Back to Jobs
YipitData
Legal & HR 7h ago

GRC Analyst

YipitData
United StatesUnited States
Full-time
$102,500 / year + equity
Mid-Level

Job Description

Key Skills Required

Master these to land this role

Contract LawLegal ConsultantParalegal

Want to know if you're a match for this job?

Calculate My Match Score

About The Role:

YipitData is looking for a GRC Analyst who likes asking good questions, finding the gaps others miss, and turning complicated requirements into work people can actually complete.

You will help us answer some important questions: Are our security controls working the way we say they are? Can we prove it? Where are we taking on risk? What needs to change as our products, technology, and use of AI continue to grow?

Your work will span audits, risk assessments, control testing, vendor reviews, customer questionnaires, policies, and compliance programs. You will partner with teams across Security, IT, Engineering, Legal, Finance, and People to understand how the business operates, identify where improvements are needed, and keep the work moving through completion.

This is not a role where success means uploading documents to an audit platform. We want someone who is curious enough to understand the evidence, thoughtful enough to challenge it when it does not make sense, and organized enough to make sure nothing important gets lost in the follow-up.

As a GRC Analyst You Will:

  • Take ownership of GRC workstreams and drive them from the initial request through evidence collection, testing, remediation, and completion
  • Help keep YipitData audit-ready throughout the year
  • Test security controls and determine whether they are actually working, rather than simply confirming that a document exists
  • Conduct risk assessments, identify meaningful gaps, and help teams develop remediation plans that are realistic and effective
  • Map controls across SOC 2 and other frameworks so one strong control can satisfy multiple requirements
  • Coordinate recurring work such as access reviews, control testing, policy reviews, risk updates, and audit evidence requests
  • Review vendors and help determine whether their security practices meet YipitData’s expectations
  • Support customer security questionnaires by finding the right information, validating it, and making sure our answers are accurate and consistent
  • Translate compliance requirements into clear actions for teams that do not live and breathe GRC
  • Draft and maintain policies, standards, control narratives, risk records, metrics, and other program documentation
  • Track findings and remediation commitments, follow up with owners, and keep issues from quietly sitting open forever
  • Look for ways to simplify and automate repetitive GRC work so the program can scale with the business
  • Help us think through governance for emerging technologies, including AI products, agents, and new ways of handling data

You Are Likely To Succeed If:

  • You can operate in an environment that is constantly changing: where not every process is perfect or every answer is immediately available
  • You have experience in security, compliance, risk, audit, privacy, vendor risk, or another field that taught you how to evaluate whether expectations are being met
  • You have hands-on SOC 2 experience, including supporting Type I or Type II audits, testing controls, validating evidence, coordinating with auditors, and tracking remediation through completion
  • You understand that evidence is only useful if it actually proves the control
  • You can connect a policy or framework requirement to what people and systems are doing in the real world
  • You are familiar with SOC 2, NIST CSF, or similar security and compliance frameworks
  • You are a strong writer who can make complicated requirements clear for those not familiar with security frameworks
  • You notice inconsistencies, missing information, and answers that do not quite add up
  • You are comfortable asking follow-up questions and respectfully pushing back when something needs a closer look
  • You can keep multiple workstreams organized, meet deadlines, and follow through
  • You communicate well with both technical and non-technical teams and can explain why a requirement matters
  • You take ownership, use good judgment, and know when to work independently versus when to escalate
  • You are interested in figuring out how traditional governance needs to evolve for AI and other emerging technologies

How would you rate this job post?

See what other professionals think about this role.

banner

YipitData is a leading provider of data analytics and insights, delivering actionable intelligence to businesses and organizations. As a cutting-edge technology company, YipitData specializes in collecting, processing, and analyzing large datasets to uncover hidden trends and patterns. With its innovative approach to data analysis, YipitData empowers clients to make informed decisions, drive growth, and improve their overall performance. The company's expertise in data science, machine learning, and statistical modeling enables it to develop tailored solutions that cater to the unique needs of each client. By leveraging its expertise and capabilities, YipitData has established itself as a trusted partner for businesses seeking to extract maximum value from their data assets. With a strong focus on innovation, quality, and customer satisfaction, YipitData continues to push the boundaries of what is possible with data analytics, helping organizations to achieve their goals and stay ahead of the competition.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More