> Markdown version of [/jobs/ext/185847-senior-grc-analyst](https://www.wearedevelopers.com/jobs/ext/185847-senior-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior GRC Analyst - **Company:** Black Kite - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $100,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Network Security, Cloud Services, Vulnerability Analysis - **Published:** May 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1521dae8b781af29 ## About the Role Do you have experience in Vendor risk management?, * 2-4 years of hands-on experience in GRC, compliance, or information security * Practical working knowledge of SOC 2, NIST, or ISO 27001 applied in a real compliance environment * Experience producing compliance evidence, contributing to audit cycles, or managing specific framework control domains independently * Familiarity with cloud services principles and their security and compliance implications * General knowledge of core security domains: network security, email security, endpoint protection, vulnerability scanning, access controls, log management * Strong written communication - audit-ready documentation produced independently PREFERRED * Hands-on experience administering Vanta or an equivalent compliance platform as a primary owner - not just a user * Direct experience with FedRAMP ConMon - monthly reporting, POA&M tracking, evidence production * Experience owning or significantly contributing to a customer security questionnaire response program * Familiarity with TPCRM programs and vendor questionnaire workflows * Active or in-progress certification: CompTIA Security+, CISA, CRISC, ISO 27001 Lead Auditor/Implementer, or equivalent ## Description The Senior GRC Analyst reports to the Director of Information Security and owns three primary functions: the compliance platform (Vanta), inbound customer security assessments, and FedRAMP ConMon execution support. This is an independent practitioner role - direction comes from the Director, but you own your work without step-by-step guidance. The "Senior" in this title is earned by the scope, not just the experience level. Owning the compliance platform means auditors see your work directly. Owning customer assessments means your responses are read by enterprise security teams before they sign. Supporting FedRAMP ConMon means authorization status depends in part on what you produce monthly. The stakes are real. WHAT YOU'LL OWN Compliance platform (Vanta) - primary owner * Own the compliance platform end-to-end: evidence library currency, control mapping accuracy, framework completeness across SOC 2, ISO 27001, FedRAMP, and GDPR * Evidence is current year-round - not assembled at audit time; no stale or missing evidence in any active certification domain Customer security assessments - primary owner * Own the inbound customer assessment intake and response process - all RFPs and security questionnaires are assigned, tracked, and responded to within defined SLA * Collaborate with sales, legal, and technical teams on complex questionnaire responses; escalate novel or sensitive items to the Director * Maintain and improve the questionnaire response library across all active frameworks FedRAMP ConMon - execution support * Support monthly ConMon reporting - vulnerability scan results, POA&M updates, and evidence - as primary executor * Maintain POA&M tracking accuracy; flag aging items to the Director before they breach defined thresholds TPCRM and compliance support * Support third-party risk identification, assessment, and monitoring activities as directed * Monitor compliance framework and regulatory changes; assess impact and surface findings to the Director with a recommended response * Support internal audit processes - evidence coordination, control testing documentation, and auditor request responses ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges)