FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

GRC Analyst
Ambience Healthcare. Run the SOC 2 program end to end, including auditor relationship, evidence collection, interpretation in Vanta, and continuous audit readiness .
Posted 9/29/2026full-timeSan Francisco • California • United StatesMid-LevelSenior💰 $164,000 - $205,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in managing SOC 2 programs, including auditor relations and evidence collection, while establishing AI governance frameworks. Proficient in writing compliance policies and conducting vendor risk assessments in a highly regulated environment.
Highest-signal resume keywords
SOC 2 Program ManagementGRC Automation Platform ExperienceAI Governance FrameworksVendor Risk AssessmentPolicy Writing for Compliance
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
SOC 2 Audit ManagementCompliance Policy WritingThreat ModelingEvidence CollectionData Flow Analysis
Soft Skills
OwnershipCollaborationAdaptabilityCommunication
Tools & Technologies
VantaDrataClaude Code
Certifications & Qualifications
ISO 27001ISO 42001
Industry Keywords
HealthcareFintechRegulated IndustryPHI Management
About the role
Key responsibilities & impact- Run the SOC 2 program end to end, including auditor relationship, evidence collection, interpretation in Vanta, and continuous audit readiness
- Help establish AI governance frameworks such as ISO 42001
- Build and maintain an authoritative inventory of PHI locations and systems/models that touch it
- Identify and close HIPAA and governance gaps
- Use AI coding assistants to verify whether controls are implemented and produce clear, evidenced answers
- Build and run security review processes for vendors and AI model providers
- Partner with legal and finance to complete documented vendor risk assessments
- Partner with engineering to enumerate, prioritize, and remediate security risks
- Author security and compliance policies for engineering, legal, and go-to-market teams
- Serve as the first point of contact for RFPs and security questionnaires
- Maintain a customer-facing trust portal with current security and compliance evidence
Requirements
What you’ll need- Senior-level GRC or compliance experience in a SaaS environment
- Ownership of a SOC 2 (or equivalent) audit from evidence collection through auditor sign-off
- Experience ideally using a GRC automation platform like Vanta or Drata
- Comfortable using an AI coding tool like Claude Code to answer compliance questions directly from source code
- Ability to threat-model a new vendor, including data touched, data flows, and required controls
- Ability to write policies and standards that hold up to audit and are usable by engineers
- Ability to work directly with engineering, legal, and customers
- Ability to thrive in ambiguity and take ownership of a partially built function
- ISO 27001 experience and exposure to ISO 42001 or other AI governance frameworks are nice-to-have
- Experience in healthcare, fintech, or another highly regulated industry is nice-to-have
Benefits
Comp & perks- Offers equity
- Comprehensive medical, dental, and vision coverage for you and your dependents
- 401(k) with a company match of up to 3% of base salary
- Remote-friendly culture
- Full equipment provisioning
- Parental leave
- Annual company-wide off-sites, team off-sites and regular team lunches and all-hands gatherings, with travel, lodging and meals covered
- Flexible time off with no annual cap
- Company-wide holidays
- Annual holiday shutdown from December 24–January 1