Security Governance Risk & Compliance Analyst I

Commerce
United States
Workplace: RemoteFull timeUSD 49,729 - 73,130 annuallyFunction: Legal, Risk & Compliance0Education: bachelorsSkills: ["Communication","Attention to detail","Process improvement","Cross-functional collaboration","Curiosity"]

Support the Governance, Risk & Compliance program by conducting third-party vendor risk assessments, maintaining the vendor risk register, and tracking remediation to closure. Assist with internal control testing and evidence collection for SOC 2, ISO 27001, and PCI-DSS. Coordinate audit requests, monitor policy documentation, escalate risk exceptions for senior review, and prepare risk metrics and reporting as the program scales.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Commerce
Commerce
2 days ago

Security Governance Risk & Compliance Analyst I

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 10 hours agoStatus: Live

Job Summary

Support the Governance, Risk & Compliance program by conducting third-party vendor risk assessments, maintaining the vendor risk register, and tracking remediation to closure. Assist with internal control testing and evidence collection for SOC 2, ISO 27001, and PCI-DSS. Coordinate audit requests, monitor policy documentation, escalate risk exceptions for senior review, and prepare risk metrics and reporting as the program scales.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Entry level

Key Responsibilities

  • •Support third-party risk assessments by reviewing vendor security questionnaires and documentation.
  • •Maintain and update the vendor risk register and track remediation activities to closure.
  • •Assist with internal control testing and evidence collection for compliance frameworks (SOC 2, ISO 27001, PCI-DSS, etc.).
  • •Coordinate audit requests and liaise with internal stakeholders to gather required documentation.
  • •Monitor policy/procedure documentation and track risk exceptions, escalating items for senior review; prepare leadership and committee-level reporting and metrics.

Pay and Benefits

Salary: USD 49,729 - 73,130 annually

Key Requirements

  • •0–2 years of experience in GRC, risk operations, compliance, or a related function (internships count).
  • •Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Business, or related field (equivalent work experience considered).
  • •Interest in GRC engineering and ability to learn quickly in a fast-paced environment.
  • •Hands-on familiarity with Claude Code (or similar AI coding tools) and thinking through how it applies to cybersecurity/GRC work.
  • •Strong written and verbal communication skills and high attention to detail with documentation, spreadsheets, and tracking tools.
Experience:0GRCRisk operationsComplianceEnterprise risk managementInformation security
Education:Bachelor's in Computer Science, Cybersecurity, Information Systems, Business, or a related field
Skills:CommunicationAttention to detailProcess improvementCross-functional collaborationCuriosity
Certifications:Security+CISA
Tech Stack:Claude CodeSOC 2ISO 27001PCI-DSSNISTMicrosoft OfficeGoogle Workspace

Company Brief

Commerce
Provides a SaaS e-commerce platform enabling retailers and brands to build, run, and scale online stores with customizable storefronts, integrations, and omnichannel selling tools.
Industry: SaaS
Company Size: Enterprise (1,001+ employees)
Revenue: USD 100M to 250M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Austin, United States
Founded: 2009
WebsiteLinkedIn