Talent.com
GRC Analyst

GRC Analyst

BambooHRDraper, UT, US
30+ days ago
Job type
  • Full-time
Job description

Job Description

Job Description

Please Note : This is a Utah-based hybrid position which will require some regular in-office days each week. Additionally, employment with BambooHR is contingent on passing both a background and credit check.

Essential Job Duties

The GRC Analyst is a key member of BambooHR's GRC team responsible for evaluating and supporting compliance initiatives covering information security, policy, risk management, data classification, vendor management, privacy, audit, and awareness. This position assists other members of the GRC team with implementing information security policies and documentation, assessing compliance with existing policies, and ensuring overall compliance with security-related requirements from customers. In addition, this position assists with performing security assessments and monitoring and tracking compliance status; developing and improving processes, procedures, standards, and guidance; providing guidance on security control implementation; and implementing process improvement and maturity initiatives. The position will also assist in evaluating risks and controls to support the company's NIST CSF, ISO 27001, ISO 27018, ISO 42001, SOC 1, SOC 2, HITRUST, FedRAMP, and other regulatory and compliance initiatives. Success in this role requires a good understanding of information security best practices, strong security knowledge, the ability to understand and communicate risk and controls, organization, planning, good communication, and writing skills.

You will :

  • Work with internal stakeholder teams to document the implementation of security compliance control implementations for technical, management, and operational requirements
  • Conduct gap analysis of current policies, procedures, and practices as they relate to established guidelines outlined by NIST, FISMA, HIPAA, and other regulatory standards
  • Conduct risk assessments of technology infrastructure and operational processes and controls for assigned areas
  • Embrace AI as an essential tool for improving GRC accuracy, efficiency, and proactive risk management
  • Use AI-powered platforms for continuous controls monitoring, predictive risk assessments, and identifying compliance gaps while incorporating responsible AI use into practices
  • Improve efficiency in evidence collection and analysis, allowing the team to begin shifting time toward higher-value GRC activities with AI support
  • Build and maintain the controls matrix, in alignment with multiple compliance frameworks, including SOC 1 & SOC 2, PCI DSS, NIST CSF, ISO 27001, ISO 27018, ISO42001, HITRUST, and HIPAA
  • Develop and maintain security documentation such as the System Security Plan, Privacy Impact Assessment, Configuration Management Plan, Contingency Plan, Contingency Plan Test Report, POA&M, annual FISMA assessment, and incident reports
  • Assist in delivering and maintaining information security training and awareness programs
  • Perform vendor management / security risk assessments and interface with vendors on occasion
  • Track efforts related to threat and vulnerability assessment processes to monitor and remediate vulnerabilities in a timely manner

What You Need to Get the Job Done

  • Bachelor's degree in Computer Science, Information Technology, or related field
  • Minimum of 1 year of experience in compliance, audit, and / or information security
  • CISSP, CISA, CCSA, or equivalent certification preferred
  • Familiarity with enterprise-level compliance tools such as Drata, Vanta, ServiceNow, Archer, IBM GRC or other industry equivalent software
  • Foundational understanding and eagerness to learn FedRAMP, NIST CSF, FISMA, NIST RMF, NIST FIPS 199, ISO 27001, ISO 27018, ISO 42001, SOC 1, SOC 2, HIPAA and HITRUST
  • Basic understanding of cloud based environments for production applications, including Amazon Web Services, Google Cloud, or other large-scale cloud deployments
  • Experience in the vulnerability assessment lifecycle from the point of identification to remediation
  • Interpersonal skills to work as a team member and as a liaison
  • Excellent verbal communication, presentation, organizational and planning skills, and great attitude and ability to learn new things quickly
  • AI at BambooHR : At BambooHR, we believe in leveraging cutting-edge technology to empower people and transform HR. We're actively integrating AI into our solutions and workflows to enhance efficiency and drive innovation. To that end, we're looking to our existing team members and future hires to share this forward-thinking mindset : individuals who are curious about AI's potential, eager to learn and adapt, and ready to explore how intelligent tools can elevate their work along with BambooHR's impact on setting people free to do great work. Join us in reimagining the future of HR!
  • What You'll Love About Us

  • A Great Company Culture that has been recognized by multiple organizations like Inc, and Salt Lake Tribune
  • Comprehensive health, life, and disability insurance
  • Generous leave policies that include 4 weeks of vacation, 12 company holidays, parental leave, and volunteer time off so you can enjoy quality of life
  • 401k plans with up to 6% company match
  • $2000 Paid-Paid Vacation bonus
  • EAP through Headspace
  • Check out all our benefits that benefit you
  • About Us

    At BambooHR, we're building something different : we're building a people intelligence platform that transforms HR and sets people free to do great work! We're a proven market leader driving innovation while building lasting success through thoughtful, sustainable growth. Here, you'll find a place that champions growth : both professional and personal, both individual and collective.

    We invest in potential, giving you the space to stretch your capabilities and turn good ideas into reality while providing the safety net of a supportive, values-driven culture. Our approach combines meaningful work with meaningful lives, offering competitive benefits, professional development, and the flexibility to thrive both in and outside the office.

    What sets us apart isn't just what we do, but how we do it : with openness, integrity, and a shared commitment to doing the right thing. Join us in creating HR software that makes work better for everyone, while we make work better for you.

    BambooHR is committed to the full inclusion of all qualified individuals and will ensure that persons with disabilities are provided reasonable accommodations throughout the hiring process. If you would like to request accommodations, please let your recruiter know.

    BambooHR is An Equal Opportunity Employer M / F / D / V

    Because our team members are trusted to handle sensitive information, we require all candidates that receive and accept employment offers to complete a background check before being hired.

    For information on California Privacy Policy, click here.

    Our process utilizes AI as an assistant to efficiently process and analyze candidate data. Recruiters and hiring managers maintain full oversight and accountability, ensuring that all final selection and rejection decisions are human-made and based solely on objective job qualifications. Please see our General Privacy Notice and California Privacy Notice for more details.

    Create a job alert for this search

    Grc Analyst • Draper, UT, US

    Related jobs
    • Promoted
    CRM Analyst

    CRM Analyst

    VirtualVocationsSalt Lake City, Utah, United States
    Full-time
    A company is looking for a CRM Analyst to support marketing activities through data management and system maintenance.Key Responsibilities Develop and maintain CRM system to support marketing act...Show moreLast updated: 1 day ago
    • Promoted
    Risk and Compliance Analyst

    Risk and Compliance Analyst

    VirtualVocationsProvo, Utah, United States
    Full-time
    A company is looking for a Risk & Compliance Analyst.Key Responsibilities Design and implement compliance controls across a unified framework to manage regulatory and privacy obligations Drive r...Show moreLast updated: 30+ days ago
    • Promoted
    Epic Cadence Certified Analyst

    Epic Cadence Certified Analyst

    VirtualVocationsProvo, Utah, United States
    Full-time
    A company is looking for an Epic Application Analyst III, Cadence / Prelude.Key Responsibilities Serve as the primary development contact for Epic modules, focusing on configuration and optimizatio...Show moreLast updated: 1 day ago
    • Promoted
    CBP Cargo Specialist

    CBP Cargo Specialist

    VirtualVocationsSalt Lake City, Utah, United States
    Full-time
    A company is looking for a CBP Cargo Functional Specialist to provide leadership and guidance in cargo business processes and requirements for U. Key Responsibilities Provide leadership and guidan...Show moreLast updated: 1 day ago
    • Promoted
    Lead HRIS Analyst

    Lead HRIS Analyst

    VirtualVocationsProvo, Utah, United States
    Full-time
    A company is looking for a Lead HRIS Analyst to drive the development and execution of the Workday strategy and roadmap.Key Responsibilities Own the strategic direction, optimization, and governa...Show moreLast updated: 9 days ago
    • Promoted
    • New!
    Georgia Licensed Actuarial Engineer Manager

    Georgia Licensed Actuarial Engineer Manager

    VirtualVocationsProvo, Utah, United States
    Full-time
    A company is looking for a Python Engineer Manager (Actuarial).Key Responsibilities Lead a team of engineers to develop scalable data solutions and implement cloud-based strategies for actuarial ...Show moreLast updated: 7 hours ago
    • Promoted
    Senior Risk Analyst

    Senior Risk Analyst

    VirtualVocationsProvo, Utah, United States
    Full-time
    A company is looking for a Senior Risk Analyst responsible for mitigating merchant loss and ensuring compliance with regulations. Key Responsibilities Monitor Risk queues daily and take appropriat...Show moreLast updated: 30+ days ago
    • Promoted
    Regulatory Compliance Analyst (SIE, Series 99)

    Regulatory Compliance Analyst (SIE, Series 99)

    VirtualVocationsSalt Lake City, Utah, United States
    Full-time
    A company is looking for a Regulatory Compliance Analyst.Key Responsibilities Produce, validate, and submit non-financial regulatory reports Collaborate with various business units to ensure com...Show moreLast updated: 2 days ago
    • Promoted
    GCP Application Architect

    GCP Application Architect

    VirtualVocationsProvo, Utah, United States
    Full-time
    A company is looking for a GCP Application Architect.Key Responsibilities Conduct technical assessments of applications for migration readiness to Google Cloud Platform (GCP) Collaborate with ap...Show moreLast updated: 1 day ago
    • Promoted
    Microsoft Dynamics 365 Analyst

    Microsoft Dynamics 365 Analyst

    VirtualVocationsProvo, Utah, United States
    Full-time
    A company is looking for a Microsoft Dynamics 365 Technical Analyst to oversee and improve their Dynamics 365 environment. Key Responsibilities Maintain and update the Dynamics 365 environment for...Show moreLast updated: 1 day ago
    • Promoted
    Senior Analyst, Global Prospect Research

    Senior Analyst, Global Prospect Research

    VirtualVocationsProvo, Utah, United States
    Full-time
    A company is looking for a Senior Analyst, Global Prospect Research.Key Responsibilities Conduct in-depth research on prospective funders and deliver insightful profiles and analyses Collaborate...Show moreLast updated: 1 day ago
    • Promoted
    • New!
    Principal Program Planning and Scheduling Analyst

    Principal Program Planning and Scheduling Analyst

    Northrop Grumman CorporationRoy, UT, United States
    Full-time
    Principal Program Planning and Scheduling Analyst at Northrop Grumman Corporation summary : .The Principal Program Planning and Scheduling Analyst develops and maintains detailed project schedules to...Show moreLast updated: 16 hours ago
    • Promoted
    • New!
    EPLI Project Analyst

    EPLI Project Analyst

    VirtualVocationsProvo, Utah, United States
    Full-time
    A company is looking for an EPLI Project Analyst to assist with legal project management and client service initiatives.Key Responsibilities Facilitate matter intake and allocation of legal resou...Show moreLast updated: 3 hours ago
    • Promoted
    Senior GRC Analyst

    Senior GRC Analyst

    VirtualVocationsProvo, Utah, United States
    Full-time
    A company is looking for a Senior Governance, Risk and Compliance (GRC) Analyst - Platform Technology and Payments.Key Responsibilities Establish and manage a compliance program for the technolog...Show moreLast updated: 30+ days ago
    • Promoted
    Business Analyst I - Georgia

    Business Analyst I - Georgia

    VirtualVocationsProvo, Utah, United States
    Full-time
    A company is looking for a Business Analyst I (Remote-GA).Key Responsibilities Perform data analysis to identify factors affecting business profitability, growth, and efficiency Provide operatio...Show moreLast updated: 1 day ago
    • Promoted
    Epic Certified Application Analyst

    Epic Certified Application Analyst

    VirtualVocationsSalt Lake City, Utah, United States
    Full-time
    A company is looking for an Epic Resolute Professional Billing Application Analyst I, II, III.Key Responsibilities Provide primary support for Epic applications, specifically Resolute Professiona...Show moreLast updated: 30+ days ago
    • Promoted
    Remote Commercial Banking Analyst - AI Trainer

    Remote Commercial Banking Analyst - AI Trainer

    Data AnnotationLehi, Utah
    Remote
    Full-time +1
    We are looking for a finance professional to join our team to train AI models.You will measure the progress of these AI chatbots, evaluate their logic, and solve problems to improve the q...Show moreLast updated: 29 days ago
    • Promoted
    Senior HRIS Analyst

    Senior HRIS Analyst

    VirtualVocationsProvo, Utah, United States
    Full-time
    Key Responsibilities Provide advanced technical support for HR information systems including issue analysis, design, configuration, testing, and implementation Optimize workflow processes by bui...Show moreLast updated: 30+ days ago
    • Promoted
    Reinsurance Analyst

    Reinsurance Analyst

    VirtualVocationsSalt Lake City, Utah, United States
    Full-time
    A company is looking for a Reinsurance Analyst or Senior.Key Responsibilities Collaborate with business partners on reinsurance strategy and execution Lead reinsurance submission and marketing d...Show moreLast updated: 2 days ago
    • Promoted
    Epic Radiant Analyst

    Epic Radiant Analyst

    VirtualVocationsSalt Lake City, Utah, United States
    Full-time
    A company is looking for an Epic Radiant Analyst to join their team.Key Responsibilities Drive strategic process improvement and manage complex projects in healthcare IT Provide advisory service...Show moreLast updated: 2 days ago