Senior Grc Analyst

Crusoe · Data AI · San Francisco, CA - US · IT, Compliance, and Security

This role supports the day-to-day execution of a Governance, Risk, and Compliance program, focusing on operational compliance activities such as user access reviews, evidence collection, customer trust support, and vendor risk management. The analyst will maintain continuous compliance posture by supporting audits, updating policies, responding to customer security inquiries, and improving GRC processes. A key aspect of the role involves leveraging AI tools to streamline GRC activities and identifying opportunities for process improvement.

What you'd actually do

  1. Supporting User Access Reviews (UARs) across systems and applications on a recurring schedule
  2. Monitoring completion of security awareness training and following up with teams as needed
  3. Assisting in maintaining and updating organizational security policies and standards
  4. Supporting third-party security assessments and vendor risk management processes
  5. Collecting, organizing, and preparing audit evidence for SOC 2, ISO 27001, HIPAA, and other frameworks

Skills

Required

  • 5-7 years of experience in GRC, information security, IT audit, or a related compliance role
  • Foundational knowledge of compliance frameworks such as SOC 2, ISO 27001, HIPAA, or NIST CSF
  • Experience working with GRC platforms (Vanta preferred; Drata, AuditBoard, or similar tools also valued)
  • Hands-on experience performing user access reviews, vendor risk assessments, or audit support activities
  • Familiarity with customer security questionnaires and customer trust processes
  • Comfort using AI tools (e.g., Gemini, Claude, Copilot) to improve efficiency in day-to-day work

Nice to have

  • Certifications such as Security+, CISA (in progress), or ISO 27001 foundations
  • Exposure to cloud environments (GCP preferred; AWS/Azure helpful)
  • Experience with policy management or security awareness training tools
  • Interest in AI governance, risk, or emerging compliance frameworks

What the JD emphasized

  • SOC 2
  • ISO 27001
  • HIPAA