Governance, Risk, Complaince (GRC) Analyst

Aaru
New York
Workplace: OnsiteFull timeUSD 150,000 - 200,000 annuallyFunction: Legal, Risk & ComplianceSkills: ["Precision","Process building","Cross-functional communication","Intellectual honesty","Automation mindset"]

Own governance, risk, and compliance for an enterprise-focused AI company by leading security reviews, audit readiness, control testing, and evidence/policy governance. Build and automate repeatable GRC workflows in the company’s GRC platform, manage third-party/vendor risk through questionnaires and SOC 2/ISO reviews, and support AI governance across models and agents in collaboration with engineering, product, and legal.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Aaru
Aaru
6 days ago

Governance, Risk, Complaince (GRC) Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Own governance, risk, and compliance for an enterprise-focused AI company by leading security reviews, audit readiness, control testing, and evidence/policy governance. Build and automate repeatable GRC workflows in the company’s GRC platform, manage third-party/vendor risk through questionnaires and SOC 2/ISO reviews, and support AI governance across models and agents in collaboration with engineering, product, and legal.
Location: New York
Workplace: Onsite
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Mid level

Key Responsibilities

  • •Own responses to security questionnaires, due diligence requests, and RFP security sections while representing the company’s security posture in customer security and vendor risk conversations.
  • •Manage external audit readiness and execution, including RFI responses, control walkthroughs, and remediation to closure.
  • •Run recurring control testing and monitoring (access reviews and periodic testing), document effectiveness, identify gaps, and drive remediation with owners.
  • •Maintain policy and evidence governance by keeping policies versioned/attested and automating evidence collection so artifacts are generated via integration.
  • •Lead vendor assessment and third-party risk lifecycle, including questionnaires, SOC 2/ISO reviews, risk scoring, and policy enforcement across procurement and renewals, plus AI governance alongside engineering, product, and legal.

Pay and Benefits

Salary: USD 150,000 - 200,000 annually
Perks:Health InsuranceDentalVisionEquityVisa SponsorshipRelocation

Key Requirements

  • •3–5 years in GRC, security compliance, or IT audit, ideally in an enterprise-selling environment.
  • •Working knowledge of SOC 2 and familiarity with ISO 27001, NIST CSF, HIPAA, or PCI-DSS.
  • •Experience using tools like Vanta, Drata, OneTrust, or similar to automate evidence collection and manage controls.
  • •Comfort using AI tools for drafting, research, gap analysis, and evidence review with validated outputs.
  • •Ability to explain control requirements precisely to engineers, customers’ security teams, and commercial buyers.
Skills:PrecisionProcess buildingCross-functional communicationIntellectual honestyAutomation mindset
Certifications:CISACRISCCISMISO 27001 Lead AuditorISO 27001 Lead Implementer
Tech Stack:SOC 2ISO 27001NIST CSFHIPAAPCI-DSSVantaDrataOneTrustISO 42001NIST AI RMFEU AI ActGDPRSingapore PDPAPythonJavaScript

Eligibility

Work Authorization:Sponsorship available.

Company Brief

Aaru
Aaru builds multi-agent simulation software that models entire populations to predict behavior and future events, replacing traditional research with decision-ready forecasts for enterprises, governments, and agencies across industries.
Industry: AI & Machine Learning
Company Size: Small (11 to 50 employees)
Revenue: USD 1M to 5M
Growth: Early Stage Startup
Valuation: Unicorn (USD 1B+)
Funding: Series A
Headquarters: San Francisco, United States
Founded: 2024
WebsiteLinkedIn