Upwind Security logo
Upwind Security
Posted 10 days agoVerified live 1d ago

GRC Analyst

Brief overview

Remote
UndergradOr in progress
3+ yrsMinimum
Governance, Risk, and Compliance (GRC)Risk ManagementSOC 2ISO 27001NIST 800-53NIST Cybersecurity Framework (NIST CSF)FedRAMPSecurity Audits and AssessmentsSecurity QuestionnairesThird-Party Risk ManagementCloud SecurityAWS

Job description

Summary

Upwind is a next-generation cloud security platform company focused on runtime-informed cloud security, compliance, and risk management. The GRC Analyst will support security and compliance programs across risk assessments, audits, policy governance, third-party risk, customer assurance, and regulatory frameworks while helping teams implement sustainable remediation and using automation and AI to improve GRC operations.

Responsibilities

  • Operate and improve Upwind's GRC and security compliance programs
  • Support compliance work across SOC 2, ISO 27001, NIST, and FedRAMP, including control implementation, evidence collection, documentation, remediation tracking, continuous monitoring, and audit readiness
  • Coordinate audit and compliance evidence from Engineering, IT, Security, Legal, and HR
  • Translate compliance requirements into clear actions for technical and business teams
  • Perform control assessments, gap analyses, and risk assessments, and recommend how to fix what you find
  • Work with process owners to build remediation that holds up over time and can be evidenced
  • Track vulnerabilities, risks, audit findings, and POA&Ms through completion
  • Handle customer security questionnaires, due diligence requests, and security documentation
  • Support third-party risk management and vendor security assessments
  • Write and maintain policies, standards, procedures, and control documentation
  • Maintain GRC systems, evidence repositories, and risk registers
  • Research new regulatory and customer requirements and determine how they apply to us
  • Use AI and automation to speed up research, documentation, evidence organization, and workflow, with appropriate validation and data handling
  • Raise gaps and issues early, with a proposed fix

Skills

  • 3 to 5 years in GRC, cybersecurity, risk management, compliance, or audit. We'll consider less conventional backgrounds if the relevant experience is there
  • Familiarity with NIST 800-53, SOC 2, ISO 27001, NIST CSF, or similar frameworks
  • Experience supporting audits, assessments, security questionnaires, or evidence collection
  • Strong written communication and documentation skills
  • Enough technical fluency to work effectively with Engineering, IT, and Security
  • Ability to turn audit findings into remediation plans that process owners will actually adopt
  • Comfort working in a fast-moving environment where priorities shift
  • Ownership. You drive assigned work to a conclusion and flag blockers rather than waiting
  • Curiosity. You can research an unfamiliar requirement and figure out the right questions to ask
  • Demonstrated use of technology to improve GRC work: risk analysis, evidence collection, control monitoring, remediation tracking, research, customer trust, or workflow automation
  • Organized and detail-oriented
  • FedRAMP, NIST 800-53, or other U.S. government compliance experience, including POA&Ms, continuous monitoring, or assessment activities
  • Experience working with external assessors on formal readiness or assessment activities
  • Cloud security experience, particularly AWS or AWS GovCloud
  • Background in SaaS, cloud security, or a high-growth technology company
  • Experience with a global, distributed workforce across time zones
  • Hands-on experience with cloud-based GRC, compliance automation, or AI-enabled workflow platforms
  • Experience building GRC automations, integrations, or dashboards
  • Familiarity with Jira, GitHub, or similar tools
  • Certifications such as Security+, CISA, CRISC, CISM, CGRC, or ISO 27001
  • Relevant certifications such as Security+, CISA, CRISC, CISM, CGRC, ISO 27001, or similar

Qualifications

Must Haves

  • 3 to 5 years in GRC, cybersecurity, risk management, compliance, or audit. We'll consider less conventional backgrounds if the relevant experience is there
  • Familiarity with NIST 800-53, SOC 2, ISO 27001, NIST CSF, or similar frameworks
  • Experience supporting audits, assessments, security questionnaires, or evidence collection
  • Strong written communication and documentation skills
  • Enough technical fluency to work effectively with Engineering, IT, and Security
  • Ability to turn audit findings into remediation plans that process owners will actually adopt
  • Comfort working in a fast-moving environment where priorities shift
  • Ownership. You drive assigned work to a conclusion and flag blockers rather than waiting
  • Curiosity. You can research an unfamiliar requirement and figure out the right questions to ask
  • Demonstrated use of technology to improve GRC work: risk analysis, evidence collection, control monitoring, remediation tracking, research, customer trust, or workflow automation
  • Organized and detail-oriented

Nice to Haves

  • FedRAMP, NIST 800-53, or other U.S. government compliance experience, including POA&Ms, continuous monitoring, or assessment activities
  • Experience working with external assessors on formal readiness or assessment activities
  • Cloud security experience, particularly AWS or AWS GovCloud
  • Background in SaaS, cloud security, or a high-growth technology company
  • Experience with a global, distributed workforce across time zones
  • Hands-on experience with cloud-based GRC, compliance automation, or AI-enabled workflow platforms
  • Experience building GRC automations, integrations, or dashboards
  • Familiarity with Jira, GitHub, or similar tools
  • Certifications such as Security+, CISA, CRISC, CISM, CGRC, or ISO 27001
  • Relevant certifications such as Security+, CISA, CRISC, CISM, CGRC, ISO 27001, or similar

More jobs like this