> Markdown version of [/jobs/ext/1756041-grc-analyst](https://www.wearedevelopers.com/jobs/ext/1756041-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** COMPLYSHARE LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $115,000.0 - $145,000.0 - **Contract:** Permanent contract - **Skills:** Computing Platforms, PCI Data Security Standards, Enterprise Software Applications - **Published:** July 18, 2026 - **Apply:** https://jobs.ashbyhq.com/compyl/62d91d65-099c-489c-baab-d5f0be149eca ## About the Role * 5+ years of experience as a GRC analyst, consultant, or coordinator - in-house, at a consulting firm, or in a similar capacity. * Direct, hands-on experience with audits, risk assessments and risk registers, and policy rollouts - you've been in the room, not just read about it. * Working familiarity with common frameworks (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST, or similar) - deep specialization isn't required, but you should be able to orient quickly in any of them. * An instinct for GRC complexity: you can tell when something is more nuanced than it first appears, and you know how to break it down for someone who's stuck. * Strong consultative communication skills - you can explain a compliance concept to a nontechnical stakeholder without losing the substance. * A genuine interest in helping customers solve problems, not just closing tickets. Nice to Have * Certifications such as CISA, CRISC, CGRC, or ISO 27001 Lead Implementer/Auditor. * Experience working directly with a GRC software platform (as a practitioner, implementer, or vendor-side consultant). * Exposure to multiple industries or company sizes, giving you a broader sense of how GRC programs vary in practice. ## Description Serve as a hands-on GRC advisor for customers: guide risk assessments, audits (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST), risk registers, policy and control rollouts; resolve complex GRC questions; create scalable guidance and partner with Support and Customer Success to own escalations and improve the platform., Our customers don't just need a platform that tracks their GRC program. They need a trusted voice who can help them think through it. As a Senior GRC Analyst, you'll be the person customers turn to when a risk assessment gets complicated, an audit raises an unexpected question, or a policy needs to be adapted to their specific environment. This role goes beyond process execution and platform support. You'll bring real GRC judgment to every customer interaction, recognizing when a question is more complex than it looks, and guiding customers through it with the confidence of someone who has actually done this work before. What You'll Do * Serve as a hands-on GRC advisor for a portfolio of customers, guiding them through risk assessments, risk registers, audit preparation, and control rollouts. * Help customers prepare for and navigate audits (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST, and similar frameworks), translating requirements into practical next steps. * Advise on policy development and control design tailored to each customer's risk profile and maturity level - not just "what the framework says," but what actually makes sense for them. * Spot GRC complexity early - recognizing when a customer's question touches on risk, compliance, or audit nuance that needs more than a standard playbook answer. * Partner closely with Support and Customer Success to own the escalations that require real GRC expertise, not just product knowledge. * Turn recurring customer questions into scalable guidance - playbooks, internal knowledge base content, and best-practice frameworks the whole team can use. * Act as the voice of the customer internally, flagging where our platform could better support real-world GRC workflows. ## Related Videos - [Creating Europe's AI Moment – Now or Never](https://www.wearedevelopers.com/videos/100059-creating-europe-s-ai-moment-now-or-never) - [GitOps keeps focus on apps, not on infrastructure](https://www.wearedevelopers.com/videos/182-gitops-keeps-focus-on-apps-not-on-infrastructure) - [Modern Web Development with Nuxt3](https://www.wearedevelopers.com/videos/294-modern-web-development-with-nuxt3) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [AI Driven Development](https://www.wearedevelopers.com/videos/100340-ai-driven-development) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Quick guide: How to write a Software Developer CV](https://www.wearedevelopers.com/magazine/37-quick-guide-how-to-write-a-software-developer-cv) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)