GRC Analyst

Remote $134k–$202k middle 1 month ago full-time quality 8.2/10

Role in brief

Vercel, a company building infrastructure for web development and AI agents, seeks a GRC Analyst. This role involves managing compliance with security frameworks, streamlining audits, and collaborating to ensure accountability. It's suited for someone with at least three years of experience in cloud-centric audit support and strong project management skills.

GRCISO 27001SOC 2HIPAAPCI DSScloud infrastructureproject management

About the role

This role focuses on maintaining Vercel's compliance with various security frameworks. The GRC Analyst will work with internal teams to manage controls, drive remediation efforts, and ensure clear documentation of progress. This includes building relationships across the business to foster shared accountability for compliance.

A key part of the position involves streamlining annual audits. This means managing deliverables, developing treatment plans, and coordinating with different teams to track completion. The analyst will also monitor and improve existing controls and processes, looking for ways to automate and enhance GRC operations.

Success in this role means supporting go-to-market teams by handling security questionnaires and compliance inquiries, and maintaining customer-facing documentation. The analyst will also design and manage internal training programs to ensure all stakeholders understand compliance, ethics, and regulatory requirements.

The base salary for this role ranges from $134,000 to $202,000, with actual compensation adjusted based on skills, experience, and location.

Skills that matter here

  • GRC: This role involves managing governance, risk, and compliance activities, including maintaining internal controls and driving remediation efforts.
  • ISO 27001: The analyst will support the audit lifecycle for various standards, including ISO 27001, in a cloud environment.
  • SOC 2: Experience with SOC 2 audits is required, as the role supports the audit lifecycle in a cloud-centric setting.
  • HIPAA: The role requires familiarity with HIPAA compliance, supporting the audit lifecycle for this standard.
  • PCI DSS: Experience with PCI DSS is necessary, as the analyst will be involved in supporting the audit lifecycle for various compliance standards.
  • project management: Strong project management skills are essential for executing projects across different business units and levels, and for managing audit deliverables.

Who this role suits

  • Someone with a proactive and flexible approach, comfortable in a high-growth, startup environment.
  • An individual who excels at building strong working relationships and fostering shared accountability across teams.
  • A person with strong organizational skills who can manage multiple audit deliverables and track their completion effectively.
  • Someone who can communicate effectively and collaborate across various business units and levels.

From the employer

What you will do:

  • Collaborate with internal teams to maintain an effective suite of internal controls and driving remediation efforts to completion with clear documentation of progress.
  • Build strong working relationships across the business so compliance accountability is shared and stakeholders are informed.
  • Streamline annual audits by managing audit deliverables, developing treatment plans, and coordinating across teams to document and track completion to ensure audit success.
  • Monitor and improve controls, processes, and evidence management practices, identify opportunities to automate and streamline GRC operations, and contribute to controls maturity scoring and reporting.
  • Enable go-to-market teams and accelerate deal cycles by supporting security questionnaires, addressing compliance inquiries, and maintaining clear, customer-facing documentation on Vercel’s security and compliance posture.
  • Design and manage company training and enhance visibility on compliance-specific topics for internal stakeholders to ensure an understanding of compliance, ethics, and regulatory requirements within the organization.

About you:

  • At least 3 years of relevant experience in supporting the audit lifecycle in a cloud-centric environment (SOC 2, ISO 27001, PCI, HIPAA, etc.), with strong organizational skills to be flexible and proactive in a high-growth, start-up environment.
  • Experience collaborating closely with internal partners to seamlessly incorporate policies and technical controls into the SDLC.
  • Strong project management skills and sense of ownership with the ability to communicate and collaborate effectively, and execute projects across various business units and levels.

Bonus if you have:

  • Strong experience with cloud infrastructure (e.g., Azure, AWS).
  • Familiarity with compliance or software development tools and systems (e.g., Drata, Linear, Datadog, etc.).
  • Experience with frontend development and open source components.
  • Relevant industry certifications (i.e., CISM, CISSP, CCEP) is a plus, but not required.

Benefits:

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
  • The San Francisco, CA base pay range for this role is $134,000-$202,000. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role.

Questions about this role

What is the remote work policy for this role?

This is a fully remote position.

What level of seniority is expected for this position?

This is a middle-seniority role, requiring at least three years of relevant experience.

What are the core skills required for this GRC Analyst role?

Key skills include GRC, ISO 27001, SOC 2, HIPAA, PCI DSS, cloud infrastructure, and project management.

Similar jobs

Before you apply

  • Legitimate employers never ask you to pay anything to apply or get hired.
  • Never share seed phrases or private keys. No real job needs them.
  • Do not install software ("test tasks", "trading tools", "video call clients") sent during hiring.
  • Check that the application page's domain really belongs to Vercel.