> Markdown version of [/jobs/ext/2706255-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2706255-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** NINJATRADER, LLC - **Location:** Chicago, IL, United States (Remote available) - **Experience:** Experienced - **Salary:** $130,000.0 - $145,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Data Analysis, Microsoft Azure, Spreadsheets, Cloud Computing Security, Continuous Integration, Identity and Access Management, Information Technology Audit, Python (Programming Language), Systems Development Life Cycle, SQL Databases, Systems Integration, Software Vulnerability Management, Data Logging, Cloud Platform System, IT General Controls (ITGC), Restful APIs, Terraform - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/grc-analyst-ninjatrader-8687349 ## About the Role * 3-5 years of experience in GRC, IT audit, security compliance, or a related field * Hands-on experience supporting or leading audits for SOC 2, ISO 27001, SOX, or a comparable framework * Working knowledge of SOC 2 Trust Services Criteria, ISO 27001 Annex A, COSO/SOX ITGCs, NIST, or similar control frameworks * Experience with scripting and automation using Python or a similar language, including working with REST APIs to automate evidence collection * Familiarity with at least one major cloud platform (AWS, GCP, or Azure) and its security and logging services * Strong understanding of access management, change management, logging and monitoring, vulnerability management, and SDLC controls * Excellent written communication skills with the ability to create clear control documentation, risk assessments, and stakeholder reporting * Ability to manage multiple priorities while driving audit findings and remediation efforts to completion Bonus points for: * Experience with Infrastructure as Code (Terraform) and CI/CD pipeline security * Exposure to SOX ITGC testing within a public company or pre-IPO environment * Experience using SQL or data analysis for evidence collection and control sampling * Certifications such as CISA, CISSP, CCSK, ISO 27001 Lead Implementer or Lead Auditor, or cloud security certifications * Experience working directly with external auditors and managing audit timelines ## Description We're looking for a mid-level GRC Analyst to help us scale our compliance program through automation and run audits across SOC 2, ISO 27001, and SOX. This is a hands-on, technical role where you'll spend as much time writing code and integrating systems as you do reviewing controls. You'll serve as the bridge between Security, Engineering, and the business by transforming manual, evidence-heavy compliance work into automated, repeatable processes while helping leadership understand and prioritize risk. This role is ideal for someone with GRC or security experience who wants to move beyond spreadsheets and checklists into building the tooling that makes a compliance program efficient, scalable, and audit-ready year-round. In this role you will: Automation & Tooling * Build and maintain automation for continuous control monitoring, evidence collection, and audit readiness through scripts, APIs, and GRC platform integrations * Integrate compliance workflows with cloud providers, identity systems, ticketing platforms, and CI/CD pipelines to automatically collect control data and evidence * Reduce manual compliance work by codifying control checks and pulling evidence directly from source systems * Develop dashboards and reporting that provide stakeholders with real-time visibility into control health and audit readiness Audits & Frameworks * Run and coordinate audits for SOC 2 (Type I and Type II), ISO 27001, and SOX, including scoping, evidence collection, control walkthroughs, and auditor coordination * Map controls across multiple compliance frameworks to reduce duplication and maintain a unified control library * Track audit findings and control gaps through remediation and closure with business and technical stakeholders * Maintain audit-ready documentation including policies, procedures, control narratives, and evidence repositories Risk Management * Identify, assess, and document organizational risks while maintaining the enterprise risk register * Support risk assessments, including likelihood and impact scoring, treatment planning, and remediation tracking * Partner with Engineering and IT to evaluate the control impact of new systems, vendors, and architectural changes * Contribute to the third-party risk management program Cross-Functional Partnership * Partner with control owners to ensure controls are operating effectively and generating appropriate evidence * Translate compliance requirements into practical, engineering-focused guidance * Support customer security questionnaires, trust requests, and due diligence activities ## Related Videos - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Launching a marketplace on-time: A lesson in taking shortcuts using spreadsheets!](https://www.wearedevelopers.com/videos/477-launching-a-marketplace-on-time-a-lesson-in-taking-shortcuts-using-spreadsheets) - [Rest API Antipatterns](https://www.wearedevelopers.com/videos/100208-rest-api-antipatterns) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges)