GRC Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Serve as a hands-on GRC advisor for customers: guide risk assessments, audits (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST), risk registers, policy and control rollouts; resolve complex GRC questions; create scalable guidance and partner with Support and Customer Success to own escalations and improve the platform., Our customers donât just need a platform that tracks their GRC program. They need a trusted voice who can help them think through it. As a Senior GRC Analyst, youâll be the person customers turn to when a risk assessment gets complicated, an audit raises an unexpected question, or a policy needs to be adapted to their specific environment.
This role goes beyond process execution and platform support. Youâll bring real GRC judgment to every customer interaction, recognizing when a question is more complex than it looks, and guiding customers through it with the confidence of someone who has actually done this work before.
What Youâll Do
- Serve as a hands-on GRC advisor for a portfolio of customers, guiding them through risk assessments, risk registers, audit preparation, and control rollouts.
- Help customers prepare for and navigate audits (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST, and similar frameworks), translating requirements into practical next steps.
- Advise on policy development and control design tailored to each customerâs risk profile and maturity level - not just âwhat the framework says,â but what actually makes sense for them.
- Spot GRC complexity early - recognizing when a customerâs question touches on risk, compliance, or audit nuance that needs more than a standard playbook answer.
- Partner closely with Support and Customer Success to own the escalations that require real GRC expertise, not just product knowledge.
- Turn recurring customer questions into scalable guidance - playbooks, internal knowledge base content, and best-practice frameworks the whole team can use.
- Act as the voice of the customer internally, flagging where our platform could better support real-world GRC workflows.
Requirements
- 5+ years of experience as a GRC analyst, consultant, or coordinator - in-house, at a consulting firm, or in a similar capacity.
- Direct, hands-on experience with audits, risk assessments and risk registers, and policy rollouts - youâve been in the room, not just read about it.
- Working familiarity with common frameworks (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST, or similar) - deep specialization isnât required, but you should be able to orient quickly in any of them.
- An instinct for GRC complexity: you can tell when something is more nuanced than it first appears, and you know how to break it down for someone whoâs stuck.
- Strong consultative communication skills - you can explain a compliance concept to a nontechnical stakeholder without losing the substance.
- A genuine interest in helping customers solve problems, not just closing tickets.
Nice to Have
- Certifications such as CISA, CRISC, CGRC, or ISO 27001 Lead Implementer/Auditor.
- Experience working directly with a GRC software platform (as a practitioner, implementer, or vendor-side consultant).
- Exposure to multiple industries or company sizes, giving you a broader sense of how GRC programs vary in practice.
Benefits & conditions
Competitive salary and meaningful equity participation at a Series A inflection point. Comprehensive paid benefits, including health insurance, 401(k), and generous leave policies. WHY COMPYL
Category-defining market: GRC and automated compliance is one of the fastest-growing segments in enterprise software. The tailwinds are structural, not cyclical.
Real product, real traction: Healthy customer growth, a platform built by practitioners who understand the buyer.
Series A momentum: Backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures, with the capital and conviction to scale aggressively.
Autonomy, no bureaucracy: No micromanagement. Youâre trusted as the expert and given room to build the function your way.
About the company
Compyl is a high-growth, venture-backed GRC and automated security compliance platform built by security practitioners for security practitioners. Founded in 2020 by two former CISOâs, we replace the spreadsheets, point tools, and consulting engagements security teams have relied on with a single, all-in-one platform that automates evidence collection, control mapping, audit preparation, and continuous monitoring. Weâre backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on jobs.ashbyhq.comGood distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
7 Important Tips That Every Software Developer Should Know
Quick guide: How to write a Software Developer CV
What Are The Top Skills Required For Azure Developers?
9 Ways to Make Money Hacking