Job Profile:
Sr. Security Analyst
Job Description Summary:
We are committed to providing a competitive and equitable total rewards package. The compensation for this role is designed to attract, retain, and motivate top talent.
Job Description:
What's the Role? The Senior Technology Governance, Risk & Compliance (GRC) Analyst plays a critical role in maturing Rate's Technology GRC program by pairing governance, risk and compliance expertise with a forward-leaning approach to automation and AI. This person runs our GRC processes while actively building and maintaining AI-driven tools and agents that increase the speed, consistency, and scale of the GRC function. The analyst partners across Tech (Security, IT and Product) to manage highly cross-functional risk initiatives, and is expected to operate with minimal direction, move fluidly across governance, risk, and compliance workstreams, and deliver accurate work across a fast-moving workload.
Responsibilities GRC Technology & Automation - Identify high-volume, repeatable GRC tasks (evidence collection, control testing, risk scoring, reporting) and build and deploy AI agents or automation workflows to improve efficiency and consistency.
- Maintain, monitor, and iterate on existing AI tools/agents supporting GRC processes, ensuring outputs remain accurate and audit-ready.
- Support the implementation of Rate's GRC platform and provide ongoing platform administration.
- Build and maintain workflows within the GRC platform and propose process updates to improve efficiency and usability.
- Stay current on AI and automation trends relevant to GRC and proactively recommend new use cases.
Risk Management - Plan and execute risk control self-assessments (RCSAs) across Technology domains.
- Evaluate risk evidence and control documentation for completeness, accuracy, and sufficiency.
- Maintain and continuously improve the technology risk register, ensuring risks are logged, scored, tracked, and remediated to schedules.
- Support risk tolerance and risk appetite adjustments as directed by leadership, updating supporting documentation and communicating changes to stakeholders.
- Provide guidance to Tech teams (Security, Product, and IT) on risk remediation planning and prioritization.
Compliance & Controls Management - Create, update, and maintain Technology policies and standards.
- Support the ongoing management of IT General Controls (ITGCs) and other relevant control requirements.
- Support internal and external Technology audit processes, including evidence gathering, walkthroughs, and issue remediation tracking.
- Support ongoing alignment with applicable frameworks and regulatory requirements (e.g., NIST, SOC 2).
GRC Metrics & Data Analysis - Build, maintain, and interpret data sets that feed Technology GRC metrics, KPIs, and KRIs.
- Translate raw Technology risk and compliance data into clear, actionable reporting for stakeholders and leadership.
- Continuously refine metrics and dashboards to reflect evolving program priorities and risk tolerance.
- Ensure data integrity and accuracy across GRC platforms and reporting tools.
Cross-Team Program & Project Management - Lead and coordinate cross-team Tech risk and compliance initiatives involving Technology, Security, and Product.
- Manage competing priorities and timelines across multiple concurrent GRC workstreams with minimal oversight.
- Serve as a primary point of contact for stakeholders on assigned Tech risk, compliance, and audit initiatives.
- Coordinate with GRC personnel to maintain a shared, program-level view of risk, compliance, and audit activity, ensuring consistency across workstreams.
- Communicate progress, risks, and roadblocks clearly and proactively to leadership.
Qualifications - 4-6 years of experience in Technology, Security, Audit, Compliance, or GRC roles.
- Demonstrated experience using or building AI/automation tools (e.g., scripting, AI agents, etc) to improve process efficiency; hands-on comfort with AI platforms strongly preferred.
- Strong working knowledge of common control frameworks (NIST, SOC 2, etc.).
- Proven ability to manage cross-functional projects and stakeholders with minimal supervision.
- Strong data and analytical skills; experience building and maintaining metrics/dashboards from large or complex data sets.
- Comfortable evaluating risk evidence and control documentation for completeness and accuracy.
- Ability to deliver precise, high-quality work across a high-volume, fast-moving workload.
- Highly self-directed; able to prioritize and execute independently.
- Comfortable operating across multiple GRC disciplines (risk, compliance, audit, metrics) and shifting priorities fluidly.
- Strong documentation skills, with the ability to produce clear, audit-ready documentation.
- High attention to detail.
- Excellent written and verbal communication skills; able to engage stakeholders at all levels.
Reporting & StructureReports to: VP, Operational Resilience & Technology Risk
Cross-functional partners: Security, Product, and IT
Other Useful Details Employee Type: Full-Time
Pay Range: annual pay + bonus and/or commissions
Location: Remote
The company offers a comprehensive benefits program to eligible employees, including eligibility to participate in a company-sponsored 401(k); vacation benefits; eligibility for medical, dental, vision, and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; critical care insurance; personal accidental insurance; commuter benefits; pet insurance; certain time off and leave of absence benefits; well-being benefits (e.g., employee assistance program); and other supplemental benefits (e.g. legal planning assistance; identity theft protection; pet insurance; wellness resources). Please click this link to learn more about our benefit offerings for Washington State: https://www.rate.com/careers/open-positions/disclosures