Job Closed
This listing is no longer active.
Payscale powers compensation decisions for more than 25% of the US workforce
GRC Analyst II
Location
United States
Posted
4 days ago
Salary
$80.8K - $121.2K / year
Seniority
Mid Level
Job Description
GRC Analyst II
Payscale
• Maintain Payscale's data classification program, including classification schema, tagging standards, and coordination with data owners to ensure accurate and consistent classification across systems and assets • Maintain the system classification and ownership inventory, partnering with teams to ensure systems are properly classified, attributed, and reviewed on a defined cadence • Support audit coordination activities for SOC 2 and other compliance frameworks. • Conduct vendor security assessments reviews. • Manage the policy management lifecycle, including drafting new policies and standards, tracking review cycles, coordinating approvals, and maintaining version control. • Identify control gaps or process improvement opportunities and partner with business units to implement and sustain effective controls.
Job Requirements
- Bachelor's degree in cybersecurity, information systems, or a related field
- 2-4 years of work experience in GRC, information security, or a related field within a commercial SaaS or software company
- Working knowledge of information security control frameworks such as SOC 2, ISO 27001, NIST 800-53, or CIS
- Demonstrated experience with data classification frameworks and data governance concepts
- Experience conducting vendor security assessments and managing third-party risk workflows
- Hands-on experience with audit support activities, including evidence collection for SOC 2 or similar frameworks
- Solid understanding of information security policies, standards, and procedures
- Hands-on experience with GRC tools or platforms (e.g., Drata, ServiceNow GRC, or similar)
- Strong written and verbal communication skills with the ability to engage both technical and non-technical stakeholders
- Ability to manage multiple workstreams independently, prioritize effectively, and meet deadlines.
Benefits
- Flexible paid time off, giving you the opportunity to rest, relax and recharge away from work
- 14 Paid Company Holidays, includes 2 floating holidays (you choose!)
- A comprehensive benefits plan including medical, dental, life, vision, disability, and life insurance covered up to 100% by Payscale
- Unlimited infertility coverage benefits through our medical plans
- Additional supplemental health benefits offered to you and your family
- 401(k) retirement program with a fully vested immediate company match
- 16 weeks of paid parental leave for birthing and non-birthing parents
- Health Savings Account (HSA) options and company contributions each pay period
- Flexible Spending Account (FSA) options for pre-tax employee allocations
- Annual remote work stipend to be used on wellness or home office equipment
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
• Develop submission strategies and plans for post-approval CMC activities such as variations, renewals, market expansions, and annual reports. • Assess change controls and provide regulatory assessments of quality changes in production and quality control. • Review study reports from the quality control and production departments to ensure compliance with regulatory requirements. • Coordinate submission preparation with various departments including manufacturing, supply chain, quality control and quality assurance, and other regulatory departments and local companies. • Write and/or review submission content to ensure alignment with regulatory requirements, specifically related to variations and questions from health authorities. • Manage projects within all Regulatory Information Management systems, ensuring the maintenance of worldwide submissions. • Identify, escalate, and mitigate risks associated with regulatory procedures and activities.
Senior Manager, Governance Risk & Compliance
Sound PhysiciansWe deliver uncompromising care and lasting partnerships across acute and post-acute settings.
• Lead the execution of the enterprise information security GRC program and report directly to the CISO. • Translate the CISO’s cybersecurity strategy and risk tolerance into scalable and defined processes, measurable outcomes, and defensible compliance posture. • Own the security risk lifecycle, including assessments, tracking, remediation, and escalation of material risks to the CISO. • Maintain the security policy framework and translate standards (e.g., NIST CSF, ISO 27001, SOC 2) into actionable control requirements. • Manage security related compliance activities and audits; maintain evidence and track remediation to closure. • Operate the vendor security risk management program and escalate high risk vendors and systemic issues. • Produce concise risk and compliance metrics and dashboards for the CISO and senior leadership. • Mentor GRC staff and act as a trusted advisor to Security, IT, Legal, Privacy, and business teams. • Partner with the CISO and Sr. Manager of Security Operations to update the Strategic Information Security Program.
Analyst, Compliance – Investigations
GeminiGemini is a next generation cryptocurrency platform that allows customers to buy, sell, store and earn crypto.
• Conduct investigations of customer activity to determine whether such activity warrants reporting in accordance with relevant AML regulation and guidance. • Draft and prepare Suspicious Activity Reports (SARs). • Perform blockchain analysis utilizing blockchain analytics to review customer activity, including direct and indirect exposure. • Analyze customer data including, but not limited to, IP addresses, device information and signals, open source intelligence (OSINT), transaction histories, customer identification and source of wealth documentation. • Conduct customer outreach to gather additional information regarding customer activity. • Balance numerous projects, queues and priorities in a fast-paced environment.
Senior Associate, Compliance Technology – Compliance Automation
CoinbaseWe're building an open financial system for the world.
• Build and maintain curated datasets and data models (e.g., case, alert, entity, transaction, and risk features) that power compliance controls across Transaction Monitoring, EDD/KYC, and Screening systems. • Own data quality for compliance datasets by implementing validation checks, monitoring, lineage tracking, and documentation to ensure outputs are accurate, complete, and audit-ready. • Partner with cross-functional engineering teams and Compliance stakeholders to close upstream data gaps, standardize instrumentation, and translate control requirements into scalable data structures and feature sets. • Drive detection signal quality improvements by analyzing detection outputs, identifying opportunities to reduce non-actionable noise while protecting sensitivity, and defining success metrics for controlled rollouts. • Execute measurement frameworks for compliance control effectiveness, including coverage, timeliness, stability, and outcome-based metrics, and build repeatable reporting pipelines consumable by Compliance leaders, operations teams, and auditors.




