IXL Learning

Associate GRC Security Analyst

IXL Learning$80K — $105K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or related field
  • 1-3 years of experience in GRC, IT audit, compliance, or risk management
  • Familiarity with compliance frameworks like SOC2, PCI-DSS, NIST, ISO 27001, and GovRAMP
  • Experience in SOC2 Type 2 and/or PCI-DSS audits
  • Exposure to vendor risk assessments and third-party risk management
  • Strong organizational skills for documentation management
  • Excellent communication skills for cross-team collaboration

Responsibilities

  • Gather and maintain evidence for internal and external audits
  • Administer the GRC platform and manage compliance documentation
  • Conduct vendor risk assessments for third-party evaluations
  • Execute risk assessments and maintain the risk register
  • Support security awareness training programs
  • Assist with phishing simulation campaign planning and reporting
  • Map controls across compliance frameworks

Benefits

  • Opportunity to build hands-on experience in GRC and risk management
  • Cross-training with experienced security team members
  • Location in the vibrant tech hub of San Mateo, CA
Full Job Description
In this role you will support IXL's internal cybersecurity governance, compliance, and audit program by gathering evidence, performing vendor risk assessments, conducting risk assessments, and maintaining audit-ready documentation. You will also contribute to security awareness training and phishing simulation programs and cross-train with and support other members of the security team. This role is a great fit for someone early in their GRC career who is eager to build hands-on experience across multiple compliance frameworks and risk management disciplines.

This position requires you to be in our San Mateo, CA, headquarters office.
WHAT YOU'LL BE DOING
  • Support internal and external audits by gathering, organizing, and maintaining evidence in a timely and accurate manner
  • Support the operation, implementation, and administration of the team's GRC platform, including compliance documentation management and reviews, attestations, workflow configuration, user management, and data integrity maintenance
  • Perform vendor risk assessments to evaluate third-party security posture and compliance alignment
  • Conduct risk assessments and contribute to maintaining the organization's risk register and open findings tracking
  • Support security awareness training programs including content coordination, participation tracking, and reporting
  • Assist with planning, execution, and results reporting for phishing simulation campaigns
  • Map and cross-reference controls across multiple compliance frameworks such as SOC2, PCI-DSS, GovRAMP, and NIST
  • Maintain audit-ready documentation, policy version control, and evidence repositories year-round
  • Track and manage security exceptions through their full lifecycle including intake, approval, and expiration
  • Assist identifying, building and reporting on GRC-specific metrics for leadership
  • Cross-train with and support other members of the security team as needed
WHAT WE'RE LOOKING FOR
  • Bachelor's degree, preferably in Computer Science, Cybersecurity, Information Systems, or a related field
  • 1-3 years of experience in GRC, IT audit, compliance, risk management, or a related field
  • Familiarity with common compliance frameworks such as SOC2, PCI-DSS, NIST, ISO 27001, or GovRAMP
  • Previously supported audits pertaining to SOC2 Type 2 and/or PCI-DSS (Level 1 or hands-on SAQs)
  • Experience with or exposure to vendor risk assessment processes and third-party risk management
  • Strong attention to detail with the ability to organize and manage documentation and evidence across multiple workstreams
  • Excellent written and verbal communication skills with the ability to work across technical and non-technical teams
  • Comfort working in a fast-paced environment and managing multiple priorities simultaneously
  • Relevant certifications such as CompTIA Security+, CISA, or GRCP are a plus
  • Familiarity with GRC platforms like Vanta or Auditboard, or ticketing tools such as Jira is a plus

Our salary ranges are determined by role, level, and location. The base salary range for this full-time position is $80,000 to $105,000 + benefits. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position. Individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

About IXL Learning

IXL Learning is an education technology company that provides personalized learning experiences for students in grades K-12. The company was founded in 1998 and is headquartered in San Mateo, California. IXL Learning offers a variety of products, including IXL, a comprehensive learning platform that covers math, language arts, science, and social studies, as well as other products for specific subjects and grade levels. The company's products are used by millions of students and teachers around the world. IXL Learning is committed to providing high-quality educational resources that help students achieve their full potential.
Learn more about IXL Learning
Size
1,000 employees
Industry
Founded
1998
NASDAQ

Similar Jobs

More Jobs at IXL Learning

More Information Technology Jobs

Find similar Associate GRC Security Analyst jobs: