Staff Grc Analyst

Vercel Vercel · Enterprise · AMER · Security

This role focuses on Governance, Risk, and Compliance (GRC) for a tech company, specifically scaling commercial attestation programs and audits (SOC 2, ISO 27001, PCI DSS), designing continuous monitoring, and driving security and compliance control frameworks. It involves partnering with cross-functional teams to implement and remediate controls and championing a culture of compliance accountability.

What you'd actually do

  1. Own and scale commercial attestation program and audits (i.e., SOC 2, ISO 27001, PCI DSS, etc.) while maintaining alignment with business objectives and market demand.
  2. Design and strengthen continuous monitoring processes to improve control effectiveness and mature control implementation from audit-ready to always-ready.
  3. Drive evolution of security and compliance control frameworks that set the direction for proactive risk management.
  4. Partner with cross-functional stakeholders, acting as a strategic connector to plan, implement, maintain & remediate control activities and supporting requirements (e.g. policies, standards, processes, system configurations, etc.)
  5. Champion a culture of compliance accountability and business-enablement across the organization through autonomous program governance and reporting and building trusted relationships.

Skills

Required

  • Managing and running audits, certification programs and enterprise control assessments
  • Scope planning
  • Defining requirements
  • Policy and standards development
  • Control testing
  • Deep knowledge of audit processes
  • Evidence requirements
  • Remediation lifecycle management for security and compliance frameworks (i.e., SOC 2, ISO 27001, PCI DSS)
  • Owning large-scale GRC programs
  • Collaborating with technical and non-technical teams
  • Driving initiatives to completion

Nice to have

  • Familiarity with data governance, compliance or software development tools and systems (e.g., Drata, Linear, Github, etc.)
  • Experience supporting cloud, AI-native, and open source development environments and systems
  • Experience with FedRAMP or NIST frameworks, such as 800-53, AI RMF
  • Security certifications (e.g. CISA, CISSP)

What the JD emphasized

  • security requirements
  • security and compliance control frameworks
  • control activities
  • compliance accountability