Governance, Risk, Complaince (GRC) Analyst

Aaru

$100K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years in GRC, security compliance, or IT audit, preferably in enterprise environments.
  • Familiarity with SOC 2, ISO 27001, NIST CSF, HIPAA, or PCI-DSS standards.
  • Experience with automation tools like Vanta, Drata, or OneTrust.
  • Practical experience with AI tools for work tasks such as drafting and evidence review.
  • Strong writing skills for diverse audiences, from engineers to sales teams.
  • Capability to design processes in unstructured environments.

Responsibilities

  • Own customer trust and enterprise security reviews, including security questionnaire responses.
  • Manage audit processes, acting as a liaison for external auditors.
  • Conduct control testing, access reviews, and manage remediation efforts.
  • Govern policies and automate evidence collection in the GRC platform.
  • Oversee the vendor risk lifecycle, including assessments and risk scoring.
  • Manage AI governance processes and collaboration with engineering and legal teams.

Benefits

  • Comprehensive medical, vision, and dental coverage.
  • Visa sponsorship and relocation support.
  • Additional various perks to support employee well-being.
Full Job Description
ABOUT THE ROLE

Aaru is building out its governance, risk, and compliance function and is hiring its first dedicated GRC Analyst to own it.

Our customers are large enterprises that use Aaru to pressure-test high-stakes decisions before they make them. They hold us to a serious standard on how we handle their data and how our systems are controlled, and every deal we sign runs through that scrutiny. Because of what we build, that scrutiny goes further than it does for most software vendors - into how our models are trained, how personal data does and does not inform agent construction, and how simulated outputs relate to real individuals.

You will own that surface end to end: enterprise security review, audit readiness, evidence and policy governance, vendor risk, and AI governance. This is a build role rather than a maintenance one. You will not be inheriting a legacy program, and you will be expected to automate the work rather than absorb it.

RESPONSIBILITIES
  • Customer trust and enterprise security review. Own the response to security questionnaires, due diligence requests, and RFP security sections, and represent Aaru's security posture directly in customer security conversations and vendor risk reviews. Build and maintain a canonical answer library so the same questions are never solved twice.
  • Audit management. Serve as primary point of contact for external auditors across readiness, fieldwork, and surveillance cycles. Manage RFI response, control walkthroughs, and finding remediation to closure.
  • Control testing and monitoring. Run recurring control checks, access reviews, and periodic testing. Document effectiveness, identify gaps, and drive remediation with owners on defined timelines.
  • Policy and evidence governance. Keep policies current, versioned, distributed, and attested. Automate evidence collection in our GRC platform so that artifacts are generated by integration rather than gathered by hand.
  • Third-party risk. Build and manage the vendor assessment lifecycle: questionnaires, SOC 2 and ISO review, risk scoring, and policy enforcement across procurement and renewals.
  • AI governance. Own how Aaru answers for the governance of its own models and agents, working alongside engineering, product, and legal.


YOU MAY BE A FIT IF
  • You have 3-5 years in GRC, security compliance, or IT audit, ideally at a company selling into enterprise. Big 4 and specialist assurance backgrounds are well suited to this role.
  • You have working knowledge of SOC 2 and familiarity with ISO 27001, NIST CSF, HIPAA, or PCI-DSS.
  • You have used Vanta, Drata, OneTrust, or similar to automate evidence collection and manage controls, and you default to building a workflow over doing the task by hand.
  • You use AI tools for substantive work - drafting, research, gap analysis, evidence review - and you have a clear practice of validating output before it ships.
  • You have supported live sales cycles through security review, and you believe this function should never be the reason a deal slips.
  • You write with precision, and can explain a control requirement to an engineer, a customer's security team, and a commercial buyer without changing the substance.
  • You build repeatable process in environments where the process does not yet exist and you are expected to propose one.


STRONG CANDIDATES MAY ALSO
  • Have taken a company through a first SOC 2 Type II or ISO 27001 certification and know what tends to break.
  • Have worked with AI governance frameworks such as ISO 42001, NIST AI RMF, or the EU AI Act, or have answered hard diligence questions about model training data and provenance.
  • Have supported regulated financial services or public sector procurement and the documentation burden that comes with it.
  • Have handled multi-jurisdiction privacy and data residency questions, including US state privacy law, GDPR, and Singapore's PDPA.
  • Read architecture documentation comfortably and ask good questions of engineers about how a control actually works.
  • Script or automate - Python, JavaScript, or low-code - applied to compliance workflows.
  • Hold CISA, CRISC, CISM, or ISO 27001 Lead Auditor / Lead Implementer.


LOCATION

This role is based in New York City. Aaru is an in-person company, working 5 days a week in office. Candidates are expected to be located within the New York City metropolitan area or open to relocation.

BENEFITS

At Aaru, we take care of our people. In addition to a competitive base salary and equity participation, we offer comprehensive medical, vision, and dental coverage, visa sponsorship and relocation support, and various other benefits and perks.

Similar Jobs

More Jobs at Aaru

More Information Technology Jobs

Find similar Governance, Risk, Complaince (GRC) Analyst jobs: