Senior GRC Analyst Closed

๐Ÿ’ฐ $135k-$190k
๐Ÿ‡บ๐Ÿ‡ธ United States - Remote
๐Ÿ”’ Cybersecurity๐ŸŸฃ Senior

Job description

About Juniper Square

Our mission is to unlock the full potential of private markets. Privately owned assets like commercial real estate, private equity, and venture capital make up half of our financial ecosystem yet remain inaccessible to most people. We are digitizing these markets, and as a result, bringing efficiency, transparency, and access to one of the most productive corners of our financial ecosystem. If you care about making the world a better place by making markets work better through technology โ€“ all while contributing as a member of a values-driven organization โ€“ we want to hear from you.

Juniper Square offers employees a variety of ways to work, ranging from a fully remote experience to working full-time in one of our physical offices. We invest heavily in digital-first operations, allowing our teams to collaborate effectively across 27 U.S. states, 2 Canadian Provinces, India, Luxembourg, and England. We also have a physical offices in San Francisco, New York City, Mumbai and Bangalore for employees who prefer to work in an office some or all of the time.

About your role

The GRC Analyst is responsible for supporting the organization’s governance, risk management, and compliance (GRC) program. The ideal candidate will have a strong understanding and experience building scalable, right-sized risk management and compliance processes for a high-growth company. The successful candidate will also possess strong analytical and problem-solving skills, as well as excellent communication and interpersonal skills. This role will work closely with a broad set of cross-functional stakeholders within the company and should be able to build a rapport and influence towards appropriate risk management outcomes.

What youโ€™ll do

  • Governance (20%)

    1. Policy Management

      1. Develop a comprehensive set of security and privacy policies and procedures working with Legal, HR, IT, Engineering.

      2. Update policies and procedures annually while incorporating stakeholder feedback and obtain approval

      3. Define and manage incoming policy exceptions on an ongoing basis to manage associated risk

    2. Security and Privacy Training and Awareness

      1. Develop and implement role and team specific security and privacy training working closely with key business partners.

      2. Manage the roll-out, escalation and completion of all security and privacy training modules.

    3. Phishing Management

      1. Manage phishing campaigns on an ongoing basis with appropriate re-training processes baked into the process

      2. Refine existing phishing reporting processes and integrate this better with our incident management processes

    4. GRC Metrics and Reporting

      1. Ensure the GRC function meets key performance metrics
  • Risk (40%)

    1. Risk Management

      1. Maintain business unit risk registers with existing teams on a monthly basis to appropriately address key risks areas

      2. Co-develop and coach business units on right-sized and right-scoped risk remediation plans

      3. Work with cross-functional teams to onboard new business units onto the risk management process

    2. Third-Party Risk Management

      1. Continuously improve vendor and contractor risk assessments during vendor onboarding with a defined SLA.

      2. Conduct annual vendor monitoring and re-assessment processes for existing vendors

      3. Maintain the vendor risk register and work with vendors to reduce risk on an ongoing basis

  • Compliance (40%)

    1. Compliance

      1. Maintain and onboard existing/new security compliance certifications and frameworks (e.g. SOC2, ISO and others)

        1. Work with cross-functional teams to procure controls evidence to provide to external auditors timely and issue reports timely.

        2. Work cross functionally between teams and auditors to ensure a smooth and efficient audit process

        3. Improve the audit process through automation and controls rationalization year over year

        4. Monitor and test effectiveness of compliance control health throughout the year; not just during audits

        5. Serve as a subject matter expert for all things compliance;

             1. Identify and assess business changes for relevant impacts on compliance posture (e.g. geographical expansion, internal tool replacement, new products)
          
    2. Customer Trust

      1. Maintain our trust center by keeping security documents and knowledge base up-to-date

      2. Support sales teams with open security and privacy questions

      3. Review incoming security and privacy addendums to customer contracts

      4. Support customer security and privacy audits

      5. Work with Sales and Solutions engineering to coach and educate teams on our security and compliance posture

Qualifications

  • Bachelor’s degree in information systems, engineering, business, risk management, or a related field

  • 5+ years of experience in GRC, security, audit or a related field with past experience in managing a SOC2/ISO 27001 program

  • Knowledge of GRC frameworks and regulations

  • Experience developing scalable GRC processes

  • Ability to work on multiple GRC projects simultaneously

  • Ability to partner with stakeholders collaboratively โ€œguardrailsโ€ without having a โ€œgatedโ€ approach to risk management

  • Excellent communication and interpersonal skills

Compensation

Compensation for this position includes a base salary and a variety of benefits. The U.S. base salary range for this role is $135,000 to $190,000. Actual base salaries will be based on candidate-specific factors, including experience, skillset, and location, and local minimum pay requirements as applicable.

Benefits include:

  • Health, dental, and vision care for you and your family

  • Life insurance

  • Mental wellness coverage

  • Fertility and growing family support

  • Flex Time Off in addition to company paid holidays

  • Paid family leave, medical leave, and bereavement leave policies

  • Retirement saving plans

  • Allowance to customize your work and technology setup at home

  • Annual professional development stipend

Your recruiter can provide additional details about compensation and benefits.

#LI-AD1

Similar Remote Jobs

Benefits of using Remote First Jobs

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

Advanced Filters

Filter by category, benefits, seniority, and more.

Priority Job Alerts

Get timely alerts for new job openings every day.

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

Search remote, work from home, 100% online jobs

We help you connect with top remote-first companies.

Search jobs

Hiring remote talent? Post a job

Frequently Asked Questions

What makes Remote First Jobs different from other job boards?

Unlike other job boards that only show jobs from companies that pay to post, we actively scan over 20,000 companies to find remote positions. This means you get access to thousands more jobs, including ones from companies that don't typically post on traditional job boards. Our platform is dedicated to fully remote positions, focusing on companies that have adopted remote work as their standard practice.

How often are new jobs added?

New jobs are constantly being added as our system checks company websites every day. We process thousands of jobs daily to ensure you have access to the most up-to-date remote job listings. Our algorithms scan over 20,000 different sources daily, adding jobs to the board the moment they appear.

Can I trust the job listings on Remote First Jobs?

Yes! We verify all job listings and companies to ensure they're legitimate. Our system automatically filters out spam, junk, and fake jobs to ensure you only see real remote opportunities.

Can I suggest companies to be added to your search?

Yes! We're always looking to expand our listings and appreciate suggestions from our community. If you know of companies offering remote positions that should be included in our search, please let us know. We actively work to increase our coverage of remote job opportunities.

How do I apply for jobs?

When you find a job you're interested in, simply click the 'Apply Now' button on the job listing. This will take you directly to the company's application page. We kindly ask you to mention that you found the position through Remote First Jobs when applying, as it helps us grow and improve our service ๐Ÿ™