> Markdown version of [/jobs/ext/2289038-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2289038-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** Gusto - **Location:** San Jose, CA, United States - **Experience:** Expert - **Salary:** $183,000.0 - $205,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Information Systems, Enterprise Software Applications, IT General Controls (ITGC) - **Published:** August 29, 2026 - **Apply:** https://job-boards.greenhouse.io/gusto/jobs/8082139 ## About the Role * 8+ years of experience in governance, risk, and compliance within SaaS, ideally in the HCM, payroll, or fintech sectors. * Bachelor's degree in Business, Information Systems, or a related field. * Strong understanding of SaaS business models, with experience implementing controls and policies in fast-paced, product-driven environments. * Proven experience leading or supporting a SOC 2 Type 2 compliance initiative, including collaboration with auditors and cross-functional teams. * Familiarity with compliance tools and platforms such as Optro, Vanta, Drata, Viso Trust, or similar. * Demonstrated ability to translate complex GRC requirements into actionable, scalable processes. * Excellent written and verbal communication skills, including the ability to educate and influence cross-functional stakeholders. * A data-informed mindset, with the ability to use analytics to assess GRC performance and maturity. * One or more relevant professional certifications: * CISA, CRISC, or GRCP preferred * CGEIT, CRMA, or PMI-RMP are a bonus Our cash compensation amount for this role is targeted at $183,000-205,000 in the San Francisco Bay Area. Stock equity is additional. Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above., You are considered to have a disability if you have a physical or mental impairment or medical condition that substantially limits a major life activity, or if you have a history or record of such an impairment or medical condition. Disabilities include, but are not limited to: * Blindness * Deafness * Cancer * Diabetes * Epilepsy * Autism * Cerebral palsy * HIV/AIDS * Schizophrenia * Muscular dystrophy * Bipolar disorder * Major depression * Multiple sclerosis (MS) * Missing limbs or partially missing limbs * Post-traumatic stress disorder (PTSD) * Obsessive compulsive disorder * Impairments requiring the use of a wheelchair * Intellectual disability ## Description Gusto is seeking a Security, Governance, Risk & Compliance professional to join our team managing our security governance, risk and compliance initiatives. This person will guide the company from foundational Governance, Risk & Compliance (GRC) maturity through to steady-state operations, leveraging AI to automate and improve old practices and tools, ensuring ongoing compliance with SOC 2 Type 2, IT General Controls, ICOC and related frameworks, while embedding security-minded practices throughout Gusto. This is a cross-functional role with key touchpoints in every department. Here's what you'll do day-to-day: * Develop, maintain, and ensure adherence to security and compliance SOPs, internal documentation, and company-wide policies-particularly supporting SOC 2 and future framework adoption. * Own and manage trust management platforms including documentation of controls, risks, vendors, and exceptions, and lead the implementation of AI agents to automate and improve the implementation of our controls framework and evidence collection to support it * Collaborate with Legal, Enterprise Applications, and Gusto counterparts to establish and maintain data governance policies (e.g., classification, retention, handling). * Conduct ongoing internal risk assessments to identify exposure and control gaps; coordinate remediation plans with functional teams. * Manage the third-party vendor risk program, including onboarding reviews, monitoring, and renewal assessments. * Lead interactions with external auditors and regulatory bodies during compliance assessments (e.g., SOC 2 Type 2) and oversee responses to client security assessments and due diligence requests. * Stay current on relevant compliance frameworks, laws, and regulations to ensure appropriate coverage and adaptability. * Partner cross-functionally (e.g., Security, Legal, Engineering, Sales, IT) to implement scalable GRC processes, harmonize systems, and foster GRC understanding through employee enablement programs and KPI-driven insights., Glassdoor Indeed Facebook Built In Colorado News Article Conference or Meetup Company Blog Company Employee Company Website Billboard/Outdoor Ads Are you legally authorized to work in the country where you are applying?* Select... Will you now or in the future require visa sponsorship for employment?* Select... If you'll require this employer to commence, i.e., "sponsor," an immigration or work permit case in order to employ you, either now or at some point in the future, then you should answer yes. An example of an immigration or work permit case that may require sponsorship now or in the future would be an H-1B or other employment-based work permit sponsorship. Do you have at minimum 8+ years of experience in governance, risk, and compliance within SaaS, ideally in the HCM, payroll, or fintech sectors?* Select... Do you have proven experience leading or supporting a SOC 2 Type 2 compliance initiative, including collaboration with auditors and cross-functional teams?* Select... Do you currently have one or more relevant professional certifications such as CISA, CRISC, or GRCP? * Select... Do you currently reside in the San Francisco Bay Area and are willing to come into the office twice a week on Tuesdays and Wednesdays?* Select..., In addition to the information required to consider your application, below is a set of demographic questions that help us identify areas for improvement in our process and further support the development and execution of our diversity efforts and programs as well as to create a more inclusive environment for all employees. ## Related Videos - [Beyond Gut Feelings: The Rise of Data-Driven HR](https://www.wearedevelopers.com/videos/1326-beyond-gut-feelings-the-rise-of-data-driven-hr) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Beyond the Hype: Building Trustworthy and Reliable LLM Applications with Guardrails](https://www.wearedevelopers.com/videos/1594-beyond-the-hype-building-trustworthy-and-reliable-llm-applications-with-guardrails) - [Edit Your Future: Queerverse Radical AI](https://www.wearedevelopers.com/videos/909-edit-your-future-queerverse-radical-ai) - [What if your HR software adapted to you, not the other way around?](https://www.wearedevelopers.com/videos/100259-what-if-your-hr-software-adapted-to-you-not-the-other-way-around) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Software Developer Salary in Switzerland [2023]](https://www.wearedevelopers.com/magazine/215-software-developer-salary-in-switzerland-2023) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Software Developer Salary in Germany [2023]](https://www.wearedevelopers.com/magazine/194-software-developer-salary-in-germany-2023) - [Highest Paying Tech Companies in Europe](https://www.wearedevelopers.com/magazine/162-highest-paying-tech-companies-in-europe) - [Backend Developer Salary in Germany [2023]](https://www.wearedevelopers.com/magazine/196-backend-developer-salary-in-germany-2023)