GRC Analyst
Paxos
Let the right jobs find you
Get personalised suggestions from verified company career pages, matched to your role, location, level, and skills.
Overview
Position Type
Full Time
Experience
Not specified
Job Description
The GRC Analyst supports the development, implementation, and maintenance of governance, risk management, and compliance programs within the organization. The role involves assessing security risks, monitoring compliance with internal policies and external regulations, coordinating audits, and ensuring that appropriate controls are in place to protect business information and technology assets. The GRC Analyst works with cross-functional teams, including Information Security, IT, Legal, Privacy, Internal Audit, and Business Operations, to identify risks, track remediation activities, and improve the organization’s overall risk and compliance posture. Your experience should include: Experience in Governance, Risk, and Compliance (GRC), information security, IT risk management, or cybersecurity compliance roles. Hands-on experience performing security risk assessments, control assessments, compliance and Privacy reviews. Experience working with security frameworks and standards such as ISO 27001, NIST CSF, SOC 2, PCI DSS, GDPR, or similar regulatory requirements. Experience supporting internal and external audits, including evidence collection, control validation, and remediation tracking. Experience developing, reviewing, and maintaining security policies, standards, procedures, and compliance documentation. Experience managing risk registers, control matrices, audit findings, and corrective action plans. Experience conducting third-party/vendor security risk assessments and reviewing supplier compliance documentation.