Summary
Upwind is a next-generation cloud security platform company focused on runtime-informed cloud security, compliance, and risk management. The GRC Analyst will support security and compliance programs across risk assessments, audits, policy governance, third-party risk, customer assurance, and regulatory frameworks while helping teams implement sustainable remediation and using automation and AI to improve GRC operations.
Responsibilities
- Operate and improve Upwind's GRC and security compliance programs
- Support compliance work across SOC 2, ISO 27001, NIST, and FedRAMP, including control implementation, evidence collection, documentation, remediation tracking, continuous monitoring, and audit readiness
- Coordinate audit and compliance evidence from Engineering, IT, Security, Legal, and HR
- Translate compliance requirements into clear actions for technical and business teams
- Perform control assessments, gap analyses, and risk assessments, and recommend how to fix what you find
- Work with process owners to build remediation that holds up over time and can be evidenced
- Track vulnerabilities, risks, audit findings, and POA&Ms through completion
- Handle customer security questionnaires, due diligence requests, and security documentation
- Support third-party risk management and vendor security assessments
- Write and maintain policies, standards, procedures, and control documentation
- Maintain GRC systems, evidence repositories, and risk registers
- Research new regulatory and customer requirements and determine how they apply to us
- Use AI and automation to speed up research, documentation, evidence organization, and workflow, with appropriate validation and data handling
- Raise gaps and issues early, with a proposed fix
Skills
- 3 to 5 years in GRC, cybersecurity, risk management, compliance, or audit. We'll consider less conventional backgrounds if the relevant experience is there
- Familiarity with NIST 800-53, SOC 2, ISO 27001, NIST CSF, or similar frameworks
- Experience supporting audits, assessments, security questionnaires, or evidence collection
- Strong written communication and documentation skills
- Enough technical fluency to work effectively with Engineering, IT, and Security
- Ability to turn audit findings into remediation plans that process owners will actually adopt
- Comfort working in a fast-moving environment where priorities shift
- Ownership. You drive assigned work to a conclusion and flag blockers rather than waiting
- Curiosity. You can research an unfamiliar requirement and figure out the right questions to ask
- Demonstrated use of technology to improve GRC work: risk analysis, evidence collection, control monitoring, remediation tracking, research, customer trust, or workflow automation
- Organized and detail-oriented
- FedRAMP, NIST 800-53, or other U.S. government compliance experience, including POA&Ms, continuous monitoring, or assessment activities
- Experience working with external assessors on formal readiness or assessment activities
- Cloud security experience, particularly AWS or AWS GovCloud
- Background in SaaS, cloud security, or a high-growth technology company
- Experience with a global, distributed workforce across time zones
- Hands-on experience with cloud-based GRC, compliance automation, or AI-enabled workflow platforms
- Experience building GRC automations, integrations, or dashboards
- Familiarity with Jira, GitHub, or similar tools
- Certifications such as Security+, CISA, CRISC, CISM, CGRC, or ISO 27001
- Relevant certifications such as Security+, CISA, CRISC, CISM, CGRC, ISO 27001, or similar
Qualifications
Must Haves
- 3 to 5 years in GRC, cybersecurity, risk management, compliance, or audit. We'll consider less conventional backgrounds if the relevant experience is there
- Familiarity with NIST 800-53, SOC 2, ISO 27001, NIST CSF, or similar frameworks
- Experience supporting audits, assessments, security questionnaires, or evidence collection
- Strong written communication and documentation skills
- Enough technical fluency to work effectively with Engineering, IT, and Security
- Ability to turn audit findings into remediation plans that process owners will actually adopt
- Comfort working in a fast-moving environment where priorities shift
- Ownership. You drive assigned work to a conclusion and flag blockers rather than waiting
- Curiosity. You can research an unfamiliar requirement and figure out the right questions to ask
- Demonstrated use of technology to improve GRC work: risk analysis, evidence collection, control monitoring, remediation tracking, research, customer trust, or workflow automation
- Organized and detail-oriented
Nice to Haves
- FedRAMP, NIST 800-53, or other U.S. government compliance experience, including POA&Ms, continuous monitoring, or assessment activities
- Experience working with external assessors on formal readiness or assessment activities
- Cloud security experience, particularly AWS or AWS GovCloud
- Background in SaaS, cloud security, or a high-growth technology company
- Experience with a global, distributed workforce across time zones
- Hands-on experience with cloud-based GRC, compliance automation, or AI-enabled workflow platforms
- Experience building GRC automations, integrations, or dashboards
- Familiarity with Jira, GitHub, or similar tools
- Certifications such as Security+, CISA, CRISC, CISM, CGRC, or ISO 27001
- Relevant certifications such as Security+, CISA, CRISC, CISM, CGRC, ISO 27001, or similar