远程工作雷达

高级GRC分析师 - 中部或东部时间,美国或加拿大

Senior GRC Analyst - Central or Eastern time, US or Canada

开发工程限定地区(需当地身份)
公司Shift Technology
薪资未公开
工作地点Canada - Remote; Canada - Toronto; US - Boston; US - Remote
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型未标注
发布时间今天
数据来源Greenhouse
前往企业招聘页投递 →
注意地域限制:该职位明确限定在 Canada - Remote; Canada - Toronto; US - Boston; US - Remote 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

Shift 为保险公司提供人工智能代理,改变其最关键的工作。通过结合深厚的行业专业知识和无与伦比的数据资源,Shift 提供了经过验证的结果,赢得了全球数百家领先保险公司的信任。我们的保险级 AI 准确、可解释、安全,使人类专家能够以无与伦比的速度、完全的信心以及对服务对象的全新关注来行动。

您的浏览器不支持视频标签。

我们的文化建立在创新、信任以及通过我们的 SaaS 平台变革保险行业的动力之上。我们来自超过 50 个不同的国家和文化,共同创造保险的未来。

了解更多请访问 www.shift-technology.com

作为高级 GRC 分析师,你将是 Shift 安全计划的核心,负责开发、维护和评估我们的集成安全与隐私管理框架。你将负责我们符合关键行业标准的合规性,领导风险评估,监督第三方安全保证计划,并支持 TrustOps 工作,包括客户材料、问题处理、合同审查和尽职调查。这个职位对于确保 Shift 满足其监管义务并保持客户的信任至关重要。作为信息安全部门的一员,该职位向 GRC 主管汇报。

职责

治理与政策管理

  • 作为主要联系人,将 Shift 的全球信息安全期望转化为可操作的政策、标准和流程。
  • 在整个组织中推广安全和合规的理念,传授标准知识并作为主题专家(SME)发挥作用。
  • 参与安全意识计划的开发和支持,确保其与政策和合规要求一致。
  • 与数据保护官合作,制定和维护隐私政策、数据处理标准和面向公众的隐私声明,符合隐私法和全球法规,如 GDPR。

风险管理与安全保证

  • 制定和维护安全保证计划,确保关键控制措施被有效设计和实施,以满足 Shift 的政策和标准。
  • 改进第三方信息安全保证和持续评估流程。
  • 与工程和业务团队合作,识别关键风险领域,并推动安全控制评估和测试。
查看英文原文

Shift delivers AI agents that transform insurers' most critical work. By combining deep industry expertise and unmatched data resources, Shift provides proven results that have earned the trust of hundreds of the world's leading insurers. Our insurance-grade AI is accurate, explainable, and secure—empowering human experts to move with unmatched speed, total confidence, and a renewed focus on the people they serve.

Your browser does not support the video tag.

Our culture is built on innovation, trust, and a drive to transform the insurance industry through our SaaS platform. We come from more than 50 different countries and cultures and together we are creating the future of insurance.

Learn more at www.shift-technology.com

As a Senior GRC Analyst, you will be a cornerstone of Shift’s security program, responsible for developing, maintaining, and assessing our integrated security and privacy management framework. You will manage our compliance with key industry standards, lead risk assessments, oversee our third-party security assurance program, and support TrustOps efforts for customer collateral, questions, contract reviews, and due diligence. This role is critical for ensuring that Shift meets its regulatory obligations and maintains the trust of our customers. As part of the Information Security department, this role reports to the GRC Lead.

RESPONSIBILITIES

Governance & Policy Management

  • Act as a lead contact to translate Shift’s global information security expectations into actionable policies, standards, and procedures.
  • Promote a mind-set of security and compliance across the organization, transferring knowledge of standards and acting as a subject matter expert (SME).
  • Contribute to the development and support of the security awareness program to ensure it aligns with policy and compliance requirements.
  • Partner with the Data Protection Officer to develop and maintain privacy policies, data handling standards, and public-facing privacy notices in line with privacy laws and global regulations such as GDPR.

Risk Management & Security Assurance

  • Develop and maintain the security assurance plan, ensuring key controls are effectively designed and implemented to meet Shift policies and standards.
  • Improve the third-party information security assurance and continuous assessment process.
  • Identify key risk areas in collaboration with engineering and business teams and facilitate security control evaluations and testing.
  • Review architectural designs and new initiatives to ensure they align with security policies and effectively mitigate risk.
  • Proactively identify potential information security GRC problem areas and execute plans to improve the overall assurance workflow.
  • Support and facilitate Data Protection Impact Assessments (DPIAs) for new products and initiatives.

Compliance & Audits

  • Manage and coordinate internal and external audits for certifications such as ISO 27001 and SOC 2 Type II.
  • Perform analysis and compile documentation and evidence to demonstrate the compliance level of systems, services, and controls.
  • Work with internal teams to manage the remediation of audit findings and track them to closure.
  • Support legal and stakeholder teams in responding to Data Subject Access Requests (DSARs)

Third-Party Risk Management

  • Develop, execute, and improve the third-party information security assurance and continuous assessment process.
  • Communicate with third parties and suppliers to conduct risk assessments, review their security posture, and manage the remediation of identified issues.

SKILLS & BACKGROUND

Experience & Education

  • 7+ years of proven experience in a GRC, IT Audit, Security Assurance, or Information Security role.
  • Bachelor’s Degree in a relevant field or equivalent work experience.
  • Professional certifications such as CIPP/E, CIPP/US, CIPT CISA, CISM, CRISC, or CISSP are highly desirable.
  • Direct experience of delivery in highly regulated industries, i.e financial services, healthcare.
  • Direct experience managing or supporting formal audit and certification processes from start to finish.

Knowledge & Frameworks

  • Deep knowledge of security and privacy frameworks is required (e.g., ISO 27001, ISO27701, SOC 2 Type II, HITRUST, NIST CSF)
  • Strong knowledge of global privacy and healthcare regulations (e.g., GDPR, HIPAA)
  • Working knowledge of AI regulations, frameworks, and standards (e.g., EU AI Act, ISO 42001)
  • Working knowledge of business continuity, disaster recovery, and incident response planning,  including plan structure, exercise and test methodologies.
  • Hands-on experience with modern GRC management tools, preferably Drata - connecting integrations, tuning automated evidence collection and monitoring tests, and building custom controls and frameworks.

Core Competencies

  • Exceptional communication and presentation skills, with the ability to translate complex compliance requirements into clear business guidance.
  • Strong stakeholder management skills with the ability to influence and align teams without direct authority.
  • Highly organized with strong project management skills, capable of managing multiple audits and assessments simultaneously.
  • An analytical mindset with the ability to balance regulatory requirements with business objectives and priorities.

RECRUITMENT PROCESS

  • First fit call with our Talent Acquisition Manager
  • Team fit call with the Hiring Manager
  • Tech round with the Team
  • A final interview with our CISO

#LI-RH1 #LI-HYBRID

The range listed is for base compensation.  Your actual base salary will vary based on factors including location and individual qualifications objectively assessed during the interview process.

In addition to base salary, your total rewards package will include additional components such as incentive pay and benefits.  If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the specific details for this position.

Base Salary Pay Range
$120,000—$150,000 USD

To support our permanent, full time employees at every stage of their careers and lives, we provide a competitive total rewards and benefits package. Here are the global benefits we’d like to highlight:

  • Flexible remote and hybrid working options
  • Competitive Salary and a variable component tied to personal and company performance
  • Multiple Learning and Development opportunities, including Focus Fridays, a half-day each month to focus on learning and personal growth
  • Generous PTO and paid holidays
  • Mental health benefits
  • 2 MAD Days per year (Make A Difference Days for paid volunteering)

Additional benefits may be offered by country, based on your eligibility - ask your recruiter for more information. Intern and Apprentice positions may receive some of these benefits - ask your recruiter for more details.

AI tools are used to help review applications for this role. Read our AI in Recruitment Notice for what the AI considers, how to request a human review, and our most recent bias audit.

At Shift we strive to be a diverse and inclusive workforce. We welcome applications from and hire people who will contribute to the diversity of our company, without regard to race, color, religion, marital status, age, national or ethnic origin, physical or mental disability, medical condition, pregnancy, genetic information, gender identity or expression, sexual orientation, or other non-merit criteria. Shift Technology is committed to providing reasonable accommodations for qualified individuals with disabilities in our application and employment process. Should you require accommodation, please email accommodation@shift-technology.com and we will work with you to meet your accessibility needs.

Please be aware of scammers and only trust correspondence that comes from emails ending in "shift-technology.com". We will never do initial outreach to you via Whatsapp/Text/SMS, never ask for banking information or personal identification numbers (ex. Social Security Number) as part of our recruitment process.

Shift Technology does not accept unsolicited CVs from recruiters or employment agencies in response to the Shift Technology Careers page or a Shift Technology social media post. Any unsolicited CVs, including those submitted directly to hiring managers, are deemed to be the property of Shift Technology.

本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位