16 grc analyst jobs at 16 companies in Cotati, CA

2w
Save
Mark Applied
Hide
GRC Analyst
San Francisco, California, United States
$95k-$150k/yr HybridFull Time
Zip
Zip: AI-powered intake-to-procure platform for enterprise spend management
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
1mo
Save
Mark Applied
Hide
Security GRC Analyst
San Francisco, California, United States
$116k-$160k/yr OnsiteFull Time
Salesforce
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
1mo
Save
Mark Applied
Hide
Senior GRC Analyst, HIPAA
United States or San Francisco
$133k-$195k/yr OnsiteFull Time
DoorDash
DoorDashNASDAQ: DASH: On-demand delivery platform connecting consumers with local merchants.
6+ YOE6+ years in security compliance/GRC with 3+ years implementing HIPAA programs in technology or regulated environments; strong HIPAA Security Rule knowledge, multi-framework experience, technical fluency with cloud/IAM/CI/CD, and stakeholder communication skills.
HITRUST, SOC 2, ISO 27001, NIST 800-53, PCI DSS, GDPR, CCPA, IAM, CI/CD, infrastructure-as-code, GRC tooling
2mo
Save
Mark Applied
Hide
Senior Governance, Risk, Compliance (GRC) Analyst
San Francisco, California, United States
$162k-$202k/yr OnsiteFull Time
Headway
Headway: A healthtech accelerating access to mental healthcare
5+ YOE5+ years in GRC/compliance/security risk; knowledge of HITRUST/SOC 2/PCI-DSS/HIPAA; experience with GRC platforms; strong communication; ability to build repeatable processes; interest in AI-enabled security workflows; healthcare/healthtech HIPAA understanding a plus
HITRUST, SOC 2, PCI-DSS, HIPAA, GRC platform (e.g., Vanta, Drata, OneTrust)
2mo
Save
Mark Applied
Hide
Governance, Risk & Compliance (GRC) Analyst
San Francisco, California, United States
$125k-$150k/yr OnsiteFull Time
Ivo
Ivo: AI-powered contract review and intelligence platform for legal teams.
3+ YOE3–5 years GRC/InfoSec/IT audit experience; hands-on SOC 2 Type II, ISO 27001, CSA STAR, ISO/IEC 42001; experience with Vanta, audits, evidence management, risk assessments, policy maintenance, and strong communication skills.
Vanta, GCP, AWS, Azure
2w
Save
Mark Applied
Hide
Third Party Risk Analyst, Security GRC
San Francisco, California, United States
$255k-$270k/yr HybridFull Time
Anthropic
Anthropic: Developing safe and reliable artificial intelligence systems.
Experience running end-to-end third-party/vendor risk assessments at a technology company; knowledge of risk fundamentals; ability to assess security, privacy, compliance, and operational risk; experience with LLM-backed workflows and procurement/GRC platforms.
LLM, RapidRatings, CreditSafe, LSEG
1w
Save
Mark Applied
Hide
Security Analyst
San Francisco, California, United States
$144k-$162k/yr HybridFull Time
Discord
Discord: A platform providing voice, video, and text communication services.
4+ YOE4+ years in security compliance/GRC or related fields; familiarity with ISO 27001/27002,SOC 2,PCI DSS,GDPR/CPRA; hands-on compliance processes; automation-first mindset; strong writing and cross-team collaboration skills.
ISO 27001, ISO 27002, SOC 2, PCI DSS, GDPR, CPRA, GRC platform, ticketing, docs and wikis
1w
Save
Mark Applied
Hide
Sr. Risk Analyst
Scottsdale or Chicago or San Francisco or New York City
$84k-$105k/yr HybridFull Time
Early Warning Services
Early Warning Services: Operates payment and risk solutions for the financial industry.
5+ YOEBachelor's degree in Accounting/Finance/Risk, 5+ years risk experience (3+ in financial services), advanced Microsoft Excel and PowerPoint skills, three-lines-of-defense experience, KRI/GRC familiarity, strong communication.
Microsoft Excel, Microsoft PowerPoint, GRC
2mo
Save
Mark Applied
Hide
Principal Cybersecurity Compliance Analyst
Roseville or Sacramento or Oakland
$150k-$200k/yr HybridFull Time
GFT (Gannett Fleming)
GFT (Gannett Fleming): Provides infrastructure engineering, design, and construction management services.
10+ YOEBachelor's degree, 10+ years in power utility GRC/cybersecurity/OT, deep knowledge of NERC CIP and FERC, experience with audits and compliance documentation, and certification such as CISSP/CISM/RIMS-CRMP required.
GRC, FERC, NERC CIP, SCADA/ICS, NIST CSF, NIST SP 800-53, ISO 27001
1mo
Save
Mark Applied
Hide
Senior Analyst, IT Internal Controls & SOX Compliance
San Francisco or Salt Lake City or Phoenix or Los Angeles or Chicago or Boston or Austin or New York City or Miami or Tampa or Atlanta or Columbus or Boise or San Diego or Minneapolis or Houston or Raleigh or Nashville or Kansas City or Charlotte or Portland or Philadelphia or Dallas or Washington D.C. or Seattle
$113k-$148k/yr RemoteFull Time
Circle
CircleNYSE: CRCL: Digital currency issuer and blockchain financial infrastructure provider.
4+ YOE4+ years Big 4 IT audit/controls experience, Bachelor's in related field, CPA/CISA/CIA/CISSP required; strong SOX/ITGC knowledge, cloud/SaaS/SDLC/IAM experience, ERP/GRC familiarity, and stakeholder communication skills.
Slack, Apple MacOS, Google Workspace, ERP, GRC, AI
3w
Save
Mark Applied
Hide
SENIOR RISK ASSESSMENT ANALYST
Oakland, California, United States
$160k-$184k/yr RemoteFull Time
University of California, Davis
University of California, Davis: A public research university providing higher education and healthcare.
8+ YOE8+ years of relevant experience overseeing enterprise cyber risk assessments; knowledge of NIST, ISO, HIPAA, PCI-DSS; GRC platform familiarity; strong communication, presentation, and project management skills.
ServiceNow, Archer
2mo
Save
Mark Applied
Hide
Security Compliance Analyst, Privacy
San Francisco or New York
$175k-$220k/yr OnsiteFull Time
LangChain
LangChain: Tools for building and deploying production-ready AI agents.
5+ YOE5+ years in privacy/GRC/security compliance; hands-on experience with GDPR, HIPAA, CCPA, SOC 2, ISO frameworks; DPAs/BAAs experience; technical fluency (can read code, validate data flows); strong writing skills.
Python
1mo
Save
Mark Applied
Hide
Governance, Risk & Compliance Analyst
San Francisco, California, United States
$200k-$220k/yr OnsiteFull Time
Perplexity
Perplexity: AI-powered search engine providing conversational answers with citations.
6+ YOE6+ years leading audit and compliance engagements; experience with SOC2/ISO27001/HIPAA, GDPR/CCPA/CPRA; building GRC tooling and automation; strong communication and cross-functional collaboration skills.
3w
Save
Mark Applied
Hide
Senior Risk and Compliance Analyst
Brisbane, California, United States
$145k-$160k/yr OnsiteFull Time
Mytra
Mytra: Develops autonomous robotics for warehouse material flow automation.
Experience in security, compliance, GRC, audit readiness, vendor and customer security reviews; organized, strong written communication, and ability to manage audit evidence and policies.
Vanta GRC
1mo
Save
Mark Applied
Hide
Senior Security Analyst, Customer Assurance
New York City or Seattle or Raleigh or San Francisco or Washington or London or Amsterdam
$134k-$214k/yr HybridFull Time
Plaid
Plaid: Provides financial data connectivity and payment infrastructure via APIs.
6+ YOE6+ years in security assurance/GRC with ownership of customer-facing security workflows; experience reviewing security contract provisions; familiarity with SOC 2, ISO 27001, NIST frameworks, PCI, GLBA, GDPR/CCPA; program design, metrics ownership, and AI-assisted workflow experience.
SOC 2, ISO 27001, NIST CSF, PCI DSS, GLBA, GDPR, CCPA, NIST 800-53
1mo
Save
Mark Applied
Hide
Governance, Risk, Compliance & Trust Analyst
Oakland, California, United States
$140k-$178k/yr HybridFull Time
Everlaw
Everlaw: Provides a cloud-based litigation platform for legal teams.
5+ YOE5+ years GRC experience; strong knowledge of FedRAMP, SOC 2, ISO frameworks; audit readiness, vendor reviews, customer security questionnaires, trust portals, and producing clear, audit-ready deliverables.
FedRAMP, SOC 2, ISO 27001, ISO 27017, ISO 27018, Covey, Covey Scout, Modern Health