28 grc analyst jobs at 26 companies in North Babylon, NY
1mo
Save
Mark Applied
Hide
1mo
GRC Analyst
New York, New York, United States
$200k-$270k/yrOnsiteFull Time
Fluidstack: Provides high-performance cloud GPU infrastructure for AI development.
Experienced in operating compliance controls and audits across SOC 2, ISO 27001, NIST 800-53 or FedRAMP; owning policy sets, evidence collection, and audit readiness on GRC platforms.
Los Angeles or Chicago or Nashville or New York or Seattle
$100k-$135k/yrHybridFull Time
Metropolis: Computer vision technology for checkout-free parking and retail payments.
3+ YOE3+ years in information security GRC or technology compliance; experience managing security awareness programs; knowledge of SOC 2 and PCI-DSS; familiarity with AI/data security and training platforms; bachelor\u0002s degree required.
PSEGNYSE: PEG: Investor-owned electric and gas utility.
4+ YOEBachelor's in related field or 8+ years' equivalent; 4+ years cybersecurity GRC/IT audit experience; proficiency with Cyber GRC tools; experience with risk and control assessments, audit coordination, and remediation tracking; DOE 10 CFR 810 eligibility.
Bengaluru or New York City or Washington or Vancouver or London or Galway or Budapest or Munich or Singapore or Sydney
HybridFull Time
Diligent: Private GRC SaaS providing governance, risk, compliance, audit, and ESG software to boards and organizational leaders.
2+ YOERequires 2–4 years in security GRC, compliance, IT audit, or customer assurance; SOC 2 and ISO 27001 knowledge; precise SLA-driven work; strong written English; queue management; and AI-assisted tooling experience.
San Francisco or Denver or New York City or Scottsdale or San Jose
$183k-$205k/yrHybridFull Time
Gusto: Gusto is a payroll, benefits, and human-resources software platform serving small and medium-sized businesses.
8+ YOE8+ years in governance, risk, and compliance within SaaS; bachelor's degree required; SOC 2 Type 2 experience; strong communication, analytics, and compliance platform skills; relevant certification preferred.
AdobeNASDAQ: ADBE: Provides software for digital media creation and marketing analytics
5+ YOE5+ years GRC/InfoSec experience, knowledge of SOC/ISO/HIPAA/FedRAMP/NIST frameworks, program and audit leadership, strong communication and analytical skills.
AWS, Azure, GCP, Adobe Common Controls Framework (CCF)
Veterinary Emergency Group: Operates a network of 24/7 emergency veterinary hospitals.
3+ YOERequires 3+ years in GRC, IT audit, compliance, or related security work; knowledge of a security or compliance framework; GRC platform experience; and strong documentation and communication skills.
PCI DSS, NIST, SOC 2, ISO 27001, Hyperproof, Archer, OneTrust
YipitData: Private market intelligence and alternative-data analytics firm serving institutional investors, retailers, brands, and enterprises.
Experience in security, compliance, risk, audit, privacy, or vendor risk; familiarity with SOC 2, NIST CSF, or similar frameworks; strong writing, organization, communication, and follow-through skills.
InfosysNYSE: INFY: Provides IT consulting, software development, and business outsourcing services.
Experience in financial services GRC/risk/regulatory domains, requirement gathering, process mapping, BRD/FRD creation, SQL and Agile familiarity, knowledge of GRC tools (Archer, IBM OpenPages), bachelor\u0002s degree or equivalent, U.S. work authorization required.
Aaru: AI platform for predictive human behavior simulation.
3+ YOERequires 3–5 years in GRC, security compliance, or IT audit; SOC 2 knowledge; familiarity with ISO 27001 and related frameworks; GRC platform experience; and strong communication and process-building skills.
Vanta, Drata, OneTrust, SOC 2, ISO 27001, NIST CSF, HIPAA, PCI-DSS, ISO 42001, NIST AI RMF, EU AI Act, GDPR, Python, JavaScript, CISA, CRISC, CISM
The Estée Lauder CompaniesNYSE: EL: Manufactures and markets prestige skincare, makeup, and fragrance products.
Experienced application security professional versed in SDLC/DevSecOps, vulnerability assessment (SAST/DAST/IAST), threat modeling, CI/CD and cloud/container security; strong programming/scripting skills and ability to mentor teams.
Estée Lauder CompaniesNYSE: EL: Manufacturer and marketer of prestige beauty and skincare products.
Experience in application security, secure SDLC, vulnerability assessment (SAST/DAST/IAST), threat modeling, CI/CD and cloud/container security, strong programming/scripting skills, and ability to consult across technical teams.
Scottsdale or Chicago or San Francisco or New York City
$84k-$105k/yrHybridFull Time
Early Warning Services: Operates payment and risk solutions for the financial industry.
5+ YOEBachelor's degree in Accounting/Finance/Risk, 5+ years risk experience (3+ in financial services), advanced Microsoft Excel and PowerPoint skills, three-lines-of-defense experience, KRI/GRC familiarity, strong communication.
Carlsbad or San Jose or North America or New York City
$147k-$232k/yrOnsiteFull Time
ViasatNASDAQ: VSAT: Provider of global satellite-based connectivity and secure communication solutions.
8+ YOERequires 8+ years in risk and compliance and working with ISO27001:2022, ISMS Lead Auditor or Lead Implementor certification, GRC tool experience, security knowledge, and strong analytical, communication, and project skills.
ISO27001:2022, GRC, ISO27001 ISMS, ISO27001 Annex A, PCI DSS, NIST SP 800-171, CMMC, IT SOX
Bengaluru or Pune or New York City or United Kingdom or Finland or Singapore or Canada or Ireland
OnsiteFull Time
AlphaSense: AI-powered market intelligence and enterprise search platform.
2+ YOEIAPP AIGP certified; 2+ years in risk/GRC/compliance or audit with exposure to AI governance; familiarity with EU AI Act, NIST AI RMF, ISO standards; experience with GRC tooling; strong written/verbal English.
EU AI Act, NIST AI RMF, ISO/IEC 42001, ISO/IEC 27001
OTG: Operates dining and retail locations in airport terminals.
3+ YOEBachelor’s degree or equivalent experience, 3–5 years in IT security, compliance, or audit, and hands-on PCI DSS experience. Knowledge of AWS, network security, GRC tools, and payment environments preferred.
Advance Local: Privately held U.S. local media group operating news outlets, marketing agencies, and technology businesses for communities and clients.
5+ YOEBachelor's degree, 5+ years in GRC/data governance or related role, experience leading cross-discipline teams, proficiency in SQL, data analysis and reporting, strong communication, metadata and privacy knowledge.
Senior Analyst, IT Internal Controls & SOX Compliance
San Francisco or Salt Lake City or Phoenix or Los Angeles or Chicago or Boston or Austin or New York City or Miami or Tampa or Atlanta or Columbus or Boise or San Diego or Minneapolis or Houston or Raleigh or Nashville or Kansas City or Charlotte or Portland or Philadelphia or Dallas or Washington D.C. or Seattle
$113k-$148k/yrRemoteFull Time
CircleNYSE: CRCL: Digital currency issuer and blockchain financial infrastructure provider.
4+ YOE4+ years Big 4 IT audit/controls experience, Bachelor's in related field, CPA/CISA/CIA/CISSP required; strong SOX/ITGC knowledge, cloud/SaaS/SDLC/IAM experience, ERP/GRC familiarity, and stakeholder communication skills.
Slack, Apple MacOS, Google Workspace, ERP, GRC, AI
Snorkel AI: Software platform for programmatic AI data development and labeling.
2+ YOERequires 2–5 years in technical compliance, IT audit, or GRC; SOC 2 Type I/II and ITGC audit expertise; cloud, IAM, CI/CD, encryption, vulnerability management, and Vanta, Drata, Jira, and KnowBe4 experience.