 5+ years in security, compliance, or GRC, with direct ownership of SOC 2 Type II and ISO 27001 programs in a cloud product environment where you've run audit cycles, not just supported them
- Hands-on experience with Vanta (or a comparable GRC platform) and a genuine interest in automating compliance workflows rather than relying on spreadsheets
- Technical fluency: you can read a pen test report, understand cloud architecture decisions, and have substantive conversations with engineers about control design and risk tradeoffs
- Strong understanding of how auditors think, ideally from having been on the auditor side, or from running enough cycles that you've internalized their perspective
- Familiarity with PCI DSS and GDPR requirements; experience with self-attestation or certification work is a strong plus
- Experience supporting enterprise sales cycles where security is a procurement requirement, including responding to complex security questionnaires
- Excellent communication skills across audiences. You can brief the CEO on risk posture and turn around and explain the same issue to an engineer in implementation terms
- Relevant certifications (CISA, CISSP, CISM, CRISC, or equivalent) preferred.
Benefits
- Equity at an early-stage, fast-growing startup
- Premium health insurance (medical, dental, vision)
- Guilt Free Unlimited PTO - 3-week minimum strongly encouraged!
- Upward Mobility
- Learning and Development Stipend
- Wealth Advisor
- 401k
- Pregnancy & Family Leave
- Fertility & Adoption Benefits
- Equal Compensation (regardless of gender or race)
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
ITSOx Control, Audit & Compliance Manager
DanaherOne of the world's foremost science and technology companies, Danaher is a global corporation that was founded in 1969 and has been developing, producing, and advertising pioneerin
Role Description The IT SOx Control, Audit and Compliance Manager is accountable for the execution and ongoing effectiveness of IT SOx controls for in-scope systems across Abcam, operating within the Digital organisation and aligned to the Danaher SOx framework. This position reports to the Senior Manager, SOx & GRC within Cybersecurity and the global Abcam Digital function. The role is based in Cambridge, following Abcam’s agile working model, with travel to other Abcam locations as required to support audit activities. In this role, you will have the opportunity to: - Lead the delivery of Abcam’s IT SOx programme, ensuring alignment with Danaher SOx policies, standards, and timelines whilst providing regular reporting, metrics, and status updates on IT SOx compliance to senior stakeholders. - Ensure IT controls are appropriately designed, implemented, operated, and monitored across in-scope systems. - Partner with system owners and key stakeholders to coordinate control execution and evidence collection, driving standard work, process optimisation, and continuous improvement across IT SOx activities. - Maintain effective relationships with Danaher SOx communities and Internal Audit to ensure consistency and leverage best practice whilst supporting internal and external audits, including issue identification, remediation tracking, and closure. Qualifications - Bachelor's or Master’s degree in IT, Security Management or equivalent professional experience. - Strong knowledge of IT regulatory requirements, especially Sarbanes-Oxley (SOx). - Extensive experience of IT technical security controls & processes. - Proven track record of participating in IT compliance audits (CISA desirable not mandatory). - Process-orientated with an emphasis on standard work and repeatability. - Compliance mindset with an eye for detail within the hands-on execution of the IT SOx program. - Excellent documentation and record-keeping skills. - Proactive plan-ahead mindset constantly evolving the current position to improve levels of compliance tracking KPI’s and progress updates. - Ability to identify quick-wins and reuse solutions leveraging knowledge from the wider Danaher IT SOx community. Requirements - Experience with Oracle Fusion and Risk Management Cloud (RMC) would be a plus. - CISA certification or equivalent audit qualification would be a plus. Benefits - Comprehensive, competitive benefit programs that add value to our lives. - Flexible, remote working arrangements for eligible roles. - Enriching careers, no matter the work arrangement.
• Provide practical and business-focused contract and compliance guidance to internal stakeholders while protecting the company and supporting growth • Support internal audits, compliance reviews, reporting obligations, and documentation requests across both Federal and commercial operations • Partner with leadership, sales, finance, operations, and delivery teams to ensure contracts and compliance requirements support business growth and operational success • Create and maintain contract trackers, renewal calendars, compliance matrices, reporting schedules, and risk summaries to provide leadership visibility into contract and compliance status • Rebuild and organize the company’s contract and compliance repository, ensuring files, agreements, renewals, reporting documentation, and compliance records are accurate, organized, maintained, and accessible • Review, draft, redline, negotiate, organize, and manage Federal and commercial contracts and related documents including NDAs, teaming agreements, subcontractor agreements, vendor agreements, reseller agreements, customer agreements, purchase orders, task orders, amendments, SOWs, and managed services agreements
• Provide practical and business-focused contract and compliance guidance to internal stakeholders while protecting the company and supporting growth • Support internal audits, compliance reviews, reporting obligations, and documentation requests across both Federal and commercial operations • Partner with leadership, sales, finance, operations, and delivery teams to ensure contracts and compliance requirements support business growth and operational success • Create and maintain contract trackers, renewal calendars, compliance matrices, reporting schedules, and risk summaries to provide leadership visibility into contract and compliance status • Evaluate current processes, identify gaps or inefficiencies, and implement scalable solutions that improve accountability, organization, and execution • Support Federal contracting activities involving GWACs, IDIQs, GSA Schedules, NASA SEWP, NIH NITAAC, CIO-SP, BPAs, task orders, and other procurement vehicles while also supporting commercial customer and vendor agreements • Manage compliance tracking, reporting obligations, renewals, contract modifications, flow-down clauses, and customer commitments across both Federal and commercial business operations • Develop and improve scalable compliance processes, contract governance procedures, approval workflows, document control procedures, reporting schedules, and internal operating procedures • Rebuild and organize the company’s contract and compliance repository, ensuring files, agreements, renewals, reporting documentation, and compliance records are accurate, organized, maintained, and accessible • Review, draft, redline, negotiate, organize, and manage Federal and commercial contracts and related documents including NDAs, teaming agreements, subcontractor agreements, vendor agreements, reseller agreements, customer agreements, purchase orders, task orders, amendments, SOWs, and managed services agreements
• Deliver specific course content in an online environment • Provide instruction, support, and guidance for students with special needs • Manage the learning process focusing on students’ individual needs • Communicate with parents and related service staff • Develop compliant IEPs and progress reports • Facilitate special education meetings • Ensure success of students in the general education classroom • Document all contact with parents and interventions • Analyze student data and prescribe remediation


