GRC Analyst

COMPLYSHARE LLC
United States
25 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$115,000.0 - $145,000.0
Working hours
Regular working hours

Tech stack

Computing Platforms PCI Data Security Standards Enterprise Software Applications

Job description

Serve as a hands-on GRC advisor for customers: guide risk assessments, audits (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST), risk registers, policy and control rollouts; resolve complex GRC questions; create scalable guidance and partner with Support and Customer Success to own escalations and improve the platform., Our customers don’t just need a platform that tracks their GRC program. They need a trusted voice who can help them think through it. As a Senior GRC Analyst, you’ll be the person customers turn to when a risk assessment gets complicated, an audit raises an unexpected question, or a policy needs to be adapted to their specific environment.

This role goes beyond process execution and platform support. You’ll bring real GRC judgment to every customer interaction, recognizing when a question is more complex than it looks, and guiding customers through it with the confidence of someone who has actually done this work before.

What You’ll Do

  • Serve as a hands-on GRC advisor for a portfolio of customers, guiding them through risk assessments, risk registers, audit preparation, and control rollouts.
  • Help customers prepare for and navigate audits (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST, and similar frameworks), translating requirements into practical next steps.
  • Advise on policy development and control design tailored to each customer’s risk profile and maturity level - not just “what the framework says,” but what actually makes sense for them.
  • Spot GRC complexity early - recognizing when a customer’s question touches on risk, compliance, or audit nuance that needs more than a standard playbook answer.
  • Partner closely with Support and Customer Success to own the escalations that require real GRC expertise, not just product knowledge.
  • Turn recurring customer questions into scalable guidance - playbooks, internal knowledge base content, and best-practice frameworks the whole team can use.
  • Act as the voice of the customer internally, flagging where our platform could better support real-world GRC workflows.

Requirements

  • 5+ years of experience as a GRC analyst, consultant, or coordinator - in-house, at a consulting firm, or in a similar capacity.
  • Direct, hands-on experience with audits, risk assessments and risk registers, and policy rollouts - you’ve been in the room, not just read about it.
  • Working familiarity with common frameworks (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST, or similar) - deep specialization isn’t required, but you should be able to orient quickly in any of them.
  • An instinct for GRC complexity: you can tell when something is more nuanced than it first appears, and you know how to break it down for someone who’s stuck.
  • Strong consultative communication skills - you can explain a compliance concept to a nontechnical stakeholder without losing the substance.
  • A genuine interest in helping customers solve problems, not just closing tickets.

Nice to Have

  • Certifications such as CISA, CRISC, CGRC, or ISO 27001 Lead Implementer/Auditor.
  • Experience working directly with a GRC software platform (as a practitioner, implementer, or vendor-side consultant).
  • Exposure to multiple industries or company sizes, giving you a broader sense of how GRC programs vary in practice.

Benefits & conditions

Competitive salary and meaningful equity participation at a Series A inflection point. Comprehensive paid benefits, including health insurance, 401(k), and generous leave policies. WHY COMPYL

Category-defining market: GRC and automated compliance is one of the fastest-growing segments in enterprise software. The tailwinds are structural, not cyclical.

Real product, real traction: Healthy customer growth, a platform built by practitioners who understand the buyer.

Series A momentum: Backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures, with the capital and conviction to scale aggressively.

Autonomy, no bureaucracy: No micromanagement. You’re trusted as the expert and given room to build the function your way.

About the company

Compyl is a high-growth, venture-backed GRC and automated security compliance platform built by security practitioners for security practitioners. Founded in 2020 by two former CISO’s, we replace the spreadsheets, point tools, and consulting engagements security teams have relied on with a single, all-in-one platform that automates evidence collection, control mapping, audit preparation, and continuous monitoring. We’re backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.ashbyhq.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Platform compliance and security certifications for sensitive data

Chad Carlson ¡ WWC 2021

1:30 min

Introduction to software quality assurance in enterprise applications

Lilia Gargouri Lilia Gargouri ¡ WWC Europe 2026

1:53 min

Entering software development through retro computing platforms

Alex Soto Alex Soto ¡ LIVE

1:35 min

Mandatory EU time tracking challenges for small business operations

Alija Nuredini Alija Nuredini ¡ WWC Europe 2026

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell ¡ WWC Europe 2026

1:48 min

Limitations and missing features in edge compute platforms

Austin Gil ¡ LIVE

Videos

See all

Related articles

See all