GRC Analyst

Vercel
United States
Workplace: HybridFull timeUSD 134,000 - 202,000 annuallyFunction: Government Affairs & Public PolicyExperience: 3+ yearsSkills: ["Organizational skills","Project management","Communication","Collaboration","Accountability"]

Own and maintain compliance across security and privacy frameworks, including ISO 27001, SOC 2, HIPAA, and PCI DSS. Collaborate with cross-functional teams to strengthen internal controls, drive remediation to completion, and streamline annual audit deliverables. Monitor control effectiveness and evidence management, improve GRC operations, and support go-to-market security questionnaires and compliance inquiries. Design internal training to build shared compliance accountability.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Vercel
Vercel
2 months ago

GRC Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Own and maintain compliance across security and privacy frameworks, including ISO 27001, SOC 2, HIPAA, and PCI DSS. Collaborate with cross-functional teams to strengthen internal controls, drive remediation to completion, and streamline annual audit deliverables. Monitor control effectiveness and evidence management, improve GRC operations, and support go-to-market security questionnaires and compliance inquiries. Design internal training to build shared compliance accountability.
Location: United States
Workplace: Hybrid
Employment Type: Full time
Job Function: Government Affairs & Public Policy
Seniority: Mid level

Key Responsibilities

  • •Collaborate with internal teams to maintain internal controls and drive remediation to completion with documented progress.
  • •Streamline annual audits by managing deliverables, developing treatment plans, and coordinating across teams to track completion.
  • •Monitor and improve controls, processes, and evidence management; identify opportunities to automate and streamline GRC operations and contribute to controls maturity reporting.
  • •Support go-to-market teams by responding to security questionnaires and compliance inquiries, and maintaining customer-facing documentation on Vercel’s security and compliance posture.
  • •Design and manage company training to improve visibility and understanding of compliance, ethics, and regulatory requirements across the organization.

Pay and Benefits

Salary: USD 134,000 - 202,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceFlexible TimeRemote Work

Key Requirements

  • •At least 3 years of experience supporting the audit lifecycle in a cloud-centric environment (e.g., SOC 2, ISO 27001, PCI, HIPAA).
  • •Strong organizational skills with the ability to be flexible and proactive in a fast-growing, startup environment.
  • •Experience partnering with internal teams to incorporate policies and technical controls into the SDLC.
  • •Strong project management skills and a sense of ownership, with clear communication and collaboration across business units.
  • •Experience supporting audit deliverables, treatment plans, and completion tracking to support audit success.
Experience:3+ years
Skills:Organizational skillsProject managementCommunicationCollaborationAccountability
Certifications:CISMCISSPCCEP
Languages:English
Tech Stack:ISO 27001SOC 2HIPAAPCI DSSGRCSDLCDrataLinearDatadogAzureAWSCloud infrastructureSecurity questionnaires

Company Brief

Vercel
Provides a frontend cloud platform and developer tools (including Next.js and v0) that simplify building, deploying, and scaling web and AI-native applications for developers and enterprises.
Industry: Cloud Computing
Company Size: Large (251 to 1,000 employees)
Revenue: USD 100M to 250M
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series F
Headquarters: San Francisco, United States
Founded: 2015
Glassdoor
Glassdoor: 4.1
WebsiteLinkedInGlassdoor