Contract Sr. Security GRC Analyst (Governance, Risk & Compliance)

location_onSan Francisco, California, United Statesscheduleyesterday
sync_altWork style:Hybrid
trending_upExperience level:Senior
badgeEmployment:Contract
historyMinimum experience:4+ years
Apply Nowopen_in_new

Job description

Contract Sr. Security GRC Analyst (Governance, Risk & Compliance)

We're a cloud-native, agentic AI SaaS company building workforce-intelligence products on Azure. Trust is core to our product, and we're looking for a Senior GRC Analyst to own our compliance programs and mature our security management system as we scale.

You'll be the engine behind our ISO 27001, SOC 2, and ISO 42001 efforts — running evidence collection, control mapping, risk assessments, and auditor engagements, and turning a young program into a repeatable, audit-ready operation. This is real ownership with executive visibility, ideal for someone who wants to shape a program rather than inherit a finished one.

What you'll do

  • Own and operate the ISMS — policies, control catalog, risk and vendor registers, Statement of Applicability.
  • Drive ISO 27001:2022 and SOC 2 Type II end to end: readiness, evidence, control testing, remediation.
  • Stand up our ISO 42001 (AI management system) program alongside existing frameworks.
  • Manage external auditor engagements, evidence requests, and audit logistics (Stage 1/2, Type II).
  • Administer our GRC platform (e.g., Vanta) — control mappings, automated evidence, control health.
  • Run risk assessments and vendor risk reviews; support pentest, vulnerability disclosure, and bug bounty programs.
  • Partner with Engineering to translate requirements into real controls across our Azure environment.
  • Handle customer trust work: security questionnaires, RFPs, and the trust center.

What we're looking for

  • 4+ years in GRC, security compliance, or IT audit, including at least one full certification cycle.
  • Hands-on ISO 27001 and SOC 2 experience — evidence, auditors, remediation.
  • Familiarity with cloud controls (Azure preferred) and a GRC platform (Vanta, Drata, OneTrust, etc.).
  • Strong risk assessment, control design, and written-communication skills.

Nice to have

  • ISO 42001 / AI governance (NIST AI RMF), AI security frameworks (OWASP LLM Top 10, MITRE ATLAS).
  • GDPR / privacy experience, especially with employee data.
  • Certifications: ISO 27001 LI/LA, CISA, CRISC, CISSP, or CCSK.
  • Early-stage or high-growth SaaS background.

Skills mentioned


San Francisco, California, United States

Apply for this job

Use the application link supplied with this listing to apply to r.Potential. Check the destination before entering personal information.

Apply Nowopen_in_new