Senior GRC Analyst
RainfocusNorth AmericaFull TimeOther
Remotely
pci dssiso 27001soc 2all othervantadrataonetrustnist sp 800 30
Job Description
📋 Description
- Lead RainFocus's GRC program across SOC 2, ISO 27001, PCI DSS, and others.
- Audit prep, evidence collection, auditor relationships.
- Manage and mature control framework; map new regs; gap assessments.
- Own annual security risk assessment (NIST SP 800-30).
- Update security policies and documentation for best practices.
- Partner with Engineering to mature vulnerability management and secrets scanning.
🎯 Requirements
- Bachelor's in Tech, Cybersecurity, or related field desirable.
- 6+ years in GRC, IT audit, or info security compliance.
- In-depth knowledge: SOC 2, ISO 27001, PCI DSS, NIST 800-series, GDPR.
- Experience with formal risk assessments, not just checklists.
- Certs like CISA, CRISC, CISSP, CIPP, CIPM desirable.
- Familiarity with tools: Drata, OneTrust, Vanta, etc.
🎁 Benefits
- Competitive salary and benefits, 401k, generous PTO.