Upwind Security Logo

Upwind Security

GRC Analyst

Posted 3 Days Ago
Remote
Hiring Remotely in US
Mid level
Remote
Hiring Remotely in US
Mid level
The GRC Analyst will operate and improve security compliance programs across SOC 2, ISO 27001, NIST, and FedRAMP. Responsibilities include risk and control assessments, audit readiness, evidence collection, remediation tracking, policy management, third-party risk, customer security questionnaires, and maintaining GRC systems. The role partners with technical and business teams, researches requirements, and uses cloud-based tools, AI, and automation to make compliance processes more scalable.
The summary above was generated by AI
Description

About Upwind

Upwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical risks, providing precise insights and efficient cloud security management. With industry-leading efficiency and eBPF-powered sensors, Upwind delivers comprehensive capabilities including agentless cloud posture discovery, real-time threat protection, and integrated API security. We are one of the fastest-growing companies in cloud and AI security, and we're building the GTM engine to match.

The Opportunity

We are looking for a motivated and resourceful GRC Analyst to join our growing Security & Compliance team.

This is a hands-on role for someone who enjoys solving problems, takes ownership of their work, and is comfortable operating in a fast-paced environment where processes are continuously evolving and improving. We are looking for someone who is curious, willing to dig into unfamiliar topics, and comfortable finding practical ways to solve compliance and security challenges.

The GRC Analyst will support our core GRC functions - including risk assessments, internal audits, policy governance, third-party risk, customer trust and assurance, and compliance programs - while also serving as a practical partner to teams across the company. This role should be able to move beyond identifying a gap or requirement and help teams understand what good remediation looks like and how to build sustainable processes to address it. We also want someone who is comfortable using modern cloud-based security, compliance, automation, and AI-enabled tools to make GRC work more effective and scalable.

We also value people who have experience in using AI and automation to make GRC work smarter and more scalable, while applying appropriate judgment and validation to the output.

What You'll Do

  • Operate and improve Upwind's GRC and security compliance programs
  • Support compliance work across SOC 2, ISO 27001, NIST, and FedRAMP, including control implementation, evidence collection, documentation, remediation tracking, continuous monitoring, and audit readiness
  • Coordinate audit and compliance evidence from Engineering, IT, Security, Legal, and HR
  • Translate compliance requirements into clear actions for technical and business teams
  • Perform control assessments, gap analyses, and risk assessments, and recommend how to fix what you find
  • Work with process owners to build remediation that holds up over time and can be evidenced
  • Track vulnerabilities, risks, audit findings, and POA&Ms through completion
  • Handle customer security questionnaires, due diligence requests, and security documentation
  • Support third-party risk management and vendor security assessments
  • Write and maintain policies, standards, procedures, and control documentation
  • Maintain GRC systems, evidence repositories, and risk registers
  • Research new regulatory and customer requirements and determine how they apply to us
  • Use AI and automation to speed up research, documentation, evidence organization, and workflow, with appropriate validation and data handling
  • Raise gaps and issues early, with a proposed fix
Requirements

What We're Looking For

  • 3 to 5 years in GRC, cybersecurity, risk management, compliance, or audit. We'll consider less conventional backgrounds if the relevant experience is there.
  • Familiarity with NIST 800-53, SOC 2, ISO 27001, NIST CSF, or similar frameworks
  • Experience supporting audits, assessments, security questionnaires, or evidence collection
  • Strong written communication and documentation skills
  • Enough technical fluency to work effectively with Engineering, IT, and Security
  • Ability to turn audit findings into remediation plans that process owners will actually adopt
  • Comfort working in a fast-moving environment where priorities shift
  • Ownership. You drive assigned work to a conclusion and flag blockers rather than waiting.
  • Curiosity. You can research an unfamiliar requirement and figure out the right questions to ask.
  • Demonstrated use of technology to improve GRC work: risk analysis, evidence collection, control monitoring, remediation tracking, research, customer trust, or workflow automation
  • Organized and detail-oriented

Nice to Have

  • FedRAMP, NIST 800-53, or other U.S. government compliance experience, including POA&Ms, continuous monitoring, or assessment activities
  • Experience working with external assessors on formal readiness or assessment activities
  • Cloud security experience, particularly AWS or AWS GovCloud
  • Background in SaaS, cloud security, or a high-growth technology company
  • Experience with a global, distributed workforce across time zones
  • Hands-on experience with cloud-based GRC, compliance automation, or AI-enabled workflow platforms
  • Experience building GRC automations, integrations, or dashboards
  • Familiarity with Jira, GitHub, or similar tools
  • Certifications such as Security+, CISA, CRISC, CISM, CGRC, or ISO 27001
  • Relevant certifications such as Security+, CISA, CRISC, CISM, CGRC, ISO 27001, or similar.

Similar Jobs

25 Days Ago
Remote
US
105K-135K Annually
Senior level
105K-135K Annually
Senior level
Healthtech • HR Tech
Own and improve the enterprise GRC program through compliance automation, scalable workflows, control design, evidence collection, risk assessments, audits, remediation tracking, dashboards, and reporting. Support SOC 2 and ISO 27001 compliance while partnering with Security, IT, Engineering, Legal, Privacy, Finance, Audit, customers, and control owners. Lead GRC projects, translate regulatory requirements into actionable guidance, identify emerging risks, and mentor junior analysts.
Top Skills: DrataHyperproofServicenow Grc / IrmVanta
One Month Ago
Remote
United States
115K-125K Annually
Entry level
115K-125K Annually
Entry level
Fitness • Healthtech • HR Tech
The GRC and Privacy Analyst will administer compliance automation, maintain continuous control monitoring, support audits, and manage security and privacy programs. Responsibilities include mapping controls to SOC 2, ISO, HIPAA, HITRUST, NIST, and AI risk frameworks; conducting risk assessments; tracking remediation; documenting evidence; applying privacy regulations such as GDPR; coordinating cross-functional compliance projects; and using AI tools to improve compliance workflows.
Top Skills: Ai ToolsVanta
One Month Ago
Remote
United States
118K-174K Annually
Senior level
118K-174K Annually
Senior level
Cloud • Information Technology • Software
Lead design and implementation of security controls, drive audit readiness across multiple frameworks (FedRAMP, SOC2, ISO, CMMC), gather audit evidence, liaise with auditors and government officials, translate compliance into practical controls with engineering/product teams, draft policies, automate compliance processes, and represent the program in customer security reviews.
Top Skills: AICloudCmmc Level 2CsaCyber EssentialsDod Il5EarFacility Clearance License (Fcl)Fedramp ModerateGdprHpcIso 27001:2022ItarNispomNist Sp 800 SeriesSoc 2 Type 2Tisax Al2

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account