RainFocus

Senior Governance, Risk, and Compliance (GRC) Analyst (Remote)

RainFocus$110K — $130K *
Orem, UT 84057In-Person
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Technology, Cybersecurity, or related field
  • 6+ years of experience in GRC, IT audit, or information security compliance
  • In-depth knowledge of SOC 2, ISO 27001, PCI DSS, NIST 800-series, GDPR
  • Experience conducting formal risk assessments beyond compliance checklists
  • Professional certifications like CISA, CRISC, CISSP, CIPP, or CIPM are preferred
  • Familiarity with security tools such as Drata, OneTrust, Vanta
  • Strong analytical, problem-solving, and communication skills

Responsibilities

  • Lead the GRC program across various compliance frameworks including SOC 2 and ISO 27001
  • Manage and enhance the control framework through gap assessments
  • Conduct the annual security risk assessment using NIST SP 800-30 methodology
  • Update security policies and documentation to adhere to industry best practices
  • Collaborate with Engineering and Security to improve vulnerability management
  • Develop and operationalize the Data Loss Prevention program
  • Drive initiatives for AI governance and manage risks related to AI tools

Benefits

  • Significant ownership of the GRC program from the onset
  • Direct reporting to the CISO
  • Opportunity to lead the maturity of a compliance program
  • Collaboration with cross-functional teams
  • Engagement with emerging security threats and compliance updates
  • Access to modern security tools and frameworks
  • Development and enhancement opportunities in security practices
Full Job Description
We are seeking a highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team. In this role, you will own and grow RainFocus's governance, risk, and compliance program - maintaining our control framework, leading risk assessments, supporting audits, and driving the program's maturity forward rather than simply maintaining the status quo. You will report directly to the CISO and have significant ownership from day one.

Key Responsibilities:

Lead RainFocus's GRC program across SOC 2, ISO 27001, PCI DSS, and other client/regulatory compliance frameworks, including audit prep, evidence collection, and auditor relationships.

Manage and mature our control framework, mapping new regulations and conducting gap assessments.

Own the annual security risk assessment process (NIST SP 800-30 methodology), including stakeholder interviews, risk scoring, and residual risk tracking.

Maintain and update security policies, standards, and documentation to ensure compliance with industry best practices.

Partner with Engineering and Security to mature vulnerability management and secrets-scanning practices, moving these from reactive to proactive, pre-deployment controls.

Help build out and operationalize a Data Loss Prevention (DLP) program, including policy design and rollout across email, endpoint, and cloud storage.

Grow and mature RainFocus's security awareness training program.

Drive AI governance efforts - policy, tooling, and monitoring for approved vs. unapproved AI tool usage across the company.

Identify and help close Shadow IT / unmanaged SaaS visibility gaps in partnership with IT.

Collaborate with cross-functional teams to implement risk management practices and ensure compliance across the organization.

Respond to security and privacy inquiries from clients, partners, and employees.

Prepare and present reports on the organization's security and privacy compliance status, including program maturity and remediation progress.

Stay abreast of emerging security threats, vulnerabilities, and compliance requirements.

Qualifications:

Bachelor's degree in Technology, Cybersecurity, or a related field is highly desirable.

6+ years of proven experience in GRC, IT audit, information security compliance, or a related field.

In-depth knowledge of relevant regulations, standards, and frameworks (e.g., SOC 2, ISO 27001, PCI DSS, NIST 800-series, GDPR, and others).

Experience running or contributing heavily to formal risk assessments - not just tracking a compliance checklist.

Professional certifications such as CISA, CRISC, CISSP, CIPP, or CIPM are highly desirable.

Familiarity with modern security tooling such as Drata, OneTrust, Vanta, etc.

Strong analytical and problem-solving skills, with keen attention to detail.

Excellent communication and interpersonal skills to work effectively with technical and non-technical stakeholders.

Ability to manage multiple projects and meet deadlines in a fast-paced environment.

Experience with cloud security and compliance frameworks is a plus.

Experience with OneTrust or related GRC technologies is a plus.

Personal Characteristics:

Strong work ethic and commitment to excellence.

Ability to work independently and as part of a team.

Excellent problem-solving and analytical skills.

Strong communication and interpersonal skills.

Ability to adapt to change and learn quickly.

Passion for security and privacy.

About RainFocus

RainFocus is a software company that provides a cloud-based event management platform. The platform offers a suite of tools for event planning, registration, and management, as well as analytics and reporting features. RainFocus serves a variety of industries, including technology, healthcare, finance, and education. The company was founded in 2014 and is headquartered in Riverton, Utah.
Learn more about RainFocus
Size
300 employees
Industry
Founded
2013

Similar Jobs

More Jobs at RainFocus

More Information Technology Jobs

Find similar Senior Governance, Risk, and Compliance (GRC) Analyst (Remote) jobs: