远程工作雷达

高级治理、风险与合规分析师

Senior Governance Risk and Compliance Analyst

市场运营未标注地域
公司RainFocus
薪资未公开
工作地点Orem, UT
地域资格未标注地域
时区要求无特别要求
用工类型未标注
发布时间25 天前
数据来源Remote OK
前往 Remote OK 查看并投递 →

RainFocus是一家最具创新力的软件公司之一,正在寻找一位卓越的高级治理、风险与合规(GRC)分析师

关于RainFocus

RainFocus关心其员工、客户以及我们所生活的世界。我们快速发展的团队为Adobe、Cisco、IBM、Oracle、VMware等财富500强公司提供服务,帮助他们在全球范围内策划和执行线下、线上及混合形式的活动。这些活动通过我们颠覆行业的软件平台进行交付,具备突破性的商业智能,以提升参会者体验、优化活动运营并加速营销成果。我们获得充足资金,增长迅速,正在打造一家改变市场的公司——这将是一项充满挑战、有趣且令人兴奋的工作。

关于该职位

我们正在寻找一位技能娴熟、积极主动的高级GRC分析师加入我们的安全与隐私团队。在该职位中,您将负责并推动RainFocus的治理、风险与合规项目——维护我们的控制框架,主导风险评估,支持审计工作,并推动项目的成熟度发展,而不仅仅是维持现状。您将直接向首席信息安全官汇报,并从第一天起就拥有重要职责。

关键职责:领导RainFocus在SOC 2、ISO 27001、PCI DSS及其他客户/监管合规框架下的GRC项目,包括审计准备、证据收集和与审计师的关系维护。

管理并提升我们的控制框架,映射新法规并进行差距分析。

负责年度安全风险评估流程(采用NIST SP 800-30方法论),包括利益相关者访谈、风险评分和剩余风险跟踪。

维护并更新安全策略、标准和文档,确保符合行业最佳实践。

与工程和安全团队合作,提升漏洞管理和密钥扫描实践,将这些措施从被动响应转变为主动的预部署控制。

协助建立并实施数据防泄漏(DLP)项目,包括政策设计和在邮件、终端及云存储中的部署。

发展和提升RainFocus的安全意识培训项目。

推动人工智能治理工作——制定政策、工具和监控机制,用于公司内部批准与未批准AI工具的使用。

与IT部门合作,识别并帮助解决影子IT/未管理SaaS的可见性缺口。

与跨职能团队协作

查看英文原文

RainFocus, one of the most innovative software companies, is in search of an exceptional Senior Governance, Risk, and Compliance (GRC) Analyst.

About RainFocus

RainFocus cares about its employees, customers, and the world in which we live. Our rapidly growing team serves Fortune 500 companies like Adobe, Cisco, IBM, Oracle, VMware, and others to prepare and execute in-person, virtual, and hybrid events across the world. Those events are delivered through our industry-disrupting software platform, with groundbreaking business intelligence, to elevate the attendee experience, streamline event operations, and accelerate marketing results. We are well-funded, growing fast, and building a company that is changing the market — it will be challenging, fun, and exciting.

About the Role

We are seeking a highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team. In this role, you will own and grow RainFocus's governance, risk, and compliance program — maintaining our control framework, leading risk assessments, supporting audits, and driving the program's maturity forward rather than simply maintaining the status quo. You will report directly to the CISO and have significant ownership from day one.

\n

Key Responsibilities:Lead RainFocus's GRC program across SOC 2, ISO 27001, PCI DSS, and other client/regulatory compliance frameworks, including audit prep, evidence collection, and auditor relationships.

Manage and mature our control framework, mapping new regulations and conducting gap assessments.

Own the annual security risk assessment process (NIST SP 800-30 methodology), including stakeholder interviews, risk scoring, and residual risk tracking.

Maintain and update security policies, standards, and documentation to ensure compliance with industry best practices.

Partner with Engineering and Security to mature vulnerability management and secrets-scanning practices, moving these from reactive to proactive, pre-deployment controls.

Help build out and operationalize a Data Loss Prevention (DLP) program, including policy design and rollout across email, endpoint, and cloud storage.

Grow and mature RainFocus's security awareness training program.

Drive AI governance efforts — policy, tooling, and monitoring for approved vs. unapproved AI tool usage across the company.

Identify and help close Shadow IT / unmanaged SaaS visibility gaps in partnership with IT.

Collaborate with cross-functional teams to implement risk management practices and ensure compliance across the organization.

Respond to security and privacy inquiries from clients, partners, and employees.

Prepare and present reports on the organization's security and privacy compliance status, including program maturity and remediation progress.

Stay abreast of emerging security threats, vulnerabilities, and compliance requirements.

Qualifications:Bachelor's degree in Technology, Cybersecurity, or a related field is highly desirable.

6+ years of proven experience in GRC, IT audit, information security compliance, or a related field.

In-depth knowledge of relevant regulations, standards, and frameworks (e.g., SOC 2, ISO 27001, PCI DSS, NIST 800-series, GDPR, and others).

Experience running or contributing heavily to formal risk assessments — not just tracking a compliance checklist.

Professional certifications such as CISA, CRISC, CISSP, CIPP, or CIPM are highly desirable.

Familiarity with modern security tooling such as Drata, OneTrust, Vanta, etc.

Strong analytical and problem-solving skills, with keen attention to detail.

Excellent communication and interpersonal skills to work effectively with technical and non-technical stakeholders.

Ability to manage multiple projects and meet deadlines in a fast-paced environment.

Experience with cloud security and compliance frameworks is a plus.

Experience with OneTrust or related GRC technologies is a plus.

Personal Characteristics:Strong work ethic and commitment to excellence.

Ability to work independently and as part of a team.

Excellent problem-solving and analytical skills.

Strong communication and interpersonal skills.

Ability to adapt to change and learn quickly.

Passion for security and privacy.

\nWhy work at RainFocus?

At RainFocus we delight millions of attendees at large-scale events by delivering better insights, experiences, and marketing. We were able to pivot our product and services offering in 2020 to continue growing and serving new clients and events.

As a member of the RainFocus team, you will have the opportunity to experience first-hand the impact of our platform at events around the world. Additionally, RainFocus offers competitive salaries, competitive benefits, 401k, generous PTO, and countless other team building activities.

What are you waiting for? Apply today! We need more talented, hard-working, fun-loving team members just like yourself!

Please mention the word **INSIGHTFULLY** and tag RMTE0LjIyOC42NC4xMzM= when applying to show you read the job post completely (#RMTE0LjIyOC42NC4xMzM=). This is a beta feature to avoid spam applicants. Companies can search these words to find applicants that read this and see they're human.

本页面信息整理自 Remote OK,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

← 返回全部职位