Doppler

Senior GRC Analyst

Doppler$100K — $130K *
US-AnywhereRemote in United States
Enterprise Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in security, compliance, or GRC with ownership of SOC 2 Type II and ISO 27001 in a cloud context
  • Hands-on experience with Vanta or similar GRC platform
  • Technical fluency with ability to read pen test reports and discuss risk with engineers
  • Strong understanding of auditor perspectives from prior experiences
  • Familiarity with PCI DSS and GDPR, and relevant certification processes
  • Experience with enterprise sales support focusing on security compliance
  • Excellent communication skills tailored to diverse audiences

Responsibilities

  • Own and maintain SOC 2 Type II and ISO 27001 certifications, including audits and evidence collection
  • Lead compliance efforts for additional certifications through gap assessments and policy updates
  • Manage GRC platform daily, including control mapping and audit preparations
  • Drive security working group initiatives for risk identification and policy updates
  • Design and implement security controls aligned with chosen frameworks
  • Oversee penetration testing and remediation of findings with engineering
  • Engage in customer security discussions, representing compliance posture credibly

Benefits

  • Equity at an early-stage startup
  • Comprehensive health insurance including medical, dental, and vision
  • Guilt Free Unlimited PTO with a strong encouragement for a minimum of 3 weeks
  • Opportunities for upward mobility
  • Learning and Development Stipend for professional growth
  • Access to a Wealth Advisor for financial planning
  • 401k retirement plan
  • Family leave benefits including pregnancy and adoption support
  • Commitment to equal compensation across gender and race
Full Job Description
The Role

At Doppler, security is core to what we ship, not an afterthought - it's woven into our product. Customers come to us to be the trusted custodian of their most sensitive credentials: API keys, database passwords, service tokens. That means our compliance posture is something prospects scrutinize during procurement and something customers depend on to justify their trust. This role owns all of it.

As our Senior GRC Analyst, you'll be the owner of Doppler's security and compliance program; maintaining our SOC 2 Type II and ISO 27001 certifications, driving our next compliance initiatives, and acting as the internal expert and external face of security for enterprise customers. You'll work closely with engineering, product, sales, and customer success, and you'll bring an automation-first mindset to everything, building systems that reduce manual toil and move us toward continuous compliance rather than point-in-time audits.

This is an individual contributor role with meaningful company-wide impact. The person who thrives here is equally comfortable diving into a pen test report with engineers and presenting risk posture to leadership.

What you'll do:

Compliance program ownership
  • Maintain Doppler's SOC 2 Type II and ISO 27001 certifications end-to-end: evidence collection, control monitoring, audit coordination, and deficiency remediation
  • Lead the compliance work for our next certifications, including gap assessments, policy updates, and required documentation
  • Evaluate additional certifications and attestations on an ongoing basis as customer and market requirements evolve
  • Own day-to-day administration of our GRC platform (Vanta), including control mapping, evidence workflows, and audit readiness

Risk and controls
  • Lead our security working group: facilitate regular risk identification sessions, policy updates, maintain the threat register, track remediation progress, and drive accountability across teams
  • Design and maintain security controls mapped to our chosen frameworks (SOC 2, ISO 27001, etc.), ensuring they're practical and consistently operating
  • Coordinate penetration testing cycles and work directly with engineering to track and close findings
  • Author and maintain security policies that are enforceable and grounded in regulatory requirements (GDPR, PCI, and others relevant to a secrets management provider)
  • Support business continuity and disaster recovery governance

Customer and sales enablement
  • Respond to security questionnaires and RFPs promptly and accurately. Doppler's customers are technical and expect precision
  • Participate in customer security reviews and calls; represent our compliance posture credibly to security teams, procurement, and compliance officers
  • Maintain public-facing trust documentation that reflects our actual program
  • Partner with sales on security-sensitive enterprise deals, especially in regulated industries or where compliance is a gating factor

Enablement and communication
  • Translate compliance status and risk posture into clear, non-jargon updates for leadership and cross-functional stakeholders
  • Lead security awareness and compliance training for internal teams
  • Influence engineering and product roadmaps where security controls intersect with product decisions


What you'll bring to the table:
  • 5+ years in security, compliance, or GRC, with direct ownership of SOC 2 Type II and ISO 27001 programs in a cloud product environment where you've run audit cycles, not just supported them
  • Hands-on experience with Vanta (or a comparable GRC platform) and a genuine interest in automating compliance workflows rather than relying on spreadsheets
  • Technical fluency: you can read a pen test report, understand cloud architecture decisions, and have substantive conversations with engineers about control design and risk tradeoffs
  • Strong understanding of how auditors think, ideally from having been on the auditor side, or from running enough cycles that you've internalized their perspective
  • Familiarity with PCI DSS and GDPR requirements; experience with self-attestation or certification work is a strong plus
  • Experience supporting enterprise sales cycles where security is a procurement requirement, including responding to complex security questionnaires
  • Excellent communication skills across audiences. You can brief the CEO on risk posture and turn around and explain the same issue to an engineer in implementation terms
  • Relevant certifications (CISA, CISSP, CISM, CRISC, or equivalent) preferred


Preferred experience:
  • Startup or high-growth environment experience
  • Experience with developer tools or infrastructure security background
  • Experience with trust center management
  • Familiarity with secrets management, credential security, or PKI.
Benefits
  • Equity at an early-stage, fast-growing startup
  • Premium health insurance (medical, dental, vision)
  • Guilt Free Unlimited PTO - 3-week minimum strongly encouraged!
  • Upward Mobility
  • Learning and Development Stipend
  • Wealth Advisor
  • 401k
  • Pregnancy & Family Leave
  • Fertility & Adoption Benefits
  • Equal Compensation (regardless of gender or race)

For a full list of our benefits check our Perks Notion Page.

About Doppler

Doppler is an email marketing platform that allows businesses to create, send, and track email campaigns. The company was founded in 2007 in Buenos Aires, Argentina, and has since expanded to other countries in Latin America and Europe. Doppler's platform includes features such as email automation, segmentation, and A/B testing. The company serves a variety of industries, including e-commerce, travel, and media.
Learn more about Doppler
Size
50 employees
Industry

Similar Jobs

More Jobs at Doppler

  • Doppler
    Senior GRC Analyst
    $100K — $130K *
    Remote
    Enterprise Technology
    Remote in United States
  • Doppler
    Account Executive
    $220K — $250K *
    Remote
    Enterprise Technology
    Remote in United States

More Enterprise Technology Jobs

Find similar Senior GRC Analyst jobs: