Senior GRC Analyst

Turing · United States · Data

Posted 2026-09-22

Apply for this role →

Senior GRC Analyst

About the role

We're looking for a Senior GRC Analyst to help run our governance, risk, and compliance program day to day. This is a strong individual-contributor role for someone who knows compliance frameworks inside and out, can lead audits with confidence, and can turn control requirements into practical work that teams across the company can actually execute.

You'll own key parts of our compliance certifications, run risk and vendor assessments, maintain our control framework, and be a trusted partner to engineering and business teams as they meet their security and compliance obligations.

What you'll do

Own and coordinate compliance audits and certifications (SOC 2, ISO 27001, and others), including evidence collection, auditor coordination, and remediation tracking.

Maintain and improve our control framework, mapping controls across multiple frameworks to reduce duplicate work.

Conduct risk assessments — identifying, documenting, and tracking risks to resolution.

Run the vendor/third-party risk program: security reviews of vendors and ongoing monitoring.

Support customer security reviews and questionnaires, and help maintain the trust center.

Develop, maintain, and socialize security policies and standards.

Partner with control owners across the company to ensure controls are operating effectively, and drive remediation when they aren't.

Identify opportunities to automate manual GRC work and partner with GRC engineering to implement them.

What we're looking for

Several years of experience (typically 4+ years) in GRC, compliance, audit, or risk.

Hands-on experience supporting or leading SOC 2 and/or ISO 27001 audits.

Solid understanding of control frameworks, risk assessment methodologies, and vendor risk management.

Strong organization and attention to detail, with the ability to manage multiple workstreams and deadlines.

Clear communicator who can work effectively with both technical and non-technical teams.

Comfort with GRC/compliance tooling.

Nice to have

Relevant certifications (CISA, CISSP, CIPP, or similar).

Experience with compliance automation and continuous controls monitoring.

Familiarity with cloud environments and how technical controls are implemented.

Experience supporting enterprise sales and customer security due diligence.

What success looks like

Within your first few months, you'll own key parts of our audit and risk programs, be a go-to partner for control owners, and start turning manual GRC work into repeatable, increasingly automated processes.

Salary: $175k

Values

Apply for this role →

← Back to all jobs