Gusto, Inc.10 дней назад

Senior GRC Analyst

15 250–17 083 ₽в месяц · до вычета
РЫНОК
12 083медиана по профессии
System Analyst · 27 вакансий с указанной зарплатой
5 680половина предложений: 9 403–15 33468 087
В рынке · выше 74% предложений
San Francisco

Обязанности

  • 01Develop, maintain, and ensure adherence to security and compliance SOPs, internal documentation, and company-wide policies—particularly supporting SOC 2 and future framework adoption
  • 02Own and manage trust management platforms including documentation of controls, risks, vendors, and exceptions, and lead the implementation of AI agents to automate and improve the implementation of our controls framework and evidence collection to support it
  • 03Collaborate with Legal, Enterprise Applications, and Gusto counterparts to establish and maintain data governance policies (e.g., classification, retention, handling)
  • 04Conduct ongoing internal risk assessments to identify exposure and control gaps; coordinate remediation plans with functional teams
  • 05Manage the third-party vendor risk program, including onboarding reviews, monitoring, and renewal assessments
  • 06Lead interactions with external auditors and regulatory bodies during compliance assessments (e.g., SOC 2 Type 2) and oversee responses to client security assessments and due diligence requests
  • 07Stay current on relevant compliance frameworks, laws, and regulations to ensure appropriate coverage and adaptability
  • 08Partner cross-functionally (e.g., Security, Legal, Engineering, Sales, IT) to implement scalable GRC processes, harmonize systems, and foster GRC understanding through employee enablement programs and KPI-driven insights

Требования

  • 018+ years of experience in governance, risk, and compliance within SaaS, ideally in the HCM, payroll, or fintech sectors
  • 02Bachelor’s degree in Business, Information Systems, or a related field
  • 03Strong understanding of SaaS business models, with experience implementing controls and policies in fast-paced, product-driven environments
  • 04Proven experience leading or supporting a SOC 2 Type 2 compliance initiative, including collaboration with auditors and cross-functional teams
  • 05Familiarity with compliance tools and platforms such as Optro, Vanta, Drata, Viso Trust, or similar
  • 06Demonstrated ability to translate complex GRC requirements into actionable, scalable processes
  • 07Excellent written and verbal communication skills, including the ability to educate and influence cross-functional stakeholders
  • 08A data-informed mindset, with the ability to use analytics to assess GRC performance and maturity
  • 09One or more relevant professional certifications: CISA, CRISC, or GRCP preferred CGEIT, CRMA, or PMI-RMP are a bonus

Условия

  • 01Our cash compensation amount for this role is targeted at $183,000-205,000 in the San Francisco Bay Area
  • 02Stock equity is additional
  • 03Gusto has physical office spaces in Denver, San Francisco, and New York City
  • 04Employees who are based in those locations will be expected to work from the office on designated days approximately 2-3 days per week (or more depending on role)
  • 05The same office expectations apply to all Symmetry roles, Gusto's subsidiary, whose physical office is in Scottsdale
  • 06When approved to work from a location other than a Gusto office, a secure, reliable, and consistent internet connection is required
  • 07This includes non-office days for hybrid employees
  • 08All full-time employees receive competitive base pay, benefits, and equity (RSUs)