Gusto

Senior GRC Analyst

Gusto$183K — $205K *
Enterprise Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in governance, risk, and compliance within SaaS, ideally in HCM, payroll, or fintech sectors.
  • Bachelor's degree in Business, Information Systems, or a related field.
  • Strong understanding of SaaS business models with experience in fast-paced environments.
  • Proven experience leading SOC 2 Type 2 compliance initiatives.
  • Familiarity with compliance tools such as Optro, Vanta, Drata, or Viso Trust.
  • Excellent communication skills to educate and influence stakeholders.
  • Relevant professional certifications (CISA, CRISC, or GRCP preferred).

Responsibilities

  • Develop and maintain security and compliance SOPs and company-wide policies.
  • Manage trust management platforms and implement AI for controls framework.
  • Collaborate with teams to establish data governance policies.
  • Conduct internal risk assessments and coordinate remediation plans.
  • Manage vendor risk program including onboarding and monitoring.
  • Lead interactions with external auditors during compliance assessments.
  • Stay updated on compliance frameworks and regulations.
  • Partner cross-functionally to implement scalable GRC processes.

Benefits

  • Physical office spaces in major cities (Denver, San Francisco, New York City).
  • Hybrid work model with 2-3 days in the office per week.
  • Emphasis on a diverse and inclusive workplace culture.
Full Job Description
About the Role:

Gusto is seeking a Security, Governance, Risk & Compliance professional to join our team managing our security governance, risk and compliance initiatives. This person will guide the company from foundational Governance, Risk & Compliance (GRC) maturity through to steady-state operations, leveraging AI to automate and improve old practices and tools, ensuring ongoing compliance with SOC 2 Type 2, IT General Controls, ICOC and related frameworks, while embedding security-minded practices throughout Gusto. This is a cross-functional role with key touchpoints in every department.

Here's what you'll do day-to-day:
  • Develop, maintain, and ensure adherence to security and compliance SOPs, internal documentation, and company-wide policies-particularly supporting SOC 2 and future framework adoption.
  • Own and manage trust management platforms including documentation of controls, risks, vendors, and exceptions, and lead the implementation of AI agents to automate and improve the implementation of our controls framework and evidence collection to support it
  • Collaborate with Legal, Enterprise Applications, and Gusto counterparts to establish and maintain data governance policies (e.g., classification, retention, handling).
  • Conduct ongoing internal risk assessments to identify exposure and control gaps; coordinate remediation plans with functional teams.
  • Manage the third-party vendor risk program, including onboarding reviews, monitoring, and renewal assessments.
  • Lead interactions with external auditors and regulatory bodies during compliance assessments (e.g., SOC 2 Type 2) and oversee responses to client security assessments and due diligence requests.
  • Stay current on relevant compliance frameworks, laws, and regulations to ensure appropriate coverage and adaptability.
  • Partner cross-functionally (e.g., Security, Legal, Engineering, Sales, IT) to implement scalable GRC processes, harmonize systems, and foster GRC understanding through employee enablement programs and KPI-driven insights.

Here's what we're looking for:
  • 8+ years of experience in governance, risk, and compliance within SaaS, ideally in the HCM, payroll, or fintech sectors.
  • Bachelor's degree in Business, Information Systems, or a related field.
  • Strong understanding of SaaS business models, with experience implementing controls and policies in fast-paced, product-driven environments.
  • Proven experience leading or supporting a SOC 2 Type 2 compliance initiative, including collaboration with auditors and cross-functional teams.
  • Familiarity with compliance tools and platforms such as Optro, Vanta, Drata, Viso Trust, or similar.
  • Demonstrated ability to translate complex GRC requirements into actionable, scalable processes.
  • Excellent written and verbal communication skills, including the ability to educate and influence cross-functional stakeholders.
  • A data-informed mindset, with the ability to use analytics to assess GRC performance and maturity.
  • One or more relevant professional certifications:
    • CISA, CRISC, or GRCP preferred
    • CGEIT, CRMA, or PMI-RMP are a bonus

Our cash compensation amount for this role is targeted at $183,000-205,000 in the San Francisco Bay Area. Stock equity is additional. Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above.

Gusto has physical office spaces in Denver, San Francisco, and New York City. Employees who are based in those locations will be expected to work from the office on designated days approximately 2-3 days per week (or more depending on role). The same office expectations apply to all Symmetry roles, Gusto's subsidiary, whose physical office is in Scottsdale.

Note: The San Francisco office expectations encompass both the San Francisco and San Jose metro areas.

When approved to work from a location other than a Gusto office, a secure, reliable, and consistent internet connection is required. This includes non-office days for hybrid employees.

Our customers come from all walks of life and so do we. We hire great people from a wide variety of backgrounds, not just because it's the right thing to do, but because it makes our company stronger. If you share our values and our enthusiasm for small businesses, you will find a home at Gusto.

About Gusto

Gusto is a cloud-based human resources software platform that provides payroll, benefits, and HR management services to small businesses. The company was founded in 2011 and is headquartered in San Francisco, California. Gusto's platform automates many of the administrative tasks associated with HR, such as payroll processing, tax filings, and benefits administration. The company also offers a range of HR services, including compliance support, employee onboarding, and time tracking. Gusto is committed to helping small businesses succeed by providing them with the tools and resources they need to manage their HR operations more efficiently.
Learn more about Gusto
Size
1,000 employees
Industry
Founded
2012

Similar Jobs

More Jobs at Gusto

  • Gusto
    Senior GRC Analyst
    $183K — $205K *
    San Francisco, CA 94112 (San Francisco County)
    Enterprise Technology
    Hybrid
  • Gusto
    GTM AI Agent Builder
    $222K — $242K *
    New York, NY 10025 (New York County)
    Business Services
    In-Person
  • Gusto
    GTM AI Agent Builder
    $189K — $242K *
    Remote
    Business Services
    Remote
  • Gusto
    GTM AI Agent Builder
    $189K — $205K *
    Atlanta, GA 30349 (Fulton County)
    Business Services
    In-Person
  • Gusto
    GTM AI Agent Builder
    $222K — $242K *
    San Francisco, CA 94112 (San Francisco County)
    Business Services
    Hybrid

More Enterprise Technology Jobs

Find similar Senior GRC Analyst jobs: